php-modern

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to fetch documentation and migration guides from the official php.net domain using web tools. This creates an attack surface where malicious content on the targeted site could attempt to influence the agent. However, as the instruction is restricted to a well-known official source, it is considered safe for the intended use case.
  • Ingestion points: Output from WebSearch and WebFetch tools as specified in SKILL.md.
  • Boundary markers: Absent. The skill does not provide instructions to ignore potential commands in the fetched data.
  • Capability inventory: The agent has permissions for file system tools and Bash execution.
  • Sanitization: Absent. No content validation is performed on the retrieved documentation.
  • [NO_CODE]: The skill contains only documentation and prompt instructions within the SKILL.md file; it does not ship with any separate scripts, binaries, or other executable files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:33 AM