symfony-yoandev-quality
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides standard configuration templates for PHP static analysis (PHPStan), architectural enforcement (deptrac), and code styling (php-cs-fixer).
- [COMMAND_EXECUTION]: The skill utilizes Docker to execute QA tools in a containerized environment via
castor.phpor aMakefile. The shell commands are constructed using predefined logic and do not involve unsafe interpolation of external user input. - [EXTERNAL_DOWNLOADS]: The skill references the
jakzal/phpqaDocker image and theramsey/composer-installGitHub Action. These are widely used and reputable resources within the PHP development ecosystem. - [CREDENTIALS_UNSAFE]: The CI workflow configuration includes default database credentials for a local testing container. These are standard placeholders for automated testing environments and do not represent a leak of sensitive production secrets.
Audit Metadata