extract-laravel-standards

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill requires the agent to inspect 'deployment-sensitive configuration', which typically includes reading sensitive files like .env that contain credentials. While the skill includes instructions to remove these secrets from final proposals, the process of reading them constitutes a data exposure risk.
  • [PROMPT_INJECTION]: The skill processes external project files as input, creating a surface for indirect prompt injection. 1. Ingestion points: Audited Laravel project files such as controllers, models, and configuration files. 2. Boundary markers: The skill does not specify delimiters to separate audited code from instructions. 3. Capability inventory: The agent can write to the local file system in the proposals directory. 4. Sanitization: Instructions mandate removing secrets but do not address sanitizing malicious instructions found in code comments.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 02:32 PM
Security Audit — agent-trust-hub — extract-laravel-standards