wp-interactivity-api
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and modify WordPress project files (PHP, HTML, JS) to manage Interactivity API features. This creates a surface for indirect prompt injection if the files being triaged contain malicious instructions.
- Ingestion points: The agent searches for
data-wp-interactivedirectives and@wordpress/interactivitystore definitions across the repository. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when processing project code.
- Capability inventory: The agent has filesystem read/write access and shell execution capabilities (bash, node, wp-cli).
- Sanitization: No explicit sanitization or strict schema validation is described for the extracted directive data.
Audit Metadata