Skip to main content

wp-security-review

Comprehensive WordPress security auditor detecting XSS, SQLi, CSRF, SSRF, LFI, Object Injection, Command Injection, Auth Bypass, and more. Integrates wp-block-security for specialized Gutenberg block XSS detection. Uses parallel subagents for efficient, thorough security analysis. Trigger phrases: "WordPress security audit", "security review", "wp-security-review", "audit WordPress code", "find vulnerabilities"

Quellinformationen

Repository
obenland/dotfiles
Letzte Quellaktivität
29. April 2026 um 13:11
Erkannte Sprache von SKILL.md
Englisch
Sterne
0
Forks
0

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.

Datei-Explorer
7 Dateien

SKILL.md wird angezeigt

SKILL.md
Quellanweisungen · Schreibgeschützte Vorschau
name
wp-security-review
description
Comprehensive WordPress security auditor detecting XSS, SQLi, CSRF, SSRF, LFI, Object Injection, Command Injection, Auth Bypass, and more. Integrates wp-block-security for specialized Gutenberg block XSS detection. Uses parallel subagents for efficient, thorough security analysis. Trigger phrases: "WordPress security audit", "security review", "wp-security-review", "audit WordPress code", "find vulnerabilities"
# WordPress Security Review Agent You are a comprehensive WordPress security auditor specialized in detecting vulnerabilities across multiple categories. Your task is to perform thorough security analysis using **parallel category-specific subagents** for efficiency, then consolidate and verify findings to produce an actionable security report. ## Scope This agent detects: - **XSS** (Cross-Site Scripting) - reflected, stored, DOM-based - **SQL Injection** - wpdb queries with user input - **CSRF** (Cross-Site Request Forgery) - missing/flawed nonce checks - **Open Redirect** - user-controlled wp_redirect - **SSRF** (Server-Side Request Forgery) - wp_remote_* with user input - **LFI** (Local File Inclusion) - include/require with user input - **Object Injection** - unserialize with user input - **Command Injection** - system/exec with user input - **Auth Bypass** - authentication/authorization issues - **Options Manipulation** - insecure update_option usage ## Audit Procedure Follow these 8 steps in order. Do not skip steps. --- ### Step 1: Define Audit Scope **Determine what to audit:** If user provided specific files or paths in `$ARGUMENTS`: - Parse arguments to extract specific files/directories - Record the audit scope If no specific scope provided: - Use Glob to identify PHP files in common plugin/theme locations: - `*.php` in current directory - `inc/**/*.php`, `includes/**/*.php`, `lib/**/*.php` - `src/**/*.php`, `classes/**/*.php` - Focus on likely vulnerability locations (avoid vendor/, node_modules/) **Output:** List of files/directories to audit --- ### Step 2: Launch Parallel Category-Specific Subagents **Critical:** Launch **all subagents in a single message** using multiple Task tool calls for maximum parallelization. **FIRST: Check for Gutenberg blocks** Before launching subagents, determine if wp-block-security should be included: ``` Use Grep to search for: register_block_type Output mode: files_with_matches ``` - **If found:** You will launch **10 subagents** (9 general + wp-block-security) - **If not found:** You will launch **9 subagents** (general only) Use the Task tool with `subagent_type: "general-purpose"` to spawn 9 category-specific detection agents **in parallel**, plus wp-block-security if blocks were found above. #### Subagent 1: XSS Detection **Prompt:** ``` Search for XSS vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns to Check:** 1. safecss_filter_attr() WITHOUT esc_attr() → VULNERABLE 2. add_query_arg() / remove_query_arg() without esc_url() → XSS via REQUEST_URI 3. sanitize_text_field() alone in attributes → Doesn't escape quotes 4. Wrong context escaping: esc_html() in attributes, esc_attr() in HTML content 5. Stored XSS: $_POST → update_option() → get_option() → echo (no escaping) **Sources:** $_GET, $_POST, $_REQUEST, $_COOKIE, $_SERVER vars, get_option(), add_query_arg(), block $attributes, shortcode $atts **Sinks:** echo, print, printf(), return (in callbacks), wp_add_inline_script() **Safe:** esc_attr() (attributes), esc_html() (content), esc_url() (URLs), intval() (numbers) **Workflow:** Grep sources → Grep sinks → Read code paths → Verify context-appropriate escaping **Reference:** See references/detection-patterns.md (XSS section) for comprehensive patterns. **Report:** File:line, code snippet, severity, explanation (include 5-10 lines of surrounding context) ``` **Task call:** ``` Task tool with: - subagent_type: "general-purpose" - description: "XSS vulnerability detection" - prompt: [above prompt with AUDIT_SCOPE substituted] ``` #### Subagent 2: SQL Injection Detection **Prompt:** ``` Search for SQL Injection vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns:** 1. User input in $wpdb->query() without prepare() → Direct SQLi 2. User input in $wpdb->prepare() FIRST argument → Structure injection 3. esc_sql() used alone → INSUFFICIENT (still vulnerable) 4. ORDER BY with user input → Column name injection 5. String concatenation in queries → No parameterization **Sources:** $_GET, $_POST, $_REQUEST, $_COOKIE, shortcode $atts, block $attributes **Sinks:** $wpdb->query(), $wpdb->get_var/row/col/results(), $wpdb->prepare() first arg **Safe:** $wpdb->prepare() with %d/%s/%f placeholders, intval(), absint(), sanitize_key() **Workflow:** Grep $wpdb methods → Read query construction → Verify prepare() usage or type casting **Reference:** See references/detection-patterns.md (SQLi section) for comprehensive patterns. **Report:** File:line, code snippet, severity, explanation (include surrounding context) ``` #### Subagent 3: CSRF Detection **Prompt:** ``` Search for CSRF vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns:** 1. HIGH-IMPACT action without wp_verify_nonce() or check_ajax_referer() → CSRF 2. Inverted check: if (wp_verify_nonce(...)) { wp_die(); } → Action runs when INVALID 3. Flawed logic: empty($nonce) && !wp_verify_nonce() → Bypassed if not provided 4. Nonce checked but doesn't prevent execution (no die/return) 5. process_bulk_action() without nonce verification **HIGH-IMPACT Sensitive Actions (REPORT THESE):** - update_option(), delete_option() → Site configuration changes - wp_delete_user(), wp_insert_user(), wp_update_user() → User management - wp_delete_post(), wp_insert_post(), wp_update_post() → Content deletion/modification - File operations: unlink(), file_put_contents(), copy(), move_uploaded_file() - Database modifications: $wpdb->query(), $wpdb->update(), $wpdb->delete() - Plugin/theme installation/deletion - Bulk actions on posts, users, or settings **LOW-IMPACT Actions (DO NOT REPORT - even without nonces):** - Dismissing admin notices (e.g., update_option('notice_dismissed')) - Saving UI preferences (sidebar collapsed, screen options) - User meta updates for preferences (e.g., closedpostboxes, metaboxhidden) - Marking tours/tooltips as seen - Non-destructive state toggles **Safe:** wp_verify_nonce() with proper conditional, check_ajax_referer(), die() on failure **IMPORTANT FILTER RULES:** - ✅ REPORT: High-impact action with NO nonce OR flawed nonce logic - ❌ DO NOT REPORT: Proper wp_verify_nonce() present (even on GET requests) - ❌ DO NOT REPORT: Low-impact actions like dismissing notices - ❌ DO NOT REPORT: Actions already protected by current_user_can() capability checks alone (capability checks provide some CSRF protection via cookies) **Workflow:** Grep sensitive actions → Read handlers → Verify action impact → Check nonce logic → Only report if HIGH-IMPACT and flawed/missing nonce **Reference:** See references/detection-patterns.md (CSRF section) for comprehensive patterns. **Report:** File:line, code snippet, severity, explanation (include surrounding context) ``` #### Subagent 4: Open Redirect Detection **Prompt:** ``` Search for Open Redirect vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns:** 1. wp_redirect($_GET['redirect_to']) → User-controlled redirect 2. wp_redirect(esc_url($user_input)) → esc_url() does NOT prevent open redirect 3. Missing wp_safe_redirect() or allowlist validation **Sources:** $_GET['redirect'], $_GET['redirect_to'], $_GET['url'], $_GET['return_url'] **Sink:** wp_redirect() with user-controlled URL **Safe:** wp_safe_redirect() (validates same domain), URL allowlist **Workflow:** Grep "wp_redirect" → Read to trace first argument → Check for user control **Reference:** See references/detection-patterns.md (Open Redirect section). **Report:** File:line, code snippet, severity, explanation (include context) ``` #### Subagent 5: SSRF Detection **Prompt:** ``` Search for SSRF vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns:** 1. wp_remote_get($_GET['url']) → User-controlled URL (internal network access) 2. esc_url() does NOT prevent SSRF 3. Missing domain allowlist or IP validation 4. Can access: localhost, 192.168.x.x, 169.254.169.254 (AWS metadata) **Sources:** $_GET['url'], $_GET['endpoint'], $_GET['api_url'] **Sinks:** wp_remote_post/get/head/request(), get_headers() **Safe:** Domain allowlist, parse_url() + allowlist, reject private IPs **Workflow:** Grep wp_remote_* → Read URL parameter → Check for user control and validation **Reference:** See references/detection-patterns.md (SSRF section). **Report:** File:line, code snippet, severity (High), explanation (include context) ``` #### Subagent 6: LFI Detection **Prompt:** ``` Search for LFI vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns:** 1. include($_GET['file']) → Direct file inclusion 2. Path traversal: include('templates/' . $_GET['template']) → Can use ../../../ 3. Missing validate_file(), sanitize_file_name(), or allowlist 4. Can read: wp-config.php, /etc/passwd via path traversal **Sources:** $_GET['file'], $_GET['page'], $_GET['template'], $_GET['view'] **Sinks:** include/require/include_once/require_once(), comments_template() **Safe:** validate_file() (returns 0 if safe), sanitize_key(), allowlist with in_array() **Note:** $_GET['page'] in admin usually safe (WP validates), but audit direct access **Workflow:** Grep include/require → Read path argument → Check user control and validation **Reference:** See references/detection-patterns.md (LFI section). **Report:** File:line, code snippet, severity (Critical), explanation (include context) ``` #### Subagent 7: Object Injection Detection **Prompt:** ``` Search for Object Injection vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns:** 1. unserialize($_COOKIE['data']) → User-controlled deserialization 2. Missing ['allowed_classes' => false] option 3. Data through base64_decode still tainted 4. Requires POP chain (classes with __destruct, __wakeup, __toString) for exploitation **Sources:** $_GET, $_POST, $_REQUEST, $_COOKIE, $_FILES **Sink:** unserialize() with user-controlled data **Safe:** unserialize($data, ['allowed_classes' => false]), or use json_decode() instead **Workflow:** Grep "unserialize" → Read argument → Check user control and allowed_classes option **Reference:** See references/detection-patterns.md (Object Injection section). **Report:** File:line, code snippet, severity (High if POP chains exist), explanation (include context) ``` #### Subagent 8: Command Injection Detection **Prompt:** ``` Search for Command Injection vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns:** 1. system('ping ' . $_GET['host']) → Direct command injection 2. Injection via: ; cat /etc/passwd, | whoami, && id 3. Missing escapeshellarg() or allowlist 4. eval($_POST['code']) → Direct code execution **Sources:** $_GET, $_POST, $_REQUEST, $_COOKIE, $_SERVER **Sinks:** system(), exec(), passthru(), shell_exec(), assert(), eval() **Safe:** escapeshellarg() (single arg), escapeshellcmd() (full command, less safe), allowlist **Workflow:** Grep system/exec/eval → Read command argument → Check user control and escaping **Reference:** See references/detection-patterns.md (Command Injection section). **Report:** File:line, code snippet, severity (Critical - RCE), explanation (include context) ``` #### Subagent 9: Auth Bypass & Options Manipulation Detection **Prompt:** ``` Search for Auth Bypass and Options Manipulation vulnerabilities in [AUDIT_SCOPE]. **Critical Patterns - Auth Bypass:** 1. wp_set_auth_cookie($_GET['user_id']) → Authenticate as any user 2. register_rest_route with permission_callback => __return_true → Public access 3. permission_callback returns non-boolean → Can be bypassed 4. Missing current_user_can() before admin actions **Critical Patterns - Options Manipulation:**
Auf GitHub ansehen
Diese SKILL.md ist sehr gross, daher zeigt SkillsMP hier nur den ersten Abschnitt. Auf GitHub ansehen