symfony-yoandev-standards

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local shell commands (php -v, ls) and a short PHP script to perform environment discovery. These are standard developer operations used to identify framework versions and project structure.\n- [INDIRECT_PROMPT_INJECTION]: The skill reads and processes the composer.lock file to list dependency versions.\n
  • Ingestion points: Reads the project's composer.lock file via a PHP one-liner.\n
  • Boundary markers: None; outputs version data directly to the agent context.\n
  • Capability inventory: The agent has access to the filesystem and shell execution for diagnostics and testing.\n
  • Sanitization: The script uses a specific regex whitelist for package names but does not sanitize the version strings before echoing them to the output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 07:06 AM
Security Audit — agent-trust-hub — symfony-yoandev-standards