wp-prepare
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches agent skills from the official WordPress GitHub organization using
npx skills add. These resources provide the agent with specialized capabilities for WordPress plugin and block development. - [EXTERNAL_DOWNLOADS]: Downloads coding and security instructions from a public repository (
github/awesome-copilot) to local project storage at.github/instructions/. These files help ensure that the agent follows WordPress-specific best practices. - [COMMAND_EXECUTION]: Automates project setup using shell commands like
npm init,git init, andcomposer require. Command execution inscripts/plan_setup.mjsis handled with hardcoded templates to mitigate the risk of shell injection from user-provided metadata. - [INDIRECT_PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by importing an external markdown instruction file into the project context.
- Ingestion points: The
wordpress.instructions.mdfile is downloaded viacurlinSKILL.md(Phase 6b) andscripts/plan_setup.mjs. - Boundary markers: None; the downloaded content is integrated directly as a set of rules for the AI agent to follow.
- Capability inventory: The agent possesses capabilities to execute shell commands (npm, git, composer), perform file system operations, and manage dependencies within the repository.
- Sanitization: The skill does not sanitize the contents of the downloaded instruction file before placing it in the project directory.
Audit Metadata