elementor-dynamic-tag-fields

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The skill includes a future date (2026-06-17) in the 'wp-skills-last-updated' field and references this date within the body as a migration milestone for Elementor syntax. This is technically deceptive as it describes a hypothetical future state as a historical reference.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the creation of components that ingest and process external data, creating an indirect prompt injection surface. Ingestion points: Instructions involve fetching data from 'get_the_content()', 'get_user_meta()', and user-defined fallback settings. Boundary markers: The skill describes the architectural boundaries between 'Tag' (HTML rendering) and 'Data_Tag' (structured data) base classes and advises on using Elementor's internal fallback logic. Capability inventory: The skill guides the creation of code that can echo content directly to the frontend or return structured data to the Elementor engine. Sanitization: The skill recommends and demonstrates appropriate sanitization using 'esc_html()', 'wp_kses_post_deep()', and type casting to mitigate injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:07 PM
Security Audit — agent-trust-hub — elementor-dynamic-tag-fields