woo-setup

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation from official and trusted domains such as developer.woocommerce.com and developer.wordpress.org. These are reputable resources within the WooCommerce ecosystem.
  • [COMMAND_EXECUTION]: Recommends standard installation of the @wordpress/env package and usage of official WP-CLI commands for environment management. These represent legitimate, non-malicious development workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests data from external sources.
  • Ingestion points: Official WooCommerce and WordPress documentation sites via WebFetch and WebSearch results.
  • Boundary markers: Absent; no explicit instructions are provided to delimit or ignore instructions embedded in the fetched content.
  • Capability inventory: Bash, Write, Edit, and Grep tools are available to the skill.
  • Sanitization: Absent; the skill does not specify validation or filtering of the fetched external documentation. The risk is assessed as safe given the high reputation and technical nature of the targeted domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:34 PM