fluentcart-migration
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [METADATA_POISONING]: The skill metadata contains deceptive values, specifically listing a tested WordPress version of '7.0.2' and a last-updated date of '2026-08-06'. These entries are misleading as they reference non-existent versions and future dates.
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a process for importing large volumes of untrusted commerce data, creating an attack surface for indirect prompt injection if source data is malicious. * Ingestion points: Data adapters in
fluent-cart-migrator/Classes/EDD3/andfluent-cart/app/Modules/WooCommerceMigrator/. * Boundary markers: Instructions mandate isolated staging environments and manual reconciliation reports. * Capability inventory: The skill utilizeswp-clifor high-volume database writes andMigratorService::wipeMigratedData()for destructive resets. * Sanitization: Documentation describes monetary transformation but lacks details on sanitizing string fields against prompt injection. - [COMMAND_EXECUTION]: The skill encourages the use of
wp-clicommands for data management and notes a specific safety bypass in version 1.0.0 where the--resetflag ignores theFLUENT_CART_DEV_MODEguard, increasing the risk of accidental production data loss.
Audit Metadata