php-pro

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's workflow involves analyzing and executing commands on untrusted project code, creating a surface for indirect prompt injection.
  • Ingestion points: The agent is instructed to read and analyze project architecture, domain models, dependencies, and PHP source code files (SKILL.md).
  • Boundary markers: The skill lacks explicit instructions or delimiter patterns to ensure the agent ignores instructions potentially embedded within the code, documentation, or configuration files it processes.
  • Capability inventory: The skill workflow requires executing shell commands for static analysis and testing, specifically vendor/bin/phpstan, vendor/bin/phpunit, and vendor/bin/pest (SKILL.md, references/testing-quality.md).
  • Sanitization: There are no requirements for input validation or integrity checks for the local binaries or the application code before processing or execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:50 AM
Security Audit — agent-trust-hub — php-pro