wpds
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides standard architectural and design guidelines for WordPress-related UI development. The instructions to use a dedicated MCP server (
wpds://) ensure the agent relies on verified documentation sources rather than unverified web content. - [INDIRECT_PROMPT_INJECTION]: The skill involves processing documentation from an external MCP server, creating a potential surface for indirect instructions. This is an inherent property of documentation-fetching skills.
- Ingestion points: Documentation retrieved via
wpds://pages,wpds://components, andwpds://design-tokensURIs. - Boundary markers: The skill does not define specific delimiters for MCP-retrieved content.
- Capability inventory: The skill allows the agent to generate and potentially validate UI code snippets.
- Sanitization: No explicit sanitization of the documentation content is requested.
Audit Metadata