wordpress-pro

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation link 'https://jeffallan.github.io/claude-skills/skills/platform/wordpress-pro/' referenced in 'SKILL.md' is blacklisted as malicious by automated scanners. The 'SKILL.md' file itself has been flagged by file reputation scanners as potential malware (FileRepMalware).
  • [METADATA_POISONING]: The skill's frontmatter attributes authorship to 'Jeffallan', which contradicts the provider 'sodiqabdulwaris', representing a deceptive metadata pattern typical of impersonation.
  • [REMOTE_CODE_EXECUTION]: In 'references/plugin-architecture.md', the skill provides an implementation for a self-hosted update mechanism that fetches and executes remote packages from an external server.
  • [DATA_EXFILTRATION]: The 'Database_Backup' class in 'references/performance-security.md' creates full database exports stored within the public 'uploads' directory, creating a critical risk of sensitive data exposure.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project requirements without boundary markers, creating a surface for injection. 1. Ingestion points: WordPress project requirements in 'SKILL.md'. 2. Boundary markers: None identified. 3. Capability inventory: Writing PHP and JavaScript files, performing SQL queries, and executing network requests across all reference files. 4. Sanitization: Instructions focus on code output rather than the input processed by the agent itself.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 5, 2026, 11:39 AM
Security Audit — agent-trust-hub — wordpress-pro