php-pro

Fail

Audited by Gen Agent Trust Hub on Mar 22, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The reference documentation contains hardcoded database credentials used in connection examples.
  • Evidence: The file references/async-patterns.md contains a configuration array with the values 'user' => 'root' and 'password' => 'password'.
  • Evidence: The file references/async-patterns.md includes a hardcoded connection string 'root:password@localhost/database'.
  • [COMMAND_EXECUTION]: The skill requires the agent to execute local binary files for code analysis and testing purposes.
  • Evidence: Instructions in SKILL.md explicitly direct the agent to run vendor/bin/phpstan, vendor/bin/phpunit, and vendor/bin/pest via shell commands.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing untrusted application code and executing capabilities on it.
  • Ingestion points: PHP source files, composer configurations, and framework-specific YAML files.
  • Boundary markers: Absent; there are no instructions for the agent to ignore or delimit embedded commands in processed code.
  • Capability inventory: Shell execution of external binaries (phpstan, phpunit, pest).
  • Sanitization: Absent; no validation of external code or configuration files before processing or execution.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 22, 2026, 03:03 PM
Security Audit — agent-trust-hub — php-pro