sota-php
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a defensive guide and audit toolset for PHP development, adhering to 2026 security baselines (PHP 8.3 through 8.5).
- [SAFE]: Audit functionality is implemented using standard, transparent shell commands (e.g., grep, composer audit) used exclusively for local static analysis of project files.
- [SAFE]: The instructions promote high-security standards, including strict typing, mandatory prepared statements (PDO), and hardened session configurations based on official documentation and OWASP recommendations.
- [SAFE]: No malicious patterns such as remote code execution, obfuscation, or data exfiltration were detected. All external references point exclusively to official language documentation (php.net), package managers (getcomposer.org), or established static analysis tools (phpstan.org).
- [SAFE]: The skill's audit mode involves processing untrusted source code, which technically constitutes an ingestion surface for indirect prompt injection. However, this is the intended primary purpose of the skill and is managed by the agent's internal safety protocols rather than posing a direct threat in the skill's logic.
Audit Metadata