php-xss-audit
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PHP source code as input for auditing, which presents a surface for instructions embedded in the code to influence the agent.
- Ingestion points: PHP project source code files analyzed by the agent (referenced in the audit instructions).
- Boundary markers: The instructions do not specify any delimiters or warnings to ignore instructions embedded within the source code.
- Capability inventory: The skill specifies writing audit reports to a local file system path ({output_path}/vuln_audit/xss_{timestamp}.md).
- Sanitization: No explicit sanitization or validation of the input source code is mentioned.
Audit Metadata