laravel-development-workflow

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The workflow incorporates multiple safety principles, such as prohibiting destructive database operations, production deployments, and credential modifications. It also requires the AI to prevent the exposure of secrets in logs, commands, and completion evidence.\n- [COMMAND_EXECUTION]: The skill uses standard Laravel tools like php artisan, pest, phpstan, and pint. Security risk is minimized by the instruction to only use tools already configured within the project and to avoid installing new dependencies.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses an inherent attack surface as it processes untrusted project files and repository instructions.\n
  • Ingestion points: Reads repository instructions, source code, routes, and database schemas.\n
  • Boundary markers: Absent; there are no specific markers used to delimit untrusted data from instructions.\n
  • Capability inventory: Includes the ability to execute shell commands for testing and static analysis.\n
  • Sanitization: The skill relies on the agent's internal reasoning rather than explicit validation steps for ingested code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 01:01 PM
Security Audit — agent-trust-hub — laravel-development-workflow