wp-cli-local

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands and the WP-CLI binary to perform WordPress management tasks. It uses a wrapper script to correctly route commands to the site-specific PHP and MySQL binaries provided by the Local by Flywheel application.
  • [DYNAMIC_EXECUTION]: The bash scripts (wp and setup-direnv) use inline Python code blocks to parse sites.json and site-statuses.json. This is used for extracting site metadata and does not process untrusted external input.
  • [DATA_EXPOSURE]: The skill reads local configuration files located at ~/Library/Application Support/Local/sites.json to resolve site paths and service versions. This is a standard operation for its stated purpose of managing Local by Flywheel sites.
  • [PERSISTENCE]: The setup-direnv script generates .envrc files within the target site directories. While this modifies the filesystem, it is a documented feature intended to integrate with the direnv tool for automatic environment loading during development sessions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 09:13 AM
Security Audit — agent-trust-hub — wp-cli-local