php-pro
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and implement PHP code based on user-provided architecture and requirements. This creates a surface for indirect prompt injection if the processed source code or dependency manifests contain malicious instructions.\n
- Ingestion points: Project architecture review and implementation tasks defined in
SKILL.md.\n - Boundary markers: The skill lacks explicit instructions to ignore embedded instructions within processed source code.\n
- Capability inventory: The skill utilizes development tools (
phpstan,phpunit,pest) via thevendor/bin/directory.\n - Sanitization: There are no explicit sanitization steps for input data before it is processed by the agent.
Audit Metadata