WordPress Expert

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed WordPress management skill whose sensitive access is expected for its purpose, but users should configure credentials and optional write tools carefully.

Review the separate wordpress-site-tools plugin before installing it, use a dedicated least-privilege WordPress application password, start on staging, allow only the specific tools you need, keep credentials out of Git/chat/screenshots/backups, and back up the site before destructive or broad write operations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The guide instructs users to place a WordPress username and application password directly into persistent OpenClaw configuration, but it does not give concrete guidance on secret handling, file permissions, redaction, or avoiding accidental exposure through logs, screenshots, backups, or version control. Because these credentials grant authenticated access to the target WordPress site, leakage could enable unauthorized API actions against site content and administrative endpoints permitted to that account.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal