laravel-starter-kit-upgrade
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill clones official repositories from the Laravel organization on GitHub via
scripts/fetch_kit.shand retrieves repository metadata (commit messages and PR titles) using the GitHub CLI (gh api) in Phase 2 of the workflow. - [COMMAND_EXECUTION]: The skill utilizes several shell scripts to perform local environment checks, repository management, and code comparison. This includes extensive use of
gitfor branching and diffing,ghfor GitHub interaction, andjqfor processing JSON data as seen inscripts/preflight.shandscripts/run_tests.sh. - [REMOTE_CODE_EXECUTION]: The skill executes standard package managers (
composer,npm,yarn,pnpm,bun) to update dependencies inscripts/reconcile_manifests.sh. It also dynamically executes test and build commands discovered in the project'spackage.jsonorcomposer.jsonusingbash -cwithinscripts/run_tests.shto ensure behavior preservation. - [PROMPT_INJECTION]: The skill ingests potentially untrusted data from upstream commit messages and PR titles during the cataloging phase. While this provides a surface for indirect prompt injection, the skill mitigates risk by requiring explicit user selection and confirmation before any code changes are applied.
Audit Metadata