php-logic-audit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PHP source code, creating a surface for indirect prompt injection where instructions embedded in code comments or strings could influence the agent's behavior.
  • Ingestion points: PHP source code files (controllers, services, callback handlers) as specified in the audit requirements.
  • Boundary markers: Absent. The skill does not instruct the agent to use delimiters or specific ignore-rules for instructions found within the audited content.
  • Capability inventory: The agent reads project files to perform the audit and writes findings to a local markdown file.
  • Sanitization: Absent. There are no instructions to sanitize or validate the content of the source code before it is processed or included in the final audit report.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:59 AM
Security Audit — agent-trust-hub — php-logic-audit