woo-deploy

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches external documentation and performs web searches to stay updated with WP-CLI commands and best practices, creating a surface for indirect prompt injection.
  • Ingestion points: SKILL.md (Before writing code section) fetches documentation from developer.wordpress.org and results from web searches.
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore potential commands embedded in the fetched documentation.
  • Capability inventory: The skill utilizes Bash, Write, and Edit tools to perform site migrations and configuration updates.
  • Sanitization: No explicit sanitization is performed on the documentation fetched from the web before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to run WP-CLI commands for core updates, plugin management, and database search-replace operations. This behavior is consistent with the skill's primary purpose of store deployment and maintenance.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM