block-theme-global-styles

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill involves auditing and implementing WordPress theme.json design data, which is often provided by untrusted sources. This exposes the agent to indirect prompt injection where instructions hidden within the JSON or CSS data could attempt to override the agent's behavior.
  • Ingestion points: Processes user-provided theme.json files, Global Styles variations, and CSS snippets as described in SKILL.md.
  • Boundary markers: The skill does not explicitly instruct the agent to use delimiters or ignore instructions within the user-provided data.
  • Capability inventory: The skill is intended for use in environments where the agent can manage theme files and potentially execute shell commands for validation.
  • Sanitization: While the skill correctly identifies the need for server-side sanitization in WordPress (e.g., KSES), it does not specify sanitization or escaping mechanisms for the agent's internal processing of that data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:07 PM
Security Audit — agent-trust-hub — block-theme-global-styles