php-pro
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-provided PHP code snippets for performance reviews and idiomatic improvements, which constitutes a potential attack surface.
- Ingestion points: Ingests PHP implementation code and requests via user prompts as specified in SKILL.md.
- Boundary markers: The instructions lack explicit delimitation or strict isolation rules for separating untrusted user code from agent instructions.
- Capability inventory: The agent can read internal resource files (resources/implementation-playbook.md) and generate executable PHP code based on the input.
- Sanitization: There are no mentioned mechanisms for sanitizing or filtering instructions that might be embedded within the code submitted for review.
Audit Metadata