symfony-yoandev-local-dev

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for standard local development commands using docker compose and symfony CLI. These are routine operations for managing a Symfony development environment.
  • [CREDENTIALS_UNSAFE]: The Docker configuration assets use ${POSTGRES_PASSWORD:-!ChangeMe!} as a default placeholder for database credentials. This is a common practice for development templates and avoids hardcoding real secrets.
  • [REMOTE_CODE_EXECUTION]: The skill references the dunglas/frankenphp Docker image and the dunglas/symfony-docker repository. These are well-known and widely used resources within the Symfony community for containerized development.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to manage local project files and configuration. While this involves processing user-controlled project data, the interaction is constrained to standard local development tasks.
  • Ingestion points: Reads local compose.yaml and environment files.
  • Boundary markers: Relies on standard file formats (YAML, Shell).
  • Capability inventory: Local file operations, Docker command execution, and Symfony CLI usage.
  • Sanitization: Not applicable as operations are intended for the developer's own local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 07:06 AM
Security Audit — agent-trust-hub — symfony-yoandev-local-dev