wcm-membership-hooks
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [COMMAND_EXECUTION]: The workflow section instructs the agent to perform local filesystem searches using the
rg(ripgrep) utility on the WooCommerce Memberships plugin directory to verify hook implementations.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted user-provided code and local plugin source files, which could contain malicious instructions.\n - Ingestion points: User-provided code snippets and file content retrieved from the local filesystem via search tools.\n
- Boundary markers: Absent. The skill provides no instructions for the agent to ignore or delimit embedded instructions within the data it processes.\n
- Capability inventory: Shell command execution via
rg.\n - Sanitization: Absent. There is no evidence of validation or filtering for data processed at runtime.\n- [METADATA_POISONING]: The skill's YAML frontmatter contains an inconsistent
wp-skills-last-updatedvalue set to a future date ("2026-07-06"), which may be used to deceptively imply the skill's currency or validity.
Audit Metadata