laravel-specialist
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill contains a documentation reference to a site hosted on a blacklisted domain (
jeffallan.github.io) which has been flagged as malicious by security scanners. - [METADATA_POISONING]: The
SKILL.mdfile has a confirmed malicious reputation detection (FileRepMalware). The metadata also directs users to external sources that are flagged by automated scanners. - [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for ingesting user requirements to build application architecture and logic, representing an attack surface for indirect prompt injection.
- Ingestion points: User-provided specifications for models, relationships, and APIs.
- Boundary markers: Absent. No specific markers are used to isolate user data.
- Capability inventory: Extensive use of shell commands via
php artisanfor database migrations, route listing, and queue processing. - Sanitization: No sanitization methods are described to prevent malicious instructions within requirements from influencing agent actions.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata