symfony-yoandev-http

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted external data from HTTP requests (payloads, query strings, headers, and file uploads) into the application context. While it strongly advocates for the use of validation constraints and Data Transfer Objects (DTOs) as sanitization layers, the processing of user-controlled input inherently creates an attack surface.
  • Ingestion points: Identified in references/input-mapping.md via #[MapRequestPayload], #[MapQueryString], and #[MapUploadedFile].
  • Boundary markers: The instructions mandate mapping all input to typed DTOs, which serves as a structural boundary between the transport and application layers.
  • Capability inventory: The skill guides the creation of controllers that interact with domain services, but does not provide direct shell execution or arbitrary file-system write capabilities.
  • Sanitization: Strong emphasis on using Symfony\Component\Validator\Constraints to filter and validate all incoming request data before it reaches the service layer.
  • [DYNAMIC_EXECUTION]: The skill documents the use of Symfony's Expression Language for dynamic validation groups in #[MapRequestPayload]. This allows for the execution of logic defined in strings at runtime, although it is constrained to validation logic and specific variables (args, request, this). Evidence found in references/input-mapping.md using validationGroups: new Expression(...).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 07:05 AM
Security Audit — agent-trust-hub — symfony-yoandev-http