blueprint

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill documents the runPHP step, which enables the execution of arbitrary PHP code within the WordPress Playground instance.
  • [COMMAND_EXECUTION]: It details the wp-cli step, allowing for the execution of administrative commands via the WordPress command-line interface.
  • [REMOTE_CODE_EXECUTION]: The documentation covers the installPlugin and installTheme steps, which can download and execute code from external sources defined via URLs or Git repositories.
  • [EXTERNAL_DOWNLOADS]: It specifies resource types like url and git:directory that allow fetching content from remote locations, including specific guidance for GitHub repositories.
  • [DATA_EXFILTRATION]: The request step is documented, which allows the environment to make outbound HTTP requests to arbitrary URLs with configurable headers and bodies.
  • [OBFUSCATION]: The skill provides an example of encoding a JSON blueprint into a URL fragment using url_encoding for browser-based testing.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents a complex configuration surface (Blueprints) where an agent might ingest untrusted data to generate execution steps.
  • Ingestion points: Blueprint JSON generation described throughout SKILL.md.
  • Boundary markers: Not explicitly present in the specification for separating untrusted user data within a blueprint.
  • Capability inventory: Includes runPHP, wp-cli, writeFile, and request steps.
  • Sanitization: The specification does not describe specific filtering or escaping for data interpolated into blueprint steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:35 AM
Security Audit — agent-trust-hub — blueprint