wpml-compatibility-audit

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze third-party WordPress plugin and theme code provided by users to verify multilingual compatibility. This functionality creates an attack surface for indirect prompt injection if the code being audited contains malicious instructions intended to influence the agent's behavior.
  • Ingestion points: The audit workflow defined in SKILL.md requires the agent to ingest and inspect untrusted source code provided in the conversation context.
  • Boundary markers: The skill lacks explicit boundary markers or instructions for the agent to treat embedded strings in the audited code as data rather than instructions.
  • Capability inventory: No dangerous execution tools (such as shell access, file writing, or network requests) are defined in the skill configuration.
  • Sanitization: There are no instructions provided to sanitize or validate the content of the files being audited before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:08 PM
Security Audit — agent-trust-hub — wpml-compatibility-audit