wordpress-penetration-testing

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines a large number of shell commands using tools like curl, nmap, and wpscan for reconnaissance and vulnerability discovery.
  • [REMOTE_CODE_EXECUTION]: The skill provides specific code snippets for a PHP reverse shell and a webshell payload using the system() function to execute arbitrary commands.
  • [DYNAMIC_EXECUTION]: The workflow instructs the agent to create and package malicious PHP scripts and XML configuration files at runtime using shell redirection and zip utilities.
  • [INDIRECT_PROMPT_INJECTION]: 1. Ingestion points: Untrusted data from external websites retrieved via curl in the discovery and enumeration phases (SKILL.md). 2. Boundary markers: No explicit delimiters or instructions to ignore embedded content are provided. 3. Capability inventory: Extensive shell command execution, file system modification, and network access. 4. Sanitization: No sanitization is performed on external content before it is processed by shell utilities or presented to the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 04:31 PM
Security Audit — agent-trust-hub — wordpress-penetration-testing