symfony-yoandev-quality

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides standard configuration templates for PHP static analysis (PHPStan), architectural enforcement (deptrac), and code styling (php-cs-fixer).
  • [COMMAND_EXECUTION]: The skill utilizes Docker to execute QA tools in a containerized environment via castor.php or a Makefile. The shell commands are constructed using predefined logic and do not involve unsafe interpolation of external user input.
  • [EXTERNAL_DOWNLOADS]: The skill references the jakzal/phpqa Docker image and the ramsey/composer-install GitHub Action. These are widely used and reputable resources within the PHP development ecosystem.
  • [CREDENTIALS_UNSAFE]: The CI workflow configuration includes default database credentials for a local testing container. These are standard placeholders for automated testing environments and do not represent a leak of sensitive production secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 07:06 AM
Security Audit — agent-trust-hub — symfony-yoandev-quality