×
Third-party audit

Gen Agent Trust Hub

wp-abilities-verify · wordpress/agent-skills

High risk
Provider summary

This skill facilitates the verification of WordPress plugins but introduces a high-risk security vulnerability by instructing the agent to execute arbitrary shell commands defined within the target plugin's metadata files (AGENTS.md). This behavior allows a malicious repository to achieve remote code execution (RCE) on the agent's host system during the audit process. Additionally, the skill lacks sanitization for data ingested from audit documents used in environment seeding and execution.

The provider classified the analyzed snapshot as HIGH risk. This result applies to the content available at audit time.

Provider
Gen Agent Trust Hub
Normalized result
fail
Risk level
HIGH
Audited
Jul 22, 2026
Interpretation

How to use this signal

01

Confirm the source

Compare the repository, publisher, and installation command before continuing.

02

Read the content

Review SKILL.md, scripts, and allowed tools. Artificial Atlas never executes them during indexing.

03

Limit permissions

Use the narrowest possible scope and avoid broad credentials for third-party skills.