PHP Ecosystem

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill documentation encourages robust security practices, such as the mandatory use of prepared statements to prevent SQL injection and enabling strict type declarations in all PHP files to improve code reliability.\n- [EXTERNAL_DOWNLOADS]: The skill utilizes a documentation tool (mcp__plugin_claude-code-home-manager_context7__query-docs) to fetch the latest PHP language specifications. This is an expected and safe use of context-enhancement tools for providing up-to-date guidance.\n- [COMMAND_EXECUTION]: The skill provides instructions for running standard PHP development tools such as Composer, PHPUnit, PHPStan, and PHP-CS-Fixer. These are routine operations within a software development workflow and are used as intended for dependency management, testing, and static analysis.\n- [PROMPT_INJECTION]: The skill is designed to analyze and modify external PHP files and composer.json (ingestion points). While it lacks explicit boundary markers to ignore embedded instructions in analyzed files, the risk of indirect prompt injection is mitigated by the skill's strong emphasis on validation and static analysis. The agent has capabilities to edit files and execute shell commands (Bash), but these are constrained to common development tools necessary for the skill's purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 05:21 AM
Security Audit — agent-trust-hub — PHP Ecosystem