NYC

wp-project-triage

Pass

Audited by Gen Agent Trust Hub on Feb 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • Command Execution (SAFE): The skill instructs the agent to execute a local Node.js script (detect_wp_project.mjs) and potentially use WP-CLI. These are standard tools for the described purpose.
  • Indirect Prompt Injection (LOW): The skill has an attack surface for indirect injection. Ingestion points: Filesystem-based inspection of a WordPress repository. Boundary markers: Employs a structured JSON schema (triage.schema.json) for output, which acts as a data boundary. Capability inventory: Node.js and Bash (WP-CLI) execution. Sanitization: No explicit sanitization of filesystem content is mentioned in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 19, 2026, 06:38 PM