symfony:tdd-with-pest

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the Bash tool for running standard PHP development commands, including composer for dependency management, ./vendor/bin/pest for test execution, and docker compose for containerized environments. These actions are strictly within the scope of a development workflow.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing well-known and widely used PHP testing libraries (pestphp/pest, zenstruck/foundry, pestphp/pest-plugin-drift) from the official PHP package registry via Composer. These downloads are legitimate and pose no risk when used as directed.
  • [SAFE]: No malicious patterns such as prompt injection, credential exfiltration, or code obfuscation were detected. The skill uses non-sensitive placeholders for examples and correctly warns against using non-existent or unofficial plugins, promoting safer coding practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 11:39 AM
Security Audit — agent-trust-hub — symfony:tdd-with-pest