php-open-redirect-audit
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PHP source code which could contain malicious instructions embedded in comments or string literals designed to manipulate the audit result or agent behavior.
- Ingestion points: PHP source code files being audited (SKILL.md).
- Boundary markers: None defined; the agent processes raw code files.
- Capability inventory: File system write access for report generation in {output_path}/vuln_audit/.
- Sanitization: None specified for the source code input prior to analysis.
Audit Metadata