drupal-security

Pass

Audited by Gen Agent Trust Hub on Apr 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is entirely educational and defensive, providing best practices for Drupal development.
  • [SAFE]: No malicious patterns or behaviors such as prompt injection, data exfiltration, or unauthorized command execution were detected in the instructions.
  • [SAFE]: External references are limited to official documentation from trusted organizations such as Drupal.org and OWASP.
  • [SAFE]: The skill explicitly advises against security risks such as hardcoding secrets, logging sensitive data, and using unsafe PHP functions like unserialize() or eval().
  • [SAFE]: Indirect prompt injection analysis: untrusted data enters the agent context via user-provided Drupal code for auditing; no explicit boundary markers are defined; the skill lacks dangerous capabilities such as subprocess execution, network operations, or file system writes; sanitization is not applicable as the input is not executed.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 17, 2026, 10:42 AM
Security Audit — agent-trust-hub — drupal-security