wp-project-triage

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The script detect_wp_project.mjs reads wp-config.php, which typically contains highly sensitive database credentials and authentication salts. Although the implementation only extracts specific configuration flags using regular expressions, accessing the file in its entirety represents a data exposure within the skill's execution environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests file content and metadata from the scanned repository to generate a report with recommendations. This creates a surface where a malicious repository could attempt to influence the agent's behavior through the generated output.\n
  • Ingestion points: detect_wp_project.mjs recursively reads various files including block.json, package.json, and .php headers to detect project signals.\n
  • Boundary markers: The JSON report generated by the script does not include specific boundary markers or warnings to the agent regarding the untrusted nature of the scanned data.\n
  • Capability inventory: The agent uses the report's recommendations and commands fields to determine its next steps (e.g., running build or lint scripts), providing a path from untrusted file content to action.\n
  • Sanitization: The script does not perform specific sanitization or validation of the strings extracted from repository files before including them in the final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 03:36 PM
Security Audit — agent-trust-hub — wp-project-triage