wp-interactivity-api
Pass
Audited by Gen Agent Trust Hub on Feb 19, 2026
Risk Level: SAFE
Full Analysis
- [Prompt Injection] (SAFE): No instructions attempting to bypass safety filters or override agent behavior were found.
- [Data Exposure & Exfiltration] (SAFE): No hardcoded credentials, sensitive file paths, or unauthorized network operations were identified.
- [Remote Code Execution] (SAFE): The skill mentions standard development tools (node, bash, WP-CLI) but does not provide malicious execution commands or download scripts from untrusted sources.
- [Indirect Prompt Injection] (LOW): The skill ingests repository data and triage output, creating a potential surface for indirect injection if an attacker-controlled file is processed.
- Ingestion points: Repository root, triage output files.
- Boundary markers: None explicitly defined.
- Capability inventory: Filesystem access, bash command execution, node execution.
- Sanitization: Not explicitly implemented in the provided prompt instructions.
Audit Metadata