packagist
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill retrieves information from packagist.org, which is the official and well-known registry for PHP packages.
- [DATA_EXFILTRATION]: No unauthorized data transfer detected. The skill uses the WebFetch tool exclusively to interact with the Packagist API for legitimate lookup tasks.
- [PROMPT_INJECTION]: The instructions are descriptive of API functionality and do not contain directives to bypass agent safety or security protocols.
- [CREDENTIALS_UNSAFE]: No hardcoded credentials or sensitive tokens are present; the documentation uses generic placeholders for authentication configuration.
Audit Metadata