wp-project-triage
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The script
detect_wp_project.mjsreadswp-config.php, which typically contains highly sensitive database credentials and authentication salts. Although the implementation only extracts specific configuration flags using regular expressions, accessing the file in its entirety represents a data exposure within the skill's execution environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests file content and metadata from the scanned repository to generate a report with recommendations. This creates a surface where a malicious repository could attempt to influence the agent's behavior through the generated output.\n - Ingestion points:
detect_wp_project.mjsrecursively reads various files includingblock.json,package.json, and.phpheaders to detect project signals.\n - Boundary markers: The JSON report generated by the script does not include specific boundary markers or warnings to the agent regarding the untrusted nature of the scanned data.\n
- Capability inventory: The agent uses the report's
recommendationsandcommandsfields to determine its next steps (e.g., running build or lint scripts), providing a path from untrusted file content to action.\n - Sanitization: The script does not perform specific sanitization or validation of the strings extracted from repository files before including them in the final report.
Audit Metadata