php-archive-extract-audit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external PHP source code, which represents untrusted data. This creates a surface for indirect prompt injection if the audited code contains malicious instructions or comments intended to manipulate the agent.
  • Ingestion points: PHP source files containing archive extraction logic (e.g., ZipArchive, PharData, Archive_Tar) in SKILL.md.
  • Boundary markers: The skill mandates a strict '漏洞条目模板' (Vulnerability Entry Template) for all output, which helps constrain the agent's responses.
  • Capability inventory: The agent is instructed to write findings to a specific directory structure ({output_path}/vuln_audit/) but does not have instructions to execute the audited code or perform network operations.
  • Sanitization: The skill relies on the structured reporting format to mitigate the risk of instruction override from the input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:59 AM
Security Audit — agent-trust-hub — php-archive-extract-audit