bd-data-object
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted user input in the form of PHP code, pull request titles, and code diffs to provide assistance in DTO generation. 1. Ingestion points: User requests, PHP source files in src/, tests/, and plugin directories, PR titles, and diffs. 2. Boundary markers: None identified. 3. Capability inventory: The skill suggests writing PHP code and executing development tools like phpunit, phpstan, and php-cs-fixer. 4. Sanitization: None identified.
- [SAFE]: External references including the GitHub repository and contact email belong to the skill's author (lonsdale201).
- [SAFE]: The skill promotes security best practices for handling sensitive data through the use of Secret types and attributes for encryption and redaction.
Audit Metadata