code-review-php
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides high-quality instructional content for identifying vulnerabilities such as SQL injection, command execution, and LFI in PHP applications.
- [INDIRECT_PROMPT_INJECTION]: This skill facilitates the ingestion of untrusted third-party PHP source code for analysis. 1. Ingestion points: PHP files in the target repository/codebase. 2. Boundary markers: Absent. 3. Capability inventory: ripgrep, semgrep, psalm, phpstan, progpilot. 4. Sanitization: Absent. This vulnerability surface is standard for code auditing tools and is inherent to the skill's primary purpose.
Audit Metadata