tracekit-php-sdk
Pass
Audited by Gen Agent Trust Hub on Apr 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The instructions follow standard development practices for SDK integration, including the use of environment variables for secret management.
- [PROMPT_INJECTION]: The static analysis hint for concealment is identified as a false positive. The instruction for the agent to skip redundant signup prompts is a legitimate UX optimization designed to check for existing configurations, not an attempt to bypass safety filters.
- [COMMAND_EXECUTION]: The skill utilizes standard CLI commands such as 'composer require' for dependency management and 'curl' for verifying connectivity to the vendor's dashboard. These commands are appropriate and necessary for the skill's stated purpose.
Audit Metadata