wp-plugin-development

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a local Node.js script (scripts/detect_plugins.mjs) used to discover WordPress plugins within the repository. The script performs read-only operations on the filesystem to parse plugin headers and does not execute any code found in those files or make network requests.
  • [INDIRECT_PROMPT_INJECTION]: The detect_plugins.mjs script ingests content from PHP files in the project to extract metadata headers (e.g., Plugin Name, Version). This data is passed back to the agent as JSON. The script includes safety measures such as a maximum file depth, a file count limit, and a maximum read buffer (128KB) to prevent resource exhaustion or processing overly large files.
  • [SAFE]: The skill instructions and reference documents align with established WordPress security standards, specifically advocating for the use of nonces to prevent CSRF, capability checks for authorization, and $wpdb->prepare() for SQL safety. All external references link to the official WordPress Developer Resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 03:06 PM
Security Audit — agent-trust-hub — wp-plugin-development