symfony-yoandev-standards
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local shell commands (
php -v,ls) and a short PHP script to perform environment discovery. These are standard developer operations used to identify framework versions and project structure.\n- [INDIRECT_PROMPT_INJECTION]: The skill reads and processes thecomposer.lockfile to list dependency versions.\n - Ingestion points: Reads the project's
composer.lockfile via a PHP one-liner.\n - Boundary markers: None; outputs version data directly to the agent context.\n
- Capability inventory: The agent has access to the filesystem and shell execution for diagnostics and testing.\n
- Sanitization: The script uses a specific regex whitelist for package names but does not sanitize the version strings before echoing them to the output.
Audit Metadata