fluentcart-migration

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [METADATA_POISONING]: The skill metadata contains deceptive values, specifically listing a tested WordPress version of '7.0.2' and a last-updated date of '2026-08-06'. These entries are misleading as they reference non-existent versions and future dates.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a process for importing large volumes of untrusted commerce data, creating an attack surface for indirect prompt injection if source data is malicious. * Ingestion points: Data adapters in fluent-cart-migrator/Classes/EDD3/ and fluent-cart/app/Modules/WooCommerceMigrator/. * Boundary markers: Instructions mandate isolated staging environments and manual reconciliation reports. * Capability inventory: The skill utilizes wp-cli for high-volume database writes and MigratorService::wipeMigratedData() for destructive resets. * Sanitization: Documentation describes monetary transformation but lacks details on sanitizing string fields against prompt injection.
  • [COMMAND_EXECUTION]: The skill encourages the use of wp-cli commands for data management and notes a specific safety bypass in version 1.0.0 where the --reset flag ignores the FLUENT_CART_DEV_MODE guard, increasing the risk of accidental production data loss.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:06 PM
Security Audit — agent-trust-hub — fluentcart-migration