wp-playground
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
references/cli.mdfile instructs the agent to usenpx @wp-playground/cli@latestfor local WordPress development and server management. This involves executing a remote Node.js package from the official vendor repository.\n- [EXTERNAL_DOWNLOADS]: Thereferences/website.mdfile facilitates downloading plugins, themes, and entire site snapshots from remote URLs using Query API parameters such as?plugin=,?import-site=, and?blueprint-url=. These downloads originate from the officialplayground.wordpress.netdomain or user-provided external URLs.\n- [DYNAMIC_EXECUTION]: Thereferences/website.mdfile exposes methods for runtime PHP execution viawindow.playground.run({ code })and sequence execution through JSON Blueprints. This allows for arbitrary code execution within the WordPress WebAssembly environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external URLs which could contain malicious instructions designed to exploit the agent's capabilities.\n - Ingestion points: The skill ingests remote content via Blueprint URLs, ZIP site imports, and WordPress export (WXR) files as described in
references/website.md.\n - Boundary markers: No delimiters or 'ignore embedded instructions' warnings are specified for the processed external data.\n
- Capability inventory: The skill has significant capabilities including PHP code execution (
run), filesystem mutation (writeFile,mkdir,unzip), and performing web requests (request) as detailed inreferences/website.md.\n - Sanitization: No evidence of input validation, escaping, or sanitization for external content was found in the provided files.
Audit Metadata