template-method-and-plugins

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides structural guidance for PHP/Laravel development, focusing on maintainable code patterns. No malicious commands, persistence mechanisms, or unauthorized file access patterns were identified.\n- [PROMPT_INJECTION]: The skill involves a workflow that ingests local project metadata (versions and conventions) to guide its actions. While this constitutes an indirect prompt injection surface, it is a standard requirement for development tasks. The skill explicitly instructs the agent to protect sensitive data and maintain boundaries, following security best practices.\n
  • Ingestion points: Detection of Laravel/PHP versions and project conventions (SKILL.md, Workflow Step 1).\n
  • Boundary markers: None specified for the ingestion of project conventions.\n
  • Capability inventory: Running tests and quality checks (SKILL.md, Workflow Step 5).\n
  • Sanitization: The skill instructs the agent to keep credentials and personal data out of logs and outputs (SKILL.md, Checkpoints and Syarif Defaults).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 02:32 PM
Security Audit — agent-trust-hub — template-method-and-plugins