wp-block-themes
Audited by ZeroLeaks on Apr 15, 2026
The SKILL.md is clear, well-structured, and straightforward to review, with no hidden execution paths or embedded secrets detected. It keeps instruction and data boundaries reasonably separate and does not push the agent to treat external content as trusted policy. Tested scenarios did not show material prompt-injection risk or skill-induced worsening of downstream behavior. Confidence is low not due to the scope of what was scanned, but because behavior analysis was not run, meaning downstream behavioral impact relative to a no-skill baseline remains unvalidated.
The scanned SKILL.md is materially reviewable, with no hidden execution path or secret-like content detected in the markdown.
The scanned skill keeps data and instructions reasonably separate and does not strongly encourage the agent to treat external content as policy.
Behavior analysis was not run.