wp-abilities-api

Fail

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: HIGHMETADATA_POISONINGEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [METADATA_POISONING]: The skill is built entirely on fictitious information, claiming to support WordPress versions 7.0 and 7.1 (which do not exist as of current release cycles) and an "Abilities API" that is not a core feature of the WordPress platform. This deceptive metadata is designed to mislead both the AI agent and developers into trusting non-existent core functionality.
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install external code via composer require wordpress/abilities-api and to download releases from https://github.com/WordPress/abilities-api. These are not official WordPress resources, and the attempt to use the "WordPress" organization name in URLs and package names for unofficial content is a common indicator of a supply chain attack or deceptive practice.
  • [REMOTE_CODE_EXECUTION]: By providing installation commands and PHP execution patterns for fictitious or unverified third-party libraries, the skill encourages the execution of untrusted code. If these package names were registered by a malicious actor, following these instructions would lead directly to the installation of a malicious payload.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes instructions to the agent on how to "audit" itself or its own callbacks (e.g., "Run wp-security-audit on the execute_callback"), which could be used to manipulate the agent's reasoning process or bypass standard security evaluations by providing pre-defined "safe" behaviors for malicious inputs.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 9, 2026, 07:07 PM
Security Audit — agent-trust-hub — wp-abilities-api