dependency-management
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely instructional, providing guidance, recipes, and best practices for managing PHP dependencies with the standard Composer tool.
- [SAFE]: No executable scripts, subprocess calls, or remote code execution patterns are included in the skill. All commands (e.g.,
composer require,composer install) are provided as examples for the user or agent to follow manually. - [SAFE]: The skill explicitly includes security best practices, such as using
composer auditto scan for vulnerabilities and avoidingcomposer updatein production environments to prevent unreviewed code deployment. - [SAFE]: There are no signs of obfuscation, hardcoded credentials, data exfiltration, or persistence mechanisms. All external references are to standard documentation and related internal skill files.
Audit Metadata