woo-blocks
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to perform web searches and fetch external documentation to guide its actions. This creates a potential vulnerability where an attacker could influence the agent's behavior by placing malicious instructions on public web pages targeting these search queries.
- Ingestion points: The agent is directed to use
WebSearchandWebFetchto retrieve information fromdeveloper.woocommerce.comanddeveloper.wordpress.org(SKILL.md). - Boundary markers: The instructions do not specify any delimiters or safety warnings to help the agent distinguish between legitimate documentation and potential embedded instructions.
- Capability inventory: The agent has access to powerful tools including
Bash,Write, andEdit, which could be exploited if the agent follows malicious instructions found in the fetched data. - Sanitization: There are no provisions for sanitizing or validating the content retrieved from external URLs before processing.
Audit Metadata