wordpress-master

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate development assistant focused on WordPress architecture and optimization. It explicitly mandates security best practices, including SQL injection prevention via prepared statements, XSS protection, CSRF verification, and output escaping.
  • [COMMAND_EXECUTION]: While the skill uses tool capabilities like 'Bash', 'Read', and 'Write', these are scoped to WordPress development and infrastructure management. No suspicious or hardcoded command execution strings were identified.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external WordPress codebases and documentation, which constitutes an ingestion surface for indirect prompt injection. However, the instructions emphasize rigorous input validation and sanitization, and the inherent risk is consistent with a code-development assistant.
  • [DATA_EXPOSURE]: The skill documentation correctly identifies sensitive WordPress files (like wp-config.php) as objects of protection rather than targets for exfiltration. No hardcoded credentials or unauthorized network exfiltration patterns were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 08:06 AM
Security Audit — agent-trust-hub — wordpress-master