wordpress-pro
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation link 'https://jeffallan.github.io/claude-skills/skills/platform/wordpress-pro/' referenced in 'SKILL.md' is blacklisted as malicious by automated scanners. The 'SKILL.md' file itself has been flagged by file reputation scanners as potential malware (FileRepMalware).
- [METADATA_POISONING]: The skill's frontmatter attributes authorship to 'Jeffallan', which contradicts the provider 'sodiqabdulwaris', representing a deceptive metadata pattern typical of impersonation.
- [REMOTE_CODE_EXECUTION]: In 'references/plugin-architecture.md', the skill provides an implementation for a self-hosted update mechanism that fetches and executes remote packages from an external server.
- [DATA_EXFILTRATION]: The 'Database_Backup' class in 'references/performance-security.md' creates full database exports stored within the public 'uploads' directory, creating a critical risk of sensitive data exposure.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project requirements without boundary markers, creating a surface for injection. 1. Ingestion points: WordPress project requirements in 'SKILL.md'. 2. Boundary markers: None identified. 3. Capability inventory: Writing PHP and JavaScript files, performing SQL queries, and executing network requests across all reference files. 4. Sanitization: Instructions focus on code output rather than the input processed by the agent itself.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata