laravel-security
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and generate application logic and configuration based on developer requirements, creating a potential surface for indirect injection if the input content contains malicious instructions.
- Ingestion points: Processes user-provided code snippets, environment variables, and application configuration files in SKILL.md.
- Boundary markers: Recommends the use of Laravel's built-in validation rules, CSRF protection, and Blade escaping directives to maintain boundaries between data and logic.
- Capability inventory: Performs database query construction (Eloquent), configuration file management, and authentication logic definition.
- Sanitization: Strongly promotes the use of safe Blade templating, HTMLPurifier, and input validation to filter untrusted content.
Audit Metadata