wp-metadata-api
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references official WordPress developer documentation at developer.wordpress.org, which is an established and trusted service.
- [DYNAMIC_EXECUTION]: The instructions address the security risks of PHP deserialization (unserialize) and proactively recommend defensive measures like setting 'allowed_classes' to false to prevent object injection.
- [SAFE]: No evidence of prompt injection, data exfiltration, obfuscation, or persistence mechanisms was found. The skill aligns with its stated purpose of improving code quality and security for WordPress plugins.
Audit Metadata