php-ldap-audit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze untrusted PHP source code and external route traces, which serves as a significant attack surface for indirect prompt injection. Malicious instructions could be hidden within the analyzed code's comments, strings, or metadata to influence the agent's audit logic or output.
  • Ingestion points: Untrusted PHP source code files, JSON-decoded data structures, and outputs from the php-route-tracer utility mentioned in SKILL.md.
  • Boundary markers: The skill does not specify the use of boundary markers or explicit instructions to treat code content as data only, which could lead the agent to follow instructions embedded within the code.
  • Capability inventory: The agent has the capability to generate detailed vulnerability reports and functional HTTP PoC payloads based on the untrusted input.
  • Sanitization: There is no mention of sanitizing, escaping, or validating the source code or tracer data before it is processed by the agent's reasoning context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:59 AM
Security Audit — agent-trust-hub — php-ldap-audit