wp-interactivity-api

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external repository content and interacts with project files to triage and debug Interactivity API usage. While this constitutes an attack surface for indirect prompt injection, where malicious code in a repository could attempt to influence the agent's behavior, it is a standard requirement for coding assistant skills.
  • Ingestion points: The skill reads repository files and triage output (wp-project-triage).
  • Boundary markers: None explicitly defined in the skill instructions for separating user data from system instructions.
  • Capability inventory: The skill utilizes bash and node for filesystem operations and build processes.
  • Sanitization: No explicit sanitization of repository content is described within the skill's procedure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:49 PM
Security Audit — agent-trust-hub — wp-interactivity-api