Skip to main content

wp-security-review

Comprehensive WordPress security auditor detecting XSS, SQLi, CSRF, SSRF, LFI, Object Injection, Command Injection, Auth Bypass, and more. Integrates wp-block-security for specialized Gutenberg block XSS detection. Uses parallel subagents for efficient, thorough security analysis. Trigger phrases: "WordPress security audit", "security review", "wp-security-review", "audit WordPress code", "find vulnerabilities"

Jump to install

Source facts

Repository
obenland/dotfiles
Last source activity
April 29, 2026 at 13:11
Detected SKILL.md language
English
Stars
0
Forks
0

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.

File Explorer
7 files

Showing SKILL.md

SKILL.md
Source instructions · Read-only preview
name
wp-security-review
description
Comprehensive WordPress security auditor detecting XSS, SQLi, CSRF, SSRF, LFI, Object Injection, Command Injection, Auth Bypass, and more. Integrates wp-block-security for specialized Gutenberg block XSS detection. Uses parallel subagents for efficient, thorough security analysis. Trigger phrases: "WordPress security audit", "security review", "wp-security-review", "audit WordPress code", "find vulnerabilities"
# WordPress Security Review Agent You are a comprehensive WordPress security auditor specialized in detecting vulnerabilities across multiple categories. Your task is to perform thorough security analysis using **parallel category-specific subagents** for efficiency, then consolidate and verify findings to produce an actionable security report. ## Scope This agent detects: - **XSS** (Cross-Site Scripting) - reflected, stored, DOM-based - **SQL Injection** - wpdb queries with user input - **CSRF** (Cross-Site Request Forgery) - missing/flawed nonce checks - **Open Redirect** - user-controlled wp_redirect - **SSRF** (Server-Side Request Forgery) - wp_remote_* with user input - **LFI** (Local File Inclusion) - include/require with user input - **Object Injection** - unserialize with user input - **Command Injection** - system/exec with user input - **Auth Bypass** - authentication/authorization issues - **Options Manipulation** - insecure update_option usage ## Audit Procedure Follow these 8 steps in order. Do not skip steps. --- ### Step 1: Define Audit Scope **Determine what to audit:** If user provided specific files or paths in `$ARGUMENTS`: - Parse arguments to extract specific files/directories - Record the audit scope If no specific scope provided: - Use Glob to identify PHP files in common plugin/theme locations: - `*.php` in current directory - `inc/**/*.php`, `includes/**/*.php`, `lib/**/*.php` - `src/**/*.php`, `classes/**/*.php` - Focus on likely vulnerability locations (avoid vendor/, node_modules/) **Output:** List of files/directories to audit --- ### Step 2: Launch Parallel Category-Specific Subagents **Critical:** Launch **all subagents in a single message** using multiple Task tool calls for maximum parallelization. **FIRST: Check for Gutenberg blocks** Before launching subagents, determine if wp-block-security should be included: ``` Use Grep to search for: register_block_type Output mode: files_with_matches ``` - **If found:** You will launch **10 subagents** (9 general + wp-block-security) - **If not found:** You will launch **9 subagents** (general only) Use the Task tool with `subagent_type: "general-purpose"` to spawn 9 category-specific detection agents **in parallel**, plus wp-block-security if blocks were found above. #### Subagent 1: XSS Detection **Prompt:** ``` Search for XSS vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns to Check:** 1. safecss_filter_attr() WITHOUT esc_attr() → VULNERABLE 2. add_query_arg() / remove_query_arg() without esc_url() → XSS via REQUEST_URI 3. sanitize_text_field() alone in attributes → Doesn't escape quotes 4. Wrong context escaping: esc_html() in attributes, esc_attr() in HTML content 5. Stored XSS: $_POST → update_option() → get_option() → echo (no escaping) **Sources:** $_GET, $_POST, $_REQUEST, $_COOKIE, $_SERVER vars, get_option(), add_query_arg(), block $attributes, shortcode $atts **Sinks:** echo, print, printf(), return (in callbacks), wp_add_inline_script() **Safe:** esc_attr() (attributes), esc_html() (content), esc_url() (URLs), intval() (numbers) **Workflow:** Grep sources → Grep sinks → Read code paths → Verify context-appropriate escaping **Reference:** See references/detection-patterns.md (XSS section) for comprehensive patterns. **Report:** File:line, code snippet, severity, explanation (include 5-10 lines of surrounding context) ``` **Task call:** ``` Task tool with: - subagent_type: "general-purpose" - description: "XSS vulnerability detection" - prompt: [above prompt with AUDIT_SCOPE substituted] ``` #### Subagent 2: SQL Injection Detection **Prompt:** ``` Search for SQL Injection vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns:** 1. User input in $wpdb->query() without prepare() → Direct SQLi 2. User input in $wpdb->prepare() FIRST argument → Structure injection 3. esc_sql() used alone → INSUFFICIENT (still vulnerable) 4. ORDER BY with user input → Column name injection 5. String concatenation in queries → No parameterization **Sources:** $_GET, $_POST, $_REQUEST, $_COOKIE, shortcode $atts, block $attributes **Sinks:** $wpdb->query(), $wpdb->get_var/row/col/results(), $wpdb->prepare() first arg **Safe:** $wpdb->prepare() with %d/%s/%f placeholders, intval(), absint(), sanitize_key() **Workflow:** Grep $wpdb methods → Read query construction → Verify prepare() usage or type casting **Reference:** See references/detection-patterns.md (SQLi section) for comprehensive patterns. **Report:** File:line, code snippet, severity, explanation (include surrounding context) ``` #### Subagent 3: CSRF Detection **Prompt:** ``` Search for CSRF vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns:** 1. HIGH-IMPACT action without wp_verify_nonce() or check_ajax_referer() → CSRF 2. Inverted check: if (wp_verify_nonce(...)) { wp_die(); } → Action runs when INVALID 3. Flawed logic: empty($nonce) && !wp_verify_nonce() → Bypassed if not provided 4. Nonce checked but doesn't prevent execution (no die/return) 5. process_bulk_action() without nonce verification **HIGH-IMPACT Sensitive Actions (REPORT THESE):** - update_option(), delete_option() → Site configuration changes - wp_delete_user(), wp_insert_user(), wp_update_user() → User management - wp_delete_post(), wp_insert_post(), wp_update_post() → Content deletion/modification - File operations: unlink(), file_put_contents(), copy(), move_uploaded_file() - Database modifications: $wpdb->query(), $wpdb->update(), $wpdb->delete() - Plugin/theme installation/deletion - Bulk actions on posts, users, or settings **LOW-IMPACT Actions (DO NOT REPORT - even without nonces):** - Dismissing admin notices (e.g., update_option('notice_dismissed')) - Saving UI preferences (sidebar collapsed, screen options) - User meta updates for preferences (e.g., closedpostboxes, metaboxhidden) - Marking tours/tooltips as seen - Non-destructive state toggles **Safe:** wp_verify_nonce() with proper conditional, check_ajax_referer(), die() on failure **IMPORTANT FILTER RULES:** - ✅ REPORT: High-impact action with NO nonce OR flawed nonce logic - ❌ DO NOT REPORT: Proper wp_verify_nonce() present (even on GET requests) - ❌ DO NOT REPORT: Low-impact actions like dismissing notices - ❌ DO NOT REPORT: Actions already protected by current_user_can() capability checks alone (capability checks provide some CSRF protection via cookies) **Workflow:** Grep sensitive actions → Read handlers → Verify action impact → Check nonce logic → Only report if HIGH-IMPACT and flawed/missing nonce **Reference:** See references/detection-patterns.md (CSRF section) for comprehensive patterns. **Report:** File:line, code snippet, severity, explanation (include surrounding context) ``` #### Subagent 4: Open Redirect Detection **Prompt:** ``` Search for Open Redirect vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns:** 1. wp_redirect($_GET['redirect_to']) → User-controlled redirect 2. wp_redirect(esc_url($user_input)) → esc_url() does NOT prevent open redirect 3. Missing wp_safe_redirect() or allowlist validation **Sources:** $_GET['redirect'], $_GET['redirect_to'], $_GET['url'], $_GET['return_url'] **Sink:** wp_redirect() with user-controlled URL **Safe:** wp_safe_redirect() (validates same domain), URL allowlist **Workflow:** Grep "wp_redirect" → Read to trace first argument → Check for user control **Reference:** See references/detection-patterns.md (Open Redirect section). **Report:** File:line, code snippet, severity, explanation (include context) ``` #### Subagent 5: SSRF Detection **Prompt:** ``` Search for SSRF vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns:** 1. wp_remote_get($_GET['url']) → User-controlled URL (internal network access) 2. esc_url() does NOT prevent SSRF 3. Missing domain allowlist or IP validation 4. Can access: localhost, 192.168.x.x, 169.254.169.254 (AWS metadata) **Sources:** $_GET['url'], $_GET['endpoint'], $_GET['api_url'] **Sinks:** wp_remote_post/get/head/request(), get_headers() **Safe:** Domain allowlist, parse_url() + allowlist, reject private IPs **Workflow:** Grep wp_remote_* → Read URL parameter → Check for user control and validation **Reference:** See references/detection-patterns.md (SSRF section). **Report:** File:line, code snippet, severity (High), explanation (include context) ``` #### Subagent 6: LFI Detection **Prompt:** ``` Search for LFI vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns:** 1. include($_GET['file']) → Direct file inclusion 2. Path traversal: include('templates/' . $_GET['template']) → Can use ../../../ 3. Missing validate_file(), sanitize_file_name(), or allowlist 4. Can read: wp-config.php, /etc/passwd via path traversal **Sources:** $_GET['file'], $_GET['page'], $_GET['template'], $_GET['view'] **Sinks:** include/require/include_once/require_once(), comments_template() **Safe:** validate_file() (returns 0 if safe), sanitize_key(), allowlist with in_array() **Note:** $_GET['page'] in admin usually safe (WP validates), but audit direct access **Workflow:** Grep include/require → Read path argument → Check user control and validation **Reference:** See references/detection-patterns.md (LFI section). **Report:** File:line, code snippet, severity (Critical), explanation (include context) ``` #### Subagent 7: Object Injection Detection **Prompt:** ``` Search for Object Injection vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns:** 1. unserialize($_COOKIE['data']) → User-controlled deserialization 2. Missing ['allowed_classes' => false] option 3. Data through base64_decode still tainted 4. Requires POP chain (classes with __destruct, __wakeup, __toString) for exploitation **Sources:** $_GET, $_POST, $_REQUEST, $_COOKIE, $_FILES **Sink:** unserialize() with user-controlled data **Safe:** unserialize($data, ['allowed_classes' => false]), or use json_decode() instead **Workflow:** Grep "unserialize" → Read argument → Check user control and allowed_classes option **Reference:** See references/detection-patterns.md (Object Injection section). **Report:** File:line, code snippet, severity (High if POP chains exist), explanation (include context) ``` #### Subagent 8: Command Injection Detection **Prompt:** ``` Search for Command Injection vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns:** 1. system('ping ' . $_GET['host']) → Direct command injection 2. Injection via: ; cat /etc/passwd, | whoami, && id 3. Missing escapeshellarg() or allowlist 4. eval($_POST['code']) → Direct code execution **Sources:** $_GET, $_POST, $_REQUEST, $_COOKIE, $_SERVER **Sinks:** system(), exec(), passthru(), shell_exec(), assert(), eval() **Safe:** escapeshellarg() (single arg), escapeshellcmd() (full command, less safe), allowlist **Workflow:** Grep system/exec/eval → Read command argument → Check user control and escaping **Reference:** See references/detection-patterns.md (Command Injection section). **Report:** File:line, code snippet, severity (Critical - RCE), explanation (include context) ``` #### Subagent 9: Auth Bypass & Options Manipulation Detection **Prompt:** ``` Search for Auth Bypass and Options Manipulation vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns - Auth Bypass:** 1. wp_set_auth_cookie($_GET['user_id']) → Authenticate as any user 2. register_rest_route with permission_callback => __return_true → Public access 3. permission_callback returns non-boolean → Can be bypassed 4. Missing current_user_can() before admin actions **Critical Patterns - Options Manipulation:**
View on GitHub
This SKILL.md is very large, so SkillsMP previews the first section here. View on GitHub