wp-interactivity-api

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and modify WordPress project files (PHP, HTML, JS) to manage Interactivity API features. This creates a surface for indirect prompt injection if the files being triaged contain malicious instructions.
  • Ingestion points: The agent searches for data-wp-interactive directives and @wordpress/interactivity store definitions across the repository.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when processing project code.
  • Capability inventory: The agent has filesystem read/write access and shell execution capabilities (bash, node, wp-cli).
  • Sanitization: No explicit sanitization or strict schema validation is described for the extracted directive data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:53 PM
Security Audit — agent-trust-hub — wp-interactivity-api