woo-deploy
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill fetches external documentation and performs web searches to stay updated with WP-CLI commands and best practices, creating a surface for indirect prompt injection.
- Ingestion points:
SKILL.md(Before writing code section) fetches documentation fromdeveloper.wordpress.organd results from web searches. - Boundary markers: The instructions do not define specific delimiters or instructions to ignore potential commands embedded in the fetched documentation.
- Capability inventory: The skill utilizes
Bash,Write, andEdittools to perform site migrations and configuration updates. - Sanitization: No explicit sanitization is performed on the documentation fetched from the web before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to run WP-CLI commands for core updates, plugin management, and database search-replace operations. This behavior is consistent with the skill's primary purpose of store deployment and maintenance.
Audit Metadata