php-nosql-audit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted PHP source code, which creates a surface for indirect prompt injection. If the code being audited contains malicious instructions disguised as comments or data, the agent could potentially be manipulated.
  • Ingestion points: PHP project source code provided to the agent for auditing.
  • Boundary markers: None. The skill does not define specific delimiters or instructions to treat the analyzed code as data only, increasing the risk that the agent may follow instructions embedded within the source code.
  • Capability inventory: The skill writes vulnerability reports to the local file system at {output_path}/vuln_audit/.
  • Sanitization: There are no documented sanitization or validation steps for the input source code before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:59 AM
Security Audit — agent-trust-hub — php-nosql-audit