php-config-audit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions define a legitimate security auditing process for PHP applications, requiring evidence collection and exploitability analysis for identified configuration risks.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted external data in the form of project configuration files and environment variables, which is a characteristic of its primary auditing function.
  • Ingestion points: The skill instructions in SKILL.md specify reading potentially untrusted project configuration files like .env, php.ini, and config files.
  • Boundary markers: The instructions do not define specific delimiters or "ignore" markers for handling embedded instructions within the audited configuration data.
  • Capability inventory: The skill's identified capability is restricted to writing audit reports in markdown format to a specified local output path.
  • Sanitization: No explicit sanitization or input validation steps for the content of the processed configuration files are mentioned in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:59 AM
Security Audit — agent-trust-hub — php-config-audit