php-xxe-audit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze PHP source code, which is untrusted external data. Maliciously crafted source code (e.g., containing specific comments, variable names, or complex structures) could attempt to influence the agent's audit logic or results.
  • Ingestion points: The agent processes PHP project source code to identify XML parsing points and data flow.
  • Boundary markers: The instructions do not specify any delimiters or explicit boundary markers to separate the untrusted source code from the agent's internal instructions.
  • Capability inventory: The skill allows the agent to read source files and write findings to a report file at a dynamic path ({output_path}/vuln_audit/xxe_{timestamp}.md).
  • Sanitization: No specific sanitization or validation logic is defined to prevent instructions embedded within the analyzed code from affecting the agent's behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:59 AM
Security Audit — agent-trust-hub — php-xxe-audit