wp-metadata-api

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references official WordPress developer documentation at developer.wordpress.org, which is an established and trusted service.
  • [DYNAMIC_EXECUTION]: The instructions address the security risks of PHP deserialization (unserialize) and proactively recommend defensive measures like setting 'allowed_classes' to false to prevent object injection.
  • [SAFE]: No evidence of prompt injection, data exfiltration, obfuscation, or persistence mechanisms was found. The skill aligns with its stated purpose of improving code quality and security for WordPress plugins.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:07 PM
Security Audit — agent-trust-hub — wp-metadata-api