laravel-verification

Warn

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTION
Full Analysis
  • [DATA_EXPOSURE]: The skill instructs the agent to read and verify the .env file, which typically stores sensitive secrets like database passwords and API keys.\n- [COMMAND_EXECUTION]: The skill performs extensive shell operations using php, composer, and php artisan to manage the project environment, linting, and tests.\n- [DYNAMIC_EXECUTION]: The skill uses the php artisan tinker --execute command to run PHP code snippets directly from the CLI to verify queue health.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted local files (such as source code and tests) which could contain malicious data designed to subvert the agent's logic.\n
  • Ingestion points: Local project directory files, specifically .env and files analyzed by Pint and PHPStan.\n
  • Boundary markers: None present.\n
  • Capability inventory: Shell command execution, PHP code execution, and sensitive file access.\n
  • Sanitization: No sanitization or validation of project-sourced data is implemented.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 15, 2026, 03:24 AM
Security Audit — agent-trust-hub — laravel-verification