php-yii-audit
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns or behaviors were identified in the skill. The content consists of legitimate instructions for a security auditing tool focusing on the PHP Yii2 framework.
- [INDIRECT_PROMPT_INJECTION]: The skill operates on user-provided source code via the source_path parameter, creating an ingestion surface for indirect prompt injection. However, this is expected behavior for a static analysis tool. Ingestion points: Local file system paths provided via source_path in SKILL.md. Boundary markers: Absent. Capability inventory: File system read access (implied for analysis). Sanitization: Absent. This surface is necessary for the skill's primary function and does not indicate malicious intent.
Audit Metadata