skills/soderlind/skills/wp-mutate/Gen Agent Trust Hub

wp-mutate

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The helper script scripts/detect_mutation_setup.mjs employs execFileSync to call the system's php binary. This is used to probe for the presence and configuration of extensions like Xdebug and PCOV.\n- [COMMAND_EXECUTION]: The SKILL.md file provides explicit shell commands for the agent to run mutation test suites, including vendor/bin/pest, vendor/bin/infection, and npx stryker. These interactions are central to the skill's functionality but represent an administrative capability.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the user's repository by reading source and test files (PHP and JS). This data is used to classify the test suite and rank mutation survivors. There is a risk that malicious instructions embedded in these files could attempt to manipulate the agent's behavior during the triage process.\n
  • Ingestion points: detect_mutation_setup.mjs reads composer.json, package.json, and scans PHP/JS file headers. The agent reads code diffs during the Triage, with gates step in SKILL.md.\n
  • Boundary markers: The skill contains instructions to use canonical vocabulary and warns the agent to derive assertions from intended behavior rather than implementation details.\n
  • Capability inventory: The skill uses execFileSync in its script and directs the agent to execute shell-based testing tools.\n
  • Sanitization: The classification script uses regex for pattern matching on file content rather than executing it as code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:10 PM
Security Audit — agent-trust-hub — wp-mutate