agency-wordpress-shopping-cart-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions define operational boundaries and domain-specific rules (e.g., child-theme usage, price calculation methods). No attempts to bypass AI safety filters or override system-level instructions were identified.
  • [DATA_EXFILTRATION]: No evidence of hardcoded credentials, sensitive file harvesting, or unauthorized network operations. The skill explicitly instructs the agent to keep payment credentials and secrets out of the database and committed code, suggesting a security-conscious design.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving the download and execution of remote scripts or the installation of unverified third-party packages.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on storefront data, such as product attributes and checkout fields. It includes explicit instructions for server-side validation and avoiding reliance on client-side data, which addresses the potential for malicious data ingestion.
  • [COMMAND_EXECUTION]: While the skill mentions tools like WP-CLI and standard WordPress hooks, it does not contain instructions for executing arbitrary or malicious shell commands. All mentioned technical operations are within the scope of standard WordPress development.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 02:58 PM
Security Audit — agent-trust-hub — agency-wordpress-shopping-cart-engineer