laravel-verification

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes multiple local shell commands using standard development tools including php, composer, and Laravel-specific binaries like php artisan, pint, phpstan, and psalm to perform linting, testing, and environment checks.
  • [DYNAMIC_EXECUTION]: The skill uses php artisan tinker --execute to run arbitrary PHP code strings via the command line, specifically for dispatching health check jobs to the queue.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external project sources such as the .env file, composer audit logs, and test output results. This untrusted data is interpolated into the agent's context without explicit boundary markers or sanitization, presenting a surface where malicious project content could influence agent behavior.
  • Ingestion points: System command outputs from .env, composer audit, php artisan test, and php artisan schedule:list (SKILL.md).
  • Boundary markers: None present.
  • Capability inventory: Extensive shell command execution (php artisan, composer) and dynamic PHP execution via tinker.
  • Sanitization: None present.
  • [DATA_EXFILTRATION]: The skill contains instructions to access the .env file to verify configuration keys and check APP_DEBUG/APP_ENV values. While this is a standard security verification practice for Laravel, it involves reading sensitive configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — laravel-verification