security-testing

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate instructional content for implementing security testing in PHP applications using standard frameworks like Pest and PHPUnit.
  • [PROMPT_INJECTION]: No attempts to override agent behavior, bypass safety filters, or extract system prompts were detected. The instructions focus on creating test suites for application security.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials, API keys, or sensitive file paths were found. The skill actively promotes best practices by advising against using real production secrets or PII in security tests.
  • [EXTERNAL_DOWNLOADS]: The skill references well-known and standard industry tools such as composer audit, Psalm, PHPStan, and OWASP ZAP. These are trusted resources within the software development lifecycle and do not constitute a security risk.
  • [COMMAND_EXECUTION]: No suspicious or unauthorized command execution patterns were identified. Commands mentioned (e.g., composer audit) are part of standard development workflows described for the user's benefit.
  • [REMOTE_CODE_EXECUTION]: No patterns involving the download and execution of untrusted scripts or dynamic code generation from remote sources were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 04:16 PM
Security Audit — agent-trust-hub — security-testing