ci3-rest-api
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for handling external API requests, creating a data ingestion surface. (1) Ingestion points: API request bodies and query parameters processed in controller methods. (2) Boundary markers: Authentication gates and structured validation rules. (3) Capability inventory: Database interaction through the CodeIgniter Query Builder. (4) Sanitization: Explicit instructions for using the xss_clean validation rule and field whitelisting (_filter_allowed) to prevent mass-assignment.
- [EXTERNAL_DOWNLOADS]: The documentation references the installation of standard PHP libraries chriskacerguis/codeigniter-restserver and firebase/php-jwt via Composer. These are well-established libraries for the target stack and are used for their intended purpose.
Audit Metadata