Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/morodomi/dev-crew/wordpress-attackergit clone --depth 1 https://github.com/morodomi/dev-crewWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00036 | $0.01557 |
| Opus 5 | $0.00018 | $0.00779 |
| Sonnet 5 | $0.00007 | $0.00311 |
| Haiku 4.5 | $0.00004 | $0.00156 |
Grade A, and why
wordpress-attacker scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 135 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Detection Targets
| Category | Type | Description |
|---|---|---|
| wp-sqli | SQL Injection | $wpdb without prepare |
| wp-xss | Cross-site Scripting | echo $_GET/$_POST without escaping |
| wp-lfi | Local File Inclusion | include/require with user input |
| wp-privilege | Privilege Escalation | Missing current_user_can check |
| wp-config | Misconfiguration | WP_DEBUG enabled, weak keys |
| wp-rest-api | Broken Access Control | Missing permission_callback |
| wp-xmlrpc | Misconfiguration | XML-RPC without restriction |
| wp-user-enum | Information Exposure | User enumeration via REST/feed |
| wp-deserialize | Object Injection | Unsafe unserialize with user input |
Framework Detection Patterns
| Context | Vulnerable Pattern | Safe Pattern |
|---|---|---|
| Database | $wpdb->query("...$var") |
$wpdb->prepare("...%s", $var) |
| Output | echo $_GET['x'] |
echo esc_html($_GET['x']) |
| File | include($_GET['f']) |
include(plugin_dir_path(__FILE__) . 'file.php') |
| AJAX | add_action('wp_ajax_x', 'fn') without check |
if (!current_user_can('edit_posts')) wp_die() |
| REST API | 'permission_callback' => '__return_true' |
'permission_callback' => function() { return current_user_can('edit_posts'); } |
Dangerous Patterns
patterns:
# SQL Injection ($wpdb) - direct query with variable interpolation
- '\$wpdb->query\s*\(\s*["\'].*\$'
- '\$wpdb->get_results\s*\(\s*["\'].*\$'
- '\$wpdb->get_row\s*\(\s*["\'].*\$'
- '\$wpdb->get_var\s*\(\s*["\'].*\$'
- '\$wpdb->(insert|update|delete)\s*\([^)]*\$_(GET|POST|REQUEST)'
- '\$wpdb->query\s*\([^)]*\$_(GET|POST|REQUEST)'
# XSS - direct echo/print of user input
- '(echo|print)\s+\$_(GET|POST|REQUEST)\s*\['
- 'printf\s*\([^)]*\$_(GET|POST)'
# LFI - include/require with user input
- '(include|include_once|require|require_once)\s*\(\s*\$_(GET|POST)'
# Privilege Escalation - AJAX/admin handlers without capability check
- 'add_action\s*\(\s*["\']wp_ajax_(nopriv_)?'
- 'admin_post_'
# REST API - insecure permission callbacks
- 'permission_callback.*__return_true'
- "permission_callback.*=>\\s*['\"]?true"
- 'register_rest_route\s*\(' # context check for permission_callback presence
# wp-config.php Misconfiguration
- "define\\s*\\(\\s*['\"]WP_DEBUG(_LOG|_DISPLAY)?['\"]\\s*,\\s*true\\s*\\)"
- "define\\s*\\(\\s*['\"]DISALLOW_FILE_EDIT['\"]\\s*,\\s*false\\s*\\)"
- "\\$table_prefix\\s*=\\s*['\"]wp_['\"]"
# XML-RPC
- 'xmlrpc_enabled.*true'
- 'add_filter.*xmlrpc_enabled.*__return_true'
- 'xmlrpc\.php'
# User Enumeration
- 'register_rest_route.*users'
- '/wp-json/wp/v2/users'
- 'author_rewrite_rules'
- '\?author='
- 'wp_login_failed.*\$_'
# Object Injection (Deserialization)
- '(maybe_)?unserialize\s*\(\s*\$_(GET|POST|REQUEST|COOKIE)'
- 'unserialize\s*\(\s*base64_decode'
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 135 lines · 36 tokens per session scan A 05fea4555ba0
wordpress-attacker is an agent published in the GitHub repository morodomi/dev-crew (1 stars, last pushed 3d ago), licensed MIT. It adds 36 tokens to every session and 1,557 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
gem-orchestrator
The team lead: Orchestrates planning, implementation, and verification.
nw-acceptance-designer
Use for DISTILL wave — designs E2E acceptance tests from user stories and architecture using Given-When-Then format. EXPANDED scope (plan v3 §3.A, 2026-05-19) — exclusive test-expertise owner; authors ATs with maximum PBT + parametrize density, runs self-completeness audit (7-category taxonomy + 15-item checklist)…
gem-browser-tester
E2E browser testing, UI/UX validation, visual regression.
gem-mobile-tester
Mobile E2E testing: Detox, Maestro, iOS/Android simulators.
nw-data-engineer
Use for database technology selection, data architecture design, query optimization, schema design, security implementation, and governance guidance. Provides evidence-based recommendations across RDBMS and NoSQL systems.
nw-ddd-architect
Use for DESIGN wave domain modeling. Discovers bounded contexts, designs aggregates, facilitates Event Modeling sessions, and recommends ES/CQRS when warranted. Writes to architecture SSOT.