php-pro
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [METADATA_POISONING]: The skill manifest identifies the author as
Jeffallan, which contradicts the expected author context ofmidudev. TheSKILL.mdfile has also been flagged with a negative file reputation by security scanners. - [EXTERNAL_DOWNLOADS]: A documentation link in the skill,
https://jeffallan.github.io/claude-skills/skills/language/php-pro/, is blacklisted as malicious according to automated URL reputation scans. - [INDIRECT_PROMPT_INJECTION]: The skill analyzes project source code and configuration files, creating an ingestion point for untrusted data. It lacks specific boundary markers or instructions to mitigate instructions embedded within this data.
- [COMMAND_EXECUTION]: The skill workflow requires the agent to run command-line tools like
phpstanandphpunitagainst the project files, which could lead to the execution of malicious code contained within those files.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata