php-language-modern

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill provides legitimate documentation, templates, and coding standards for modern PHP development (versions 8.1 through 8.5).
  • [COMMAND_EXECUTION]: The workflow specifies usage of internal vendor tools such as fuse-ai-pilot:explore-codebase and fuse-ai-pilot:sniper for project analysis and verification. These are standard operations within the fusengine environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for ingesting external project configuration to guide code generation. 1. Ingestion points: The agent reads composer.json and the local CI matrix to determine PHP version constraints (SKILL.md). 2. Boundary markers: There are no explicit instructions to use delimiters or ignore instructions embedded within the codebase files. 3. Capability inventory: The skill is capable of generating PHP code and invoking analysis tools. 4. Sanitization: No explicit sanitization or content filtering is implemented for the ingested codebase data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 11:06 AM
Security Audit — agent-trust-hub — php-language-modern