wp-plugin-development

Pass

Audited by Gen Agent Trust Hub on Mar 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill is designed to assist with WordPress plugin architecture and development, emphasizing security best practices like input validation and output escaping.
  • [COMMAND_EXECUTION]: The skill executes a local Node.js script to discover plugin files within the repository.
  • Evidence: node skills/wp-plugin-development/scripts/detect_plugins.mjs in SKILL.md.
  • Script Analysis: The detect_plugins.mjs script safely traverses the local filesystem to parse WordPress plugin headers (e.g., 'Plugin Name', 'Version') from PHP files. It includes depth and file count limits to prevent performance issues.
  • [EXTERNAL_DOWNLOADS]: The skill references several external resources for developer guidance.
  • Evidence: Numerous links to developer.wordpress.org in references/lifecycle.md, references/security.md, and references/settings-api.md.
  • Context: These links point to official documentation for the WordPress Settings API, security nonces, and plugin guidelines, which are trusted sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 22, 2026, 03:03 PM
Security Audit — agent-trust-hub — wp-plugin-development