wcm-membership-hooks

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [COMMAND_EXECUTION]: The workflow section instructs the agent to perform local filesystem searches using the rg (ripgrep) utility on the WooCommerce Memberships plugin directory to verify hook implementations.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted user-provided code and local plugin source files, which could contain malicious instructions.\n
  • Ingestion points: User-provided code snippets and file content retrieved from the local filesystem via search tools.\n
  • Boundary markers: Absent. The skill provides no instructions for the agent to ignore or delimit embedded instructions within the data it processes.\n
  • Capability inventory: Shell command execution via rg.\n
  • Sanitization: Absent. There is no evidence of validation or filtering for data processed at runtime.\n- [METADATA_POISONING]: The skill's YAML frontmatter contains an inconsistent wp-skills-last-updated value set to a future date ("2026-07-06"), which may be used to deceptively imply the skill's currency or validity.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:08 PM
Security Audit — agent-trust-hub — wcm-membership-hooks