wc-abandoned-cart-recovery

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill serves as documentation for developer integration and does not include any executable scripts or automation that could perform unauthorized actions. It emphasizes privacy-preserving measures and security best practices for handling customer data and order links.- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the auditing of WooCommerce orders, which include user-controlled fields such as billing details and cart contents. This creates a potential surface for indirect prompt injection if the agent processes malicious strings embedded in these fields during an audit.
  • Ingestion points: Order data accessed via WC_Order objects and order metadata as described in SKILL.md.
  • Boundary markers: The instructions do not specify explicit prompt delimiters for the data being audited.
  • Capability inventory: The skill contains no scripts with network, file-system write, or subprocess execution capabilities.
  • Sanitization: The guidelines recommend standard WordPress functions like sanitize_key and highlight the use of HMAC verification for secure endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:08 PM
Security Audit — agent-trust-hub — wc-abandoned-cart-recovery