Back to skill

Security audit

WordPress Self-Hosted

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for managing a self-hosted WordPress site, but it gives an agent high-impact site-control authority and documents a REST credential pattern that can expose a WordPress application password to local process observers.

Install only if you intend to let the agent manage a specific self-hosted WordPress site with real publish/delete authority. Use a least-privilege WordPress account, a dedicated revocable application password, pre-populated SSH known_hosts where possible, and avoid the documented curl -u password pattern in shared or monitored environments.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:92
Finding

WordPress Application Password Exposed Through Process Arguments

Content
View full analysis
" --fields password --reveal) WP_BASE="https:///wp-json/wp/v2" # Verify auth works before proceeding curl -s -u "$WP_USER:$WP_PASS" "$WP_BASE/users/me" | jq '{id, name}' # List posts curl -s -u "$WP_USER:$WP_PASS" "$WP_BASE/posts?per_page=20&status=any" | jq '[.[] | {id, title: .title.rendered, status}]' # Get post content (raw blocks) curl -s -u "$WP_USER:$WP_PASS" "$WP_BASE/posts/?context=edit" | jq -r '.content.raw' # Create post (draft) curl -s -X POST -u "$WP_USER:$WP_PASS" "$WP_BASE/posts" \ -H "Content-Type: application/json" \ -d '{"title":"Post Title","content":"

Body

","status":"draft"}' # Update post content curl -s -X POST -u "$WP_USER:$WP_PASS" "$WP_BASE/posts/" \ -H "Content-Type: application/json" \ -d "{\"content\": $(cat /tmp/content.html | python3 -c 'import json,sys; print(json.dumps(sys.stdin.read()))')}" # Publish curl -s -X POST -u "$WP_USER:$WP_PASS" "$WP_BASE/posts/" \ -H "Content-Type: application/json" \ -d '{"status": "publish"}' ``` ### Technical Analysis The application password is retrieved in plaintext from 1Password and stored in the `WP_PASS` shell variable. Expanding that variable inside curl's `-u` argument places the username and plaintext password in curl's process argument vector. Depending on the operating system, process-monitoring configuration, and timing, command arguments may be visible to other local users, diagnostic tools, audit systems, process supervisors, or logs. Keeping the password only in a shell variable does not prevent this exposure once it is expanded into a command-line argument. The SSH and SSH-agent access documented by the Skill are consistent with its declared WordPress administration function and do no ...[truncated 1903 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (7)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

scp -o StrictHostKeyChecking=accept-new /tmp/post-content.html @:/tmp/

After use, clean up local and remote temp files

rm -f /tmp/post-content.html ssh @ 'rm -f /tmp/post-content.html'

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

After use, clean up local and remote temp files

rm -f /tmp/post-content.html ssh @ 'rm -f /tmp/post-content.html'

text

Temp files contain post HTML content only — not credentials. App passwords retrieved via `op` are captured into shell variables and never written to disk.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
curl -s -u "$WP_USER:$WP_PASS" "$WP_BASE/posts/<ID>?context=edit" | jq -r '.content.raw'

# Create post (draft)
curl -s -X POST -u "$WP_USER:$WP_PASS" "$WP_BASE/posts" \
  -H "Content-Type: application/json" \
  -d '{"title":"Post Title","content":"<p>Body</p>","status":"draft"}'

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 192)May include surrounding context.

Use WordPress block format (Gutenberg):

html
<!-- wp:paragraph -->
<p>Paragraph text here.</p>
<!-- /wp:paragraph -->

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 231)May include surrounding context.

Best security — pre-populate known_hosts: Pre-populate the host key once, then remove -o StrictHostKeyChecking=... from all commands entirely:

bash
ssh-keyscan -H <wp-host> >> ~/.ssh/known_hosts

Ephemeral/CI environments only: Use -o StrictHostKeyChecking=no to skip host verification entirely. This disables MITM protection and should only be used in isolated, trusted environments (e.g., CI pipelines with known, ephemeral hosts). Not recommended for interactive or persistent use.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
curl -s -u "$WP_USER:$WP_PASS" "$WP_BASE/posts/<ID>?context=edit" | jq -r '.content.raw'

# Create post (draft)
curl -s -X POST -u "$WP_USER:$WP_PASS" "$WP_BASE/posts" \
  -H "Content-Type: application/json" \
  -d '{"title":"Post Title","content":"<p>Body</p>","status":"draft"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

-d "{"content": $(cat /tmp/content.html | python3 -c 'import json,sys; print(json.dumps(sys.stdin.read()))')}"

Publish

curl -s -X POST -u "$WP_USER:$WP_PASS" "$WP_BASE/posts/"
-H "Content-Type: application/json"
-d '{"status": "publish"}'

text

Static analysis

No suspicious patterns detected.