wp-phpstan
Pass
Audited by Gen Agent Trust Hub on Mar 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates entirely within the local development environment to assist with static analysis configuration. It does not perform network operations or access sensitive system credentials.
- [COMMAND_EXECUTION]: The skill includes a local inspection script,
scripts/phpstan_inspect.mjs, which reads project configuration files (composer.json,phpstan.neon) to provide the agent with context. It recommends running standard, well-known development tools such ascomposerandphpstanbased on the discovered project structure. - [DATA_EXFILTRATION]: Analysis of the provided Node.js script confirms it only reads non-sensitive project configuration files. The script's output is restricted to standard output for the AI agent's internal use and does not transmit data to any external services.
- [EXTERNAL_DOWNLOADS]: Documentation within the skill (
references/third-party-classes.md) suggests the use of community-standard WordPress stub packages via Composer. These are established tools in the PHP/WordPress ecosystem used for type-checking and are recommended for local development installation by the user.
Audit Metadata