php-expert

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a 'Memory Protocol' that instructs the agent to use the Bash tool to read from a specific local file path (.claude/context/memory/learnings.md) and record new patterns. This is an intended feature for maintaining state across agent sessions.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to ingest and review user-provided PHP code, which represents an attack surface for indirect prompt injection.
  • Ingestion points: Target files and paths provided by the user for code review and architectural guidance.
  • Boundary markers: No specific boundary markers or 'ignore' instructions are defined in the prompt templates to isolate user data from system instructions.
  • Capability inventory: The skill is granted access to powerful tools including Bash, Write, Edit, and Read to perform its tasks.
  • Sanitization: The instructions do not specify any sanitization or validation of the untrusted code content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 08:16 AM
Security Audit — agent-trust-hub — php-expert