template-method-and-plugins
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides structural guidance for PHP/Laravel development, focusing on maintainable code patterns. No malicious commands, persistence mechanisms, or unauthorized file access patterns were identified.\n- [PROMPT_INJECTION]: The skill involves a workflow that ingests local project metadata (versions and conventions) to guide its actions. While this constitutes an indirect prompt injection surface, it is a standard requirement for development tasks. The skill explicitly instructs the agent to protect sensitive data and maintain boundaries, following security best practices.\n
- Ingestion points: Detection of Laravel/PHP versions and project conventions (SKILL.md, Workflow Step 1).\n
- Boundary markers: None specified for the ingestion of project conventions.\n
- Capability inventory: Running tests and quality checks (SKILL.md, Workflow Step 5).\n
- Sanitization: The skill instructs the agent to keep credentials and personal data out of logs and outputs (SKILL.md, Checkpoints and Syarif Defaults).
Audit Metadata