specialist-engineering-php-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill interpolates user-controlled data directly into the system prompt of a subagent.
  • Ingestion points: The variable '{the user's question}' in SKILL.md.
  • Boundary markers: Absent. The user input is appended at the end of the subagent prompt without delimiters or instructions to the model to treat the content as untrusted data.
  • Capability inventory: The subagent is granted broad authority for PHP architecture, performance analysis, and security auditing.
  • Sanitization: Absent. The input is not escaped or validated before interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 08:50 PM
Security Audit — agent-trust-hub — specialist-engineering-php-engineer