symfony-yoandev-security
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive and correct documentation for implementing authentication and authorization in Symfony projects using native components.
- [CREDENTIALS_UNSAFE]: No hardcoded credentials were found. The skill correctly advises storing secrets in environment variables and using SHA-256 for hashing API tokens rather than storing them in plain text.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns or unsafe external downloads were detected. References to well-known Symfony packages (e.g.,
symfony/rate-limiter,symfony/expression-language) are standard for the framework. - [DATA_EXFILTRATION]: No network operations to unknown or suspicious domains are present. The only network call mentioned is to the official 'Have I Been Pwned' API for password compromise checks, which is a standard security practice.
- [PRIVILEGE_ESCALATION]: The skill correctly warns about the risks of impersonation (
switch_user) and advises protecting destructive actions against impersonating actors. - [PROMPT_INJECTION]: No attempts to override agent behavior or bypass safety guidelines were found in the skill metadata or body.
- [INDIRECT_PROMPT_INJECTION]: The skill documents how to handle untrusted data through DTOs and validation constraints (Category 8 assessment: Surface exists as the skill handles user registration/login data, but it emphasizes strict validation and sanitization, resulting in a SAFE assessment).
Audit Metadata