symfony-yoandev-local-dev
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for standard local development commands using
docker composeandsymfonyCLI. These are routine operations for managing a Symfony development environment. - [CREDENTIALS_UNSAFE]: The Docker configuration assets use
${POSTGRES_PASSWORD:-!ChangeMe!}as a default placeholder for database credentials. This is a common practice for development templates and avoids hardcoding real secrets. - [REMOTE_CODE_EXECUTION]: The skill references the
dunglas/frankenphpDocker image and thedunglas/symfony-dockerrepository. These are well-known and widely used resources within the Symfony community for containerized development. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to manage local project files and configuration. While this involves processing user-controlled project data, the interaction is constrained to standard local development tasks.
- Ingestion points: Reads local
compose.yamland environment files. - Boundary markers: Relies on standard file formats (YAML, Shell).
- Capability inventory: Local file operations, Docker command execution, and Symfony CLI usage.
- Sanitization: Not applicable as operations are intended for the developer's own local environment.
Audit Metadata