NYC
skills/automattic/agent-skills/wpds/Gen Agent Trust Hub

wpds

Pass

Audited by Gen Agent Trust Hub on Feb 19, 2026

Risk Level: SAFE
Full Analysis
  • [Prompt Injection] (SAFE): The skill contains only legitimate instructions for utilizing the WordPress Design System and lacks any patterns suggesting safety filter bypasses or role-play jailbreaks.- [Data Exposure & Exfiltration] (SAFE): No hardcoded secrets, sensitive file paths, or unauthorized network operations were identified. The use of the wpds:// protocol for local MCP server communication is a standard integration pattern.- [Unverifiable Dependencies & Remote Code Execution] (SAFE): The skill references established WordPress UI packages (@wordpress/components, @wordpress/ui) and does not attempt to download or execute external scripts at runtime.- [Indirect Prompt Injection] (SAFE): While the skill processes UI-related user requirements, it includes clear boundary markers to limit the scope of operations to UI components and tokens, reducing the risk of processing malicious data payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 19, 2026, 06:38 PM