php-framework-audit
Pass
Audited by Gen Agent Trust Hub on May 4, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [PROMPT_INJECTION]: No direct prompt injection or attempts to bypass safety filters were detected. The skill's structure as a code auditing tool presents an indirect injection surface through analyzed code, but no specific vulnerabilities were identified.
- Ingestion points: PHP source files and framework configurations (e.g., composer.json).
- Boundary markers: Not defined.
- Capability inventory: Limited to static analysis and reporting.
- Sanitization: Not specified.- [DATA_EXFILTRATION]: There is no evidence of hardcoded credentials, sensitive data harvesting, or network operations intended for data exfiltration.- [REMOTE_CODE_EXECUTION]: No remote code execution patterns, dynamic execution logic, or untrusted package installations were found.- [NO_CODE]: The skill consists entirely of instructional Markdown documentation without any executable scripts or binary components.- [SAFE]: The skill provides legitimate security research patterns and follows standard best practices for white-box code auditing.
Audit Metadata