bd-data-object

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted user input in the form of PHP code, pull request titles, and code diffs to provide assistance in DTO generation. 1. Ingestion points: User requests, PHP source files in src/, tests/, and plugin directories, PR titles, and diffs. 2. Boundary markers: None identified. 3. Capability inventory: The skill suggests writing PHP code and executing development tools like phpunit, phpstan, and php-cs-fixer. 4. Sanitization: None identified.
  • [SAFE]: External references including the GitHub repository and contact email belong to the skill's author (lonsdale201).
  • [SAFE]: The skill promotes security best practices for handling sensitive data through the use of Secret types and attributes for encryption and redaction.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:07 PM
Security Audit — agent-trust-hub — bd-data-object