wp-phpstan

Pass

Audited by Gen Agent Trust Hub on Mar 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates entirely within the local development environment to assist with static analysis configuration. It does not perform network operations or access sensitive system credentials.
  • [COMMAND_EXECUTION]: The skill includes a local inspection script, scripts/phpstan_inspect.mjs, which reads project configuration files (composer.json, phpstan.neon) to provide the agent with context. It recommends running standard, well-known development tools such as composer and phpstan based on the discovered project structure.
  • [DATA_EXFILTRATION]: Analysis of the provided Node.js script confirms it only reads non-sensitive project configuration files. The script's output is restricted to standard output for the AI agent's internal use and does not transmit data to any external services.
  • [EXTERNAL_DOWNLOADS]: Documentation within the skill (references/third-party-classes.md) suggests the use of community-standard WordPress stub packages via Composer. These are established tools in the PHP/WordPress ecosystem used for type-checking and are recommended for local development installation by the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 22, 2026, 03:03 PM
Security Audit — agent-trust-hub — wp-phpstan