write-script-php

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the wmill CLI tool for previewing local scripts, running deployed scripts, and synchronizing workspace changes.
  • [COMMAND_EXECUTION]: The wmill generate-metadata command is used to regenerate configuration files and update content hashes on the local filesystem.
  • [EXTERNAL_DOWNLOADS]: The skill describes how to specify and resolve external PHP library dependencies through @require comments, which are fetched from public registries during metadata generation.
  • [REMOTE_CODE_EXECUTION]: The wmill script preview command executes the PHP code authored by the agent in a local environment to verify functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data through function parameters. Ingestion points: main function arguments; Boundary markers: None; Capability inventory: Full PHP execution and database access; Sanitization: None described in the skill templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 04:44 AM
Security Audit — agent-trust-hub — write-script-php