php-modernization

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on executing various PHP toolchain binaries (such as php, composer, phpstan, rector, php-cs-fixer, and infection) via Python and Bash scripts to perform project introspection and modernization tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes several llm_review checkpoints in checkpoints.yaml that instruct the agent to analyze PHP source code. This represents a potential attack surface if the ingested code contains malicious instructions intended to influence the agent's behavior.
  • Ingestion points: PHP source files (e.g., in src/ and Classes/ directories), composer.json, composer.lock, and various tool configuration files (e.g., phpstan.neon, rector.php) are read by the introspect.py, verify_php_project.py, and modernize_loop.py scripts.
  • Boundary markers: The review prompts defined in checkpoints.yaml (e.g., PM-20, PM-34) lack explicit delimiters or instructions to ignore embedded commands within the analyzed code snippets, which may lead to accidental obedience by the agent.
  • Capability inventory: The skill possesses significant capabilities, including executing shell commands via subprocess.run and writing files to the project directory.
  • Sanitization: External content is not sanitized or escaped before being presented to the agent for review, facilitating the potential for injection.
  • [DYNAMIC_EXECUTION]: The modernize_loop.py and verify_php_project.py scripts dynamically locate and execute binaries within the target project's vendor/bin and .Build/bin directories, depending on the project's archetype and configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 12:20 PM
Security Audit — agent-trust-hub — php-modernization