wp-headless-and-wpgraphql
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected in this skill. The instructions and reference files are purely focused on providing best practices and checklists for reviewing headless WordPress architectures.
- [SAFE]: The included shell command patterns are intended for auditing purposes (using
rg) to identify potential vulnerabilities in external code and do not pose a risk in the context of the skill itself. - [SAFE]: The skill correctly emphasizes security boundaries, such as validating preview tokens, implementing capability checks in GraphQL resolvers, and managing cache invalidation safely.
Audit Metadata