wp-project-triage

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Node.js script located at 'skills/wp-project-triage/scripts/detect_wp_project.mjs' to inspect the repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface as it reads data from the repository being analyzed. 1. Ingestion points: Files in the repository root such as 'theme.json', 'block.json', and build configurations. 2. Boundary markers: None explicitly defined to prevent processing of malicious instructions inside scanned files. 3. Capability inventory: Execution of the local detection script and generation of a report to guide agent actions. 4. Sanitization: Not specified in the markdown instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 02:58 PM
Security Audit — agent-trust-hub — wp-project-triage