wordpress-showcase-writer
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches a brand style guide from the official WordPress GitHub repository (https://raw.githubusercontent.com/WordPress/marketing/main/shared/references/wordpress-brand-writing-style-guide.md). This is a legitimate resource provided by the software vendor for style compliance.- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external websites via user-provided Site URLs, which creates a surface for indirect prompt injection.
- Ingestion points: The agent visits and reads the Site URL provided in the inputs to ground its descriptions.
- Boundary markers: The skill lacks explicit delimiters or "ignore previous instructions" warnings when processing the fetched site content, though it instructs the agent to verify all details.
- Capability inventory: The skill's capabilities are limited to generating text drafts; it does not have access to file-system writes, subprocess execution, or administrative commands.
- Sanitization: There is no explicit sanitization or filtering of the content retrieved from the site URL.
Audit Metadata