wp-client-side-media-processing

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a security implementation guide, instructing developers to maintain server-side authority over all media data. It emphasizes that browser-produced dimensions, MIME types, and metadata must be validated on the server before being persisted, preventing trust boundary violations.\n- [SAFE]: The documentation for handling external media imports correctly directs developers to use core WordPress REST API functionality, which includes established SSRF protections and capability checks for remote sideloading.\n- [SAFE]: The skill includes technical guidance on browser isolation policies (Document-Isolation-Policy) and resource sharing (CORS), ensuring that cross-origin media processing is implemented in a secure, isolated context as required by modern web standards.\n- [SAFE]: All external URLs point to official WordPress.org core development resources, and the author metadata is consistent with the provided contact information.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:07 PM
Security Audit — agent-trust-hub — wp-client-side-media-processing