Is asif2bd/wordpress-publishing-skill-for-claude safe?

https://github.com/openclaw/skills/tree/main/skills/asif2bd/wordpress-publishing-skill-for-claude

88
SAFE

This WordPress publishing skill provides legitimate functionality for publishing content to WordPress sites via REST API. While credential files were accessed during installation, no actual data exfiltration occurred and the skill's code contains only standard WordPress publishing functionality.

Category Scores

Prompt Injection 95/100 · 30%
Data Exfiltration 75/100 · 25%
Code Execution 90/100 · 20%
Clone Behavior 95/100 · 10%
Canary Integrity 90/100 · 10%
Behavioral Reasoning 95/100 · 5%

Findings (3)

MEDIUM Credential File Access During Installation -25

The installation process accessed multiple sensitive credential files including .env, SSH keys, AWS credentials, .npmrc, Docker config, and GCloud credentials. However, no actual exfiltration occurred and canary integrity was maintained.

LOW Contains Executable Python Code -10

The skill includes Python scripts for WordPress publishing functionality. Code review shows legitimate WordPress REST API operations with no malicious behavior.

LOW Canary File Access Without Modification -10

Sensitive canary files were accessed during installation but remained unmodified, suggesting incidental access rather than malicious intent.