blueprint
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill documents the
runPHPstep, which enables the execution of arbitrary PHP code within the WordPress Playground instance. - [COMMAND_EXECUTION]: It details the
wp-clistep, allowing for the execution of administrative commands via the WordPress command-line interface. - [REMOTE_CODE_EXECUTION]: The documentation covers the
installPluginandinstallThemesteps, which can download and execute code from external sources defined via URLs or Git repositories. - [EXTERNAL_DOWNLOADS]: It specifies resource types like
urlandgit:directorythat allow fetching content from remote locations, including specific guidance for GitHub repositories. - [DATA_EXFILTRATION]: The
requeststep is documented, which allows the environment to make outbound HTTP requests to arbitrary URLs with configurable headers and bodies. - [OBFUSCATION]: The skill provides an example of encoding a JSON blueprint into a URL fragment using
url_encodingfor browser-based testing. - [INDIRECT_PROMPT_INJECTION]: The skill documents a complex configuration surface (Blueprints) where an agent might ingest untrusted data to generate execution steps.
- Ingestion points: Blueprint JSON generation described throughout
SKILL.md. - Boundary markers: Not explicitly present in the specification for separating untrusted user data within a blueprint.
- Capability inventory: Includes
runPHP,wp-cli,writeFile, andrequeststeps. - Sanitization: The specification does not describe specific filtering or escaping for data interpolated into blueprint steps.
Audit Metadata