symfony-yoandev-storage
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of defensive security documentation and best practices for Symfony applications, with no malicious code or exfiltration patterns detected.
- [INDIRECT_PROMPT_INJECTION]: The skill describes an attack surface for untrusted user data and provides the mandatory evidence chain for its defensive implementation: 1. Ingestion points: Documented receipt of files via #[MapUploadedFile]. 2. Boundary markers: Recommends using 'extensions' constraints to sniff MIME types instead of trusting client headers. 3. Capability inventory: Files are written to storage via FilesystemOperator. 4. Sanitization: Recommends randomizing filenames, using SluggerInterface, and validating bytes to prevent path traversal and stored XSS.
Audit Metadata