symfony-yoandev-frontend
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for executing standard Symfony development commands via the CLI, including
symfony console importmap:require,php bin/console asset-map:compile, andsymfony console tailwind:build. These are intended for project management and deployment. - [EXTERNAL_DOWNLOADS]: The skill references downloading external assets such as JavaScript libraries through AssetMapper and the Tailwind binary via a standard Symfony bundle. It also mentions a fallback to the
jspm.ioCDN for polyfills if they are not hosted locally. These interactions are standard for the described frontend stack. - [INDIRECT_PROMPT_INJECTION]: As an agent skill that responds to user instructions for code generation, it presents a potential surface for indirect prompt injection. The documentation mitigates this by instructing the agent to use secure coding patterns, such as using Data Transfer Objects (DTOs) instead of direct database entities and enforcing authorization checks on all interactive component endpoints.
- [SAFE]: The skill promotes security best practices by explicitly recommending the use of
importmap:auditfor checking vulnerable JavaScript dependencies and providing guidance on configuring Content Security Policy (CSP) nonces to work correctly with frontend navigation libraries.
Audit Metadata