wordpress-showcase-writer

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches a brand style guide from the official WordPress GitHub repository (https://raw.githubusercontent.com/WordPress/marketing/main/shared/references/wordpress-brand-writing-style-guide.md). This is a legitimate resource provided by the software vendor for style compliance.- [INDIRECT_PROMPT_INJECTION]: The skill analyzes external websites via user-provided Site URLs, which creates a surface for indirect prompt injection.
  • Ingestion points: The agent visits and reads the Site URL provided in the inputs to ground its descriptions.
  • Boundary markers: The skill lacks explicit delimiters or "ignore previous instructions" warnings when processing the fetched site content, though it instructs the agent to verify all details.
  • Capability inventory: The skill's capabilities are limited to generating text drafts; it does not have access to file-system writes, subprocess execution, or administrative commands.
  • Sanitization: There is no explicit sanitization or filtering of the content retrieved from the site URL.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:36 PM
Security Audit — agent-trust-hub — wordpress-showcase-writer