php-xss-audit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PHP source code as input for auditing, which presents a surface for instructions embedded in the code to influence the agent.
  • Ingestion points: PHP project source code files analyzed by the agent (referenced in the audit instructions).
  • Boundary markers: The instructions do not specify any delimiters or warnings to ignore instructions embedded within the source code.
  • Capability inventory: The skill specifies writing audit reports to a local file system path ({output_path}/vuln_audit/xss_{timestamp}.md).
  • Sanitization: No explicit sanitization or validation of the input source code is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:00 AM
Security Audit — agent-trust-hub — php-xss-audit