php-file-upload-audit
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted PHP source code, which serves as a potential vector for indirect prompt injection. A malicious codebase could include specially crafted comments or code structures intended to mislead the agent's analysis, suppress findings, or manipulate the generated report.
- Ingestion points: PHP source code files and trace evidence from external tools (
php-route-tracer). - Boundary markers: The instructions lack specific delimiters or instructions to treat the analyzed code as data rather than instructions.
- Capability inventory: The skill has the capability to write findings to the file system at a user-defined output path.
- Sanitization: No explicit sanitization or validation steps are defined for the input source code before it is processed by the agent.
Audit Metadata