wp-site-audit-and-onboarding
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
rg(ripgrep) command to perform search patterns against the target WordPress repository. These commands are used solely for stack discovery, identifying the presence of specific plugins, themes, or frameworks like WooCommerce, Bedrock, or Gutenberg. - [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it reads and processes untrusted files from external WordPress repositories. While malicious strings in those files could attempt to influence the agent's output, the skill is designed for diagnostic classification and manual routing, minimizing the impact of such attempts.
- [SAFE]: No evidence of obfuscation, remote code execution from untrusted sources, or exfiltration of sensitive files was detected. The skill's operations are confined to analyzing the local codebase provided by the user.
Audit Metadata