wow-addon-development
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of instructional markdown files providing guidance on WoW add-on development. It does not contain any executable scripts, obfuscated content, or malicious instructions.
- [INDIRECT_PROMPT_INJECTION]: The skill addresses the vulnerability surface of processing untrusted configuration strings (profiles). It provides specific security instructions to the developer to 'Never evaluate an import string as Lua' and to use bounded, data-only codecs for serialization. This demonstrates a clear focus on preventing code injection within the domain's specific constraints.
- [EXTERNAL_DOWNLOADS]: The skill references established community resources such as the Warcraft Wiki (warcraft.wiki.gg) and public API mirrors on GitHub (Gethe/wow-ui-source). These are well-known, reputable sources for documentation in the WoW development community and do not involve risky remote code execution.
Audit Metadata