laravel-verification
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple local shell commands using standard development tools including
php,composer, and Laravel-specific binaries likephp artisan,pint,phpstan, andpsalmto perform linting, testing, and environment checks. - [DYNAMIC_EXECUTION]: The skill uses
php artisan tinker --executeto run arbitrary PHP code strings via the command line, specifically for dispatching health check jobs to the queue. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external project sources such as the
.envfile,composer auditlogs, and test output results. This untrusted data is interpolated into the agent's context without explicit boundary markers or sanitization, presenting a surface where malicious project content could influence agent behavior. - Ingestion points: System command outputs from
.env,composer audit,php artisan test, andphp artisan schedule:list(SKILL.md). - Boundary markers: None present.
- Capability inventory: Extensive shell command execution (
php artisan,composer) and dynamic PHP execution viatinker. - Sanitization: None present.
- [DATA_EXFILTRATION]: The skill contains instructions to access the
.envfile to verify configuration keys and checkAPP_DEBUG/APP_ENVvalues. While this is a standard security verification practice for Laravel, it involves reading sensitive configuration files.
Audit Metadata