Back to skill

Security audit

Pinch to Post - Manage WordPress sites through WP Pinch MCP server

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed WordPress management skill that uses WP Pinch MCP tools, with no artifact evidence of hidden code, exfiltration, or deceptive behavior.

Install this only for WordPress sites you intend OpenClaw to manage. Use a least-privilege WordPress Application Password, prefer the OpenClaw Agent role or read-only mode when possible, confirm publish, plugin/theme, user, WooCommerce, cron, and bulk operations carefully, and be aware that generic trigger words like post or blog may route ordinary requests into this skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad, common terms like "post," "blog," and "site management," which can cause the skill to activate in conversations that are not specifically requesting WordPress administration. Because this skill exposes high-impact content and site-management actions, accidental invocation increases the chance of unintended reads or writes if the agent routes a request here without strong user confirmation.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
98% confidence
Finding

The trigger "wp" is extremely short and ambiguous, making unintended matches likely in normal text, abbreviations, or unrelated contexts. In a skill that can manage plugins, themes, users, and content, even low-friction accidental activation expands the risk of misrouting user intent into administrative tooling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.