laravel-tdd

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill content is purely instructional, providing code snippets for model factories, HTTP testing, and mocking external services. No malicious patterns were detected.
  • [CREDENTIALS_UNSAFE]: The code examples use standard testing placeholders for passwords (e.g., 'password' hashed with Bcrypt) and environment variables for testing databases (sqlite in :memory:), which are secure and recommended practices for local testing environments.
  • [EXTERNAL_DOWNLOADS]: Mentions well-known and trusted services like Stripe for mocking purposes (api.stripe.com) and standard PHP package binaries (vendor/bin/phpunit, vendor/bin/pest). No unauthorized or suspicious remote downloads are present.
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates how to test authorization boundaries (e.g., assertForbidden) and validation, which helps prevent security vulnerabilities in the applications being developed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — laravel-tdd