wordpress-social-writer
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a social media content generation workflow for the WordPress project. It provides comprehensive guidelines for voice, tone, and platform-specific requirements.
- [SAFE]: The skill fetches the official 'WordPress Brand Writing Style Guide' from the official WordPress GitHub repository (
github.com/WordPress/marketing). This is a trusted source and the operation is documented neutrally. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data (Post Title, URL, Content). It provides clear instructions for the agent to use this data purely for drafting social media posts. The risk is assessed as safe because the skill does not grant the agent capabilities to execute code, write files, or perform network operations with the ingested data other than fetching a specific, trusted style guide.
- [COMMAND_EXECUTION]: No shell commands, dynamic context injections, or executable scripts are present in the skill.
- [DATA_EXFILTRATION]: The skill does not access sensitive local files or perform unauthorized network exfiltration. Network access is restricted to fetching a brand guide from a trusted organization's repository.
- [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or secrets were detected. Guidelines suggest using shortlinks but do not require or provide credentials for link shortening services.
Audit Metadata