php-crypto-audit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted PHP source code for cryptographic issues, which creates a surface for indirect prompt injection. Malicious instructions hidden within the source code files could attempt to influence or override the agent's behavior. * Ingestion points: The skill processes user-provided PHP source code files (SKILL.md). * Boundary markers: The instructions do not specify the use of delimiters or provide warnings to ignore embedded instructions in the analyzed files. * Capability inventory: The skill instructs the agent to write audit reports to the filesystem at a specified output path. * Sanitization: There is no mention of sanitizing or escaping the content of the analyzed files before they are processed by the agent.
  • [NO_CODE]: The skill consists entirely of markdown instructions in the SKILL.md file and does not include any executable scripts or binary files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:00 AM
Security Audit — agent-trust-hub — php-crypto-audit