php-pro
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No patterns detected that attempt to override system instructions or bypass security filters. The instructions are strictly focused on professional PHP development standards.
- [CREDENTIALS_UNSAFE]: Reference documentation includes standard development placeholders in code examples, such as 'root:password' for local MySQL connections. These are pedagogical examples for local developer environments and do not represent a credential exposure risk.
- [COMMAND_EXECUTION]: The skill encourages the use of local development tools such as 'phpstan', 'phpunit', and 'pest' via 'vendor/bin/'. These are standard industry tools for static analysis and testing, used here to ensure code quality within the developer's local environment.
- [DATA_EXFILTRATION]: No network operations targeted at external domains for data harvesting were detected. HTTP client examples in the asynchronous PHP reference target 'api.example.com', which is a standard documentation placeholder.
- [INDIRECT_PROMPT_INJECTION]: The skill generates code for handling user input through DTOs and Form Requests. It proactively addresses injection risks by mandating validation, password hashing (bcrypt/argon2), and SQL injection protection as part of its core constraints.
Audit Metadata