wp-playground
Audited by ZeroLeaks on Apr 15, 2026
The SKILL.md carries a transparency concern due to an obfuscated or encoded execution path, which weakens pre-use reviewability and makes it harder to fully assess what the skill does before loading it. On the positive side, the skill does not appear to materially weaken instruction/data boundaries or push the agent to treat external content as trusted policy. However, confidence is low because behavior analysis was not run, meaning we cannot confirm whether loading the skill materially changes downstream behavior compared to a no-skill baseline—combined with the transparency gap, this leaves meaningful uncertainty that prevents a clean pass.
The skill has 1 transparency concern that weaken pre-use reviewability, mainly around obfuscated or encoded execution path.
The scanned skill keeps data and instructions reasonably separate and does not strongly encourage the agent to treat external content as policy.
Behavior analysis was not run.
Obfuscated or encoded execution path