skills/wpgaurav/wordpress-skills/wpds/Gen Agent Trust Hub

wpds

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides standard architectural and design guidelines for WordPress-related UI development. The instructions to use a dedicated MCP server (wpds://) ensure the agent relies on verified documentation sources rather than unverified web content.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves processing documentation from an external MCP server, creating a potential surface for indirect instructions. This is an inherent property of documentation-fetching skills.
  • Ingestion points: Documentation retrieved via wpds://pages, wpds://components, and wpds://design-tokens URIs.
  • Boundary markers: The skill does not define specific delimiters for MCP-retrieved content.
  • Capability inventory: The skill allows the agent to generate and potentially validate UI code snippets.
  • Sanitization: No explicit sanitization of the documentation content is requested.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 02:59 PM
Security Audit — agent-trust-hub — wpds