wp-playground

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The references/cli.md file instructs the agent to use npx @wp-playground/cli@latest for local WordPress development and server management. This involves executing a remote Node.js package from the official vendor repository.\n- [EXTERNAL_DOWNLOADS]: The references/website.md file facilitates downloading plugins, themes, and entire site snapshots from remote URLs using Query API parameters such as ?plugin=, ?import-site=, and ?blueprint-url=. These downloads originate from the official playground.wordpress.net domain or user-provided external URLs.\n- [DYNAMIC_EXECUTION]: The references/website.md file exposes methods for runtime PHP execution via window.playground.run({ code }) and sequence execution through JSON Blueprints. This allows for arbitrary code execution within the WordPress WebAssembly environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external URLs which could contain malicious instructions designed to exploit the agent's capabilities.\n
  • Ingestion points: The skill ingests remote content via Blueprint URLs, ZIP site imports, and WordPress export (WXR) files as described in references/website.md.\n
  • Boundary markers: No delimiters or 'ignore embedded instructions' warnings are specified for the processed external data.\n
  • Capability inventory: The skill has significant capabilities including PHP code execution (run), filesystem mutation (writeFile, mkdir, unzip), and performing web requests (request) as detailed in references/website.md.\n
  • Sanitization: No evidence of input validation, escaping, or sanitization for external content was found in the provided files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:19 PM
Security Audit — agent-trust-hub — wp-playground