wp-guard
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a defensive utility providing structured rules for reviewing WordPress plugins and themes. It includes a 'Mandatory confirmation gate' that requires explicit user authorization and scope definition before any sensitive operations can be performed.
- [EXTERNAL_DOWNLOADS]: The skill references documentation and research from well-known and trusted sources, including the official WordPress Developer Resources, the WordPress Coding Standards repository on GitHub, and established security organizations such as Veracode and GitGuardian. These references are used appropriately for educational context.
- [DATA_EXFILTRATION]: No exfiltration or unauthorized data access patterns were identified. The skill's instructions to read project configuration files (like composer.json or CLAUDE.md) are standard practices for establishing the technical context necessary for an accurate code review.
- [PROMPT_INJECTION]: The skill does not contain instructions that attempt to bypass safety filters or override the agent's core instructions. It uses natural language to define its scope and provides clear, defensive guidance for code analysis.
Audit Metadata