php-file-upload-audit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted PHP source code, which serves as a potential vector for indirect prompt injection. A malicious codebase could include specially crafted comments or code structures intended to mislead the agent's analysis, suppress findings, or manipulate the generated report.
  • Ingestion points: PHP source code files and trace evidence from external tools (php-route-tracer).
  • Boundary markers: The instructions lack specific delimiters or instructions to treat the analyzed code as data rather than instructions.
  • Capability inventory: The skill has the capability to write findings to the file system at a user-defined output path.
  • Sanitization: No explicit sanitization or validation steps are defined for the input source code before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:59 AM
Security Audit — agent-trust-hub — php-file-upload-audit