dependency-management

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional, providing guidance, recipes, and best practices for managing PHP dependencies with the standard Composer tool.
  • [SAFE]: No executable scripts, subprocess calls, or remote code execution patterns are included in the skill. All commands (e.g., composer require, composer install) are provided as examples for the user or agent to follow manually.
  • [SAFE]: The skill explicitly includes security best practices, such as using composer audit to scan for vulnerabilities and avoiding composer update in production environments to prevent unreviewed code deployment.
  • [SAFE]: There are no signs of obfuscation, hardcoded credentials, data exfiltration, or persistence mechanisms. All external references are to standard documentation and related internal skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 04:16 PM
Security Audit — agent-trust-hub — dependency-management