php-crypto-audit
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted PHP source code for cryptographic issues, which creates a surface for indirect prompt injection. Malicious instructions hidden within the source code files could attempt to influence or override the agent's behavior. * Ingestion points: The skill processes user-provided PHP source code files (SKILL.md). * Boundary markers: The instructions do not specify the use of delimiters or provide warnings to ignore embedded instructions in the analyzed files. * Capability inventory: The skill instructs the agent to write audit reports to the filesystem at a specified output path. * Sanitization: There is no mention of sanitizing or escaping the content of the analyzed files before they are processed by the agent.
- [NO_CODE]: The skill consists entirely of markdown instructions in the SKILL.md file and does not include any executable scripts or binary files.
Audit Metadata