zone-ee-wordpress-agent

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes content and configuration data from external WordPress sites, creating a surface for indirect prompt injection.
  • Ingestion points: The agent reads site content, templates, and plugin settings from the target WordPress database and filesystem to perform updates and audits.
  • Boundary markers: The instructions do not define specific delimiters or guardrails for processing ingested site data.
  • Capability inventory: The skill utilizes high-privilege interfaces including the WordPress REST API, Admin dashboard access, SFTP/SSH, and Zone.ee hosting controls.
  • Sanitization: There are no specific instructions for sanitizing or filtering site data before it is processed by the agent.
  • Mitigation: The inherent risks are significantly reduced by a mandatory staging-first policy and the requirement for explicit user approval before publishing changes to production.
  • [SAFE]: The skill demonstrates high security awareness by repeatedly instructing the user and agent to avoid storing passwords, application keys, or SSH credentials in repositories, chat logs, or templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 09:04 AM
Security Audit — agent-trust-hub — zone-ee-wordpress-agent