php-pro

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and implement PHP code based on user-provided architecture and requirements. This creates a surface for indirect prompt injection if the processed source code or dependency manifests contain malicious instructions.\n
  • Ingestion points: Project architecture review and implementation tasks defined in SKILL.md.\n
  • Boundary markers: The skill lacks explicit instructions to ignore embedded instructions within processed source code.\n
  • Capability inventory: The skill utilizes development tools (phpstan, phpunit, pest) via the vendor/bin/ directory.\n
  • Sanitization: There are no explicit sanitization steps for input data before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:19 PM
Security Audit — agent-trust-hub — php-pro