wordpress-plugin-publish

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses npx pressship commands to interact with the local filesystem and WordPress.org for plugin management tasks. This behavior is consistent with the skill's stated purpose.\n- [EXTERNAL_DOWNLOADS]: The skill utilizes npx to run the pressship utility, which may involve downloading the package from the NPM registry if it is not already available. This is standard behavior for Node.js development tools.\n- [PROMPT_INJECTION]: The instructions include safety guidelines for the agent, such as requiring explicit user approval for publishing or modifying git history. No attempts to bypass safety filters or override agent behavior were detected.\n- [DATA_EXFILTRATION]: No unauthorized network operations or sensitive file access was found. The skill directs the user to use the built-in login command for authentication, ensuring credentials are handled through standard tool flows.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 03:41 PM
Security Audit — agent-trust-hub — wordpress-plugin-publish