woo-payments
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches developer documentation and class references from official WooCommerce repositories and developer portals (developer.woocommerce.com, woocommerce.github.io) to ensure accurate implementation patterns.
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface:
- Ingestion points: WebSearch and WebFetch tools are used to retrieve live documentation (SKILL.md).
- Boundary markers: None specified.
- Capability inventory: Write, Edit, and Bash tools are available to the agent (SKILL.md).
- Sanitization: No explicit sanitization logic is defined for external content.
- Assessment: This surface is a functional requirement for the skill's primary purpose of providing developer guidance and is utilized to access trusted information.
- [SAFE]: No malicious patterns, obfuscation, or unauthorized access attempts were identified in the skill content.
Audit Metadata