woo-blocks

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to perform web searches and fetch external documentation to guide its actions. This creates a potential vulnerability where an attacker could influence the agent's behavior by placing malicious instructions on public web pages targeting these search queries.
  • Ingestion points: The agent is directed to use WebSearch and WebFetch to retrieve information from developer.woocommerce.com and developer.wordpress.org (SKILL.md).
  • Boundary markers: The instructions do not specify any delimiters or safety warnings to help the agent distinguish between legitimate documentation and potential embedded instructions.
  • Capability inventory: The agent has access to powerful tools including Bash, Write, and Edit, which could be exploited if the agent follows malicious instructions found in the fetched data.
  • Sanitization: There are no provisions for sanitizing or validating the content retrieved from external URLs before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM