woo-catalog

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill is designed to retrieve live technical documentation and API references from official WooCommerce developer portals and their public code reference repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes information from external documentation sources, creating a standard data ingestion surface for developer tools.
  • Ingestion points: Technical documentation fetched from developer.woocommerce.com and woocommerce.github.io using the WebSearch and WebFetch tools as instructed in SKILL.md.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are defined for the fetched external content.
  • Capability inventory: The skill is configured to use tools including Bash, Write, Edit, and Grep as defined in the allowed-tools section of SKILL.md.
  • Sanitization: While the skill recommends using the native wc_clean() function for product data within the generated PHP code, it does not explicitly define sanitization steps for the documentation content ingested at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM