wp-client-side-media-processing
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a security implementation guide, instructing developers to maintain server-side authority over all media data. It emphasizes that browser-produced dimensions, MIME types, and metadata must be validated on the server before being persisted, preventing trust boundary violations.\n- [SAFE]: The documentation for handling external media imports correctly directs developers to use core WordPress REST API functionality, which includes established SSRF protections and capability checks for remote sideloading.\n- [SAFE]: The skill includes technical guidance on browser isolation policies (Document-Isolation-Policy) and resource sharing (CORS), ensuring that cross-origin media processing is implemented in a secure, isolated context as required by modern web standards.\n- [SAFE]: All external URLs point to official WordPress.org core development resources, and the author metadata is consistent with the provided contact information.
Audit Metadata