polylang-compatibility-audit

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [SAFE]: The skill is a documentation-centric resource designed to guide an agent's analysis of WordPress code. It does not implement any active code execution, network communication, or file system persistence.
  • [INDIRECT_PROMPT_INJECTION]: The skill is intended to process and audit external WordPress plugin or theme code, creating an inherent attack surface for indirect prompt injection. However, since the skill does not grant the agent any tool capabilities (such as shell execution, network requests, or file writes), any potential injection attempt in the audited code remains non-exploitable. 1. Ingestion points: Third-party WordPress plugin and theme source code provided by the user for auditing. 2. Boundary markers: No specific delimiters or safety warnings are instructed for use with the input code. 3. Capability inventory: None. The skill does not use any platform tools or dangerous APIs. 4. Sanitization: No automated sanitization or filtering of input code is performed.
  • [METADATA_POISONING]: The skill's frontmatter contains a future WordPress version (7.0) and a future last-updated date (2026). These are likely author errors or placeholders rather than deceptive intent, and they do not affect the security posture of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:07 PM
Security Audit — agent-trust-hub — polylang-compatibility-audit