zone-ee-wordpress-agent
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes content and configuration data from external WordPress sites, creating a surface for indirect prompt injection.
- Ingestion points: The agent reads site content, templates, and plugin settings from the target WordPress database and filesystem to perform updates and audits.
- Boundary markers: The instructions do not define specific delimiters or guardrails for processing ingested site data.
- Capability inventory: The skill utilizes high-privilege interfaces including the WordPress REST API, Admin dashboard access, SFTP/SSH, and Zone.ee hosting controls.
- Sanitization: There are no specific instructions for sanitizing or filtering site data before it is processed by the agent.
- Mitigation: The inherent risks are significantly reduced by a mandatory staging-first policy and the requirement for explicit user approval before publishing changes to production.
- [SAFE]: The skill demonstrates high security awareness by repeatedly instructing the user and agent to avoid storing passwords, application keys, or SSH credentials in repositories, chat logs, or templates.
Audit Metadata