laravel-starter-kit-upgrade

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill clones official repositories from the Laravel organization on GitHub via scripts/fetch_kit.sh and retrieves repository metadata (commit messages and PR titles) using the GitHub CLI (gh api) in Phase 2 of the workflow.
  • [COMMAND_EXECUTION]: The skill utilizes several shell scripts to perform local environment checks, repository management, and code comparison. This includes extensive use of git for branching and diffing, gh for GitHub interaction, and jq for processing JSON data as seen in scripts/preflight.sh and scripts/run_tests.sh.
  • [REMOTE_CODE_EXECUTION]: The skill executes standard package managers (composer, npm, yarn, pnpm, bun) to update dependencies in scripts/reconcile_manifests.sh. It also dynamically executes test and build commands discovered in the project's package.json or composer.json using bash -c within scripts/run_tests.sh to ensure behavior preservation.
  • [PROMPT_INJECTION]: The skill ingests potentially untrusted data from upstream commit messages and PR titles during the cataloging phase. While this provides a surface for indirect prompt injection, the skill mitigates risk by requiring explicit user selection and confirmation before any code changes are applied.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — laravel-starter-kit-upgrade