wp-project-triage

Pass

Audited by Gen Agent Trust Hub on Mar 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill provides an indirect prompt injection surface by reading and processing the contents of arbitrary files within the repository (e.g., package.json, PHP headers).
  • Ingestion points: scripts/detect_wp_project.mjs via readFileSafe and scanForTokens.
  • Boundary markers: Absent (raw JSON output).
  • Capability inventory: Limited to filesystem read and stdout; no subprocess or network capabilities.
  • Sanitization: Absent; content is stringified directly into the report.
  • [SAFE]: The script performs filesystem-bound discovery of WordPress project configurations and tooling. It limits file reads to a maximum size and specifically targets non-sensitive constants (such as WP_DEBUG and SAVEQUERIES) for status checking rather than extracting credentials or secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 22, 2026, 03:03 PM
Security Audit — agent-trust-hub — wp-project-triage