wp-abilities-api
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is primarily documentation and procedural logic for WordPress development tasks. It uses established hooks and official package ecosystems.
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and search repository content, which establishes an attack surface for indirect prompt injection if the project codebase contains malicious instructions.
- Ingestion points: Repository root directory (searching for PHP and JS patterns).
- Boundary markers: No explicit boundary markers or 'ignore' instructions for processed data are defined in the skill text.
- Capability inventory: The skill allows for searching files, determining WordPress versioning, and verifying REST API endpoints.
- Sanitization: The skill does not define specific sanitization or validation logic for the code it searches.
Audit Metadata