php-logic-audit
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PHP source code, creating a surface for indirect prompt injection where instructions embedded in code comments or strings could influence the agent's behavior.
- Ingestion points: PHP source code files (controllers, services, callback handlers) as specified in the audit requirements.
- Boundary markers: Absent. The skill does not instruct the agent to use delimiters or specific ignore-rules for instructions found within the audited content.
- Capability inventory: The agent reads project files to perform the audit and writes findings to a local markdown file.
- Sanitization: Absent. There are no instructions to sanitize or validate the content of the source code before it is processed or included in the final audit report.
Audit Metadata