laravel-tdd
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill content is purely instructional, providing code snippets for model factories, HTTP testing, and mocking external services. No malicious patterns were detected.
- [CREDENTIALS_UNSAFE]: The code examples use standard testing placeholders for passwords (e.g., 'password' hashed with Bcrypt) and environment variables for testing databases (
sqlitein:memory:), which are secure and recommended practices for local testing environments. - [EXTERNAL_DOWNLOADS]: Mentions well-known and trusted services like Stripe for mocking purposes (
api.stripe.com) and standard PHP package binaries (vendor/bin/phpunit,vendor/bin/pest). No unauthorized or suspicious remote downloads are present. - [INDIRECT_PROMPT_INJECTION]: The skill demonstrates how to test authorization boundaries (e.g.,
assertForbidden) and validation, which helps prevent security vulnerabilities in the applications being developed.
Audit Metadata