php-pro
Fail
Audited by Gen Agent Trust Hub on Mar 22, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The reference documentation contains hardcoded database credentials used in connection examples.
- Evidence: The file
references/async-patterns.mdcontains a configuration array with the values 'user' => 'root' and 'password' => 'password'. - Evidence: The file
references/async-patterns.mdincludes a hardcoded connection string 'root:password@localhost/database'. - [COMMAND_EXECUTION]: The skill requires the agent to execute local binary files for code analysis and testing purposes.
- Evidence: Instructions in
SKILL.mdexplicitly direct the agent to runvendor/bin/phpstan,vendor/bin/phpunit, andvendor/bin/pestvia shell commands. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing untrusted application code and executing capabilities on it.
- Ingestion points: PHP source files, composer configurations, and framework-specific YAML files.
- Boundary markers: Absent; there are no instructions for the agent to ignore or delimit embedded commands in processed code.
- Capability inventory: Shell execution of external binaries (
phpstan,phpunit,pest). - Sanitization: Absent; no validation of external code or configuration files before processing or execution.
Recommendations
- AI detected serious security threats
Audit Metadata