woo-payments

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches documentation and class references from the official WooCommerce documentation site on GitHub Pages.
  • [INDIRECT_PROMPT_INJECTION]: The skill relies on fetching external documentation which is then used to guide the agent's code generation and environment modification tasks.
  • Ingestion points: The WebFetch tool is used to retrieve content from https://woocommerce.github.io/code-reference/classes/WC-Payment-Gateway.html.
  • Boundary markers: There are no explicit delimiters or instructions to the agent to treat the fetched content as untrusted data.
  • Capability inventory: The agent has access to Write, Edit, and Bash tools, which could be used to implement malicious code if the external source were compromised.
  • Sanitization: The skill does not implement any validation or sanitization of the fetched documentation before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:33 PM