wp-content
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to fetch and process data from a WordPress site which may contain untrusted instructions.
- Ingestion points: Data enters the agent's context through tools such as
core/list-postsandcore/get-postmentioned inSKILL.mdandreferences/wp-content-types.md. - Boundary markers: Absent. The instructions do not define any delimiters or warnings to ignore commands embedded in the fetched content.
- Capability inventory: The skill facilitates write actions including
core/create-postandcore/update-postvia the genericExecute abilitytool (SKILL.md). - Sanitization: Absent. No sanitization or validation logic is provided to handle content retrieved from external sources.
- [NO_CODE]: The skill consists entirely of instructional Markdown and reference schemas with no executable scripts or binaries.
Audit Metadata