laravel-security-audit
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions do not contain any attempts to override safety filters, bypass system prompts, or extract internal instructions. The language used is purely instructional and aligned with its stated purpose.
- [DATA_EXFILTRATION]: No network operations, credential access patterns, or sensitive file path references were found. The skill does not instruct the agent to send data to external servers.
- [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote scripts. The skill operates purely within the context of analyzing provided code snippets.
- [COMMAND_EXECUTION]: No shell commands, privileged operations (sudo), or system-level modifications are present in the skill instructions.
- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to ingest and analyze potentially untrusted user code, it lacks automated capabilities (such as file writing or network access) that would enable a multi-step attack chain. It functions as a standard analytical assistant.
- [OBFUSCATION]: No encoded content, hidden characters, or homoglyph substitutions were detected during the analysis.
- [DYNAMIC_EXECUTION]: The skill does not employ runtime code generation, unsafe deserialization, or dynamic loading techniques.
Audit Metadata