drupal-security
Pass
Audited by Gen Agent Trust Hub on Apr 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is entirely educational and defensive, providing best practices for Drupal development.
- [SAFE]: No malicious patterns or behaviors such as prompt injection, data exfiltration, or unauthorized command execution were detected in the instructions.
- [SAFE]: External references are limited to official documentation from trusted organizations such as Drupal.org and OWASP.
- [SAFE]: The skill explicitly advises against security risks such as hardcoding secrets, logging sensitive data, and using unsafe PHP functions like unserialize() or eval().
- [SAFE]: Indirect prompt injection analysis: untrusted data enters the agent context via user-provided Drupal code for auditing; no explicit boundary markers are defined; the skill lacks dangerous capabilities such as subprocess execution, network operations, or file system writes; sanitization is not applicable as the input is not executed.
Audit Metadata