symfony-yoandev-upgrade
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-controlled project files and logs to determine upgrade steps and detect issues. This represents a potential injection surface if those files contain malicious instructions.
- Ingestion points: Project metadata in
composer.jsonand deprecation logs invar/log/dev.logas mentioned inSKILL.mdandreferences/deprecations.md. - Boundary markers: No explicit boundary markers or safety instructions are defined to separate user-provided content from agent instructions.
- Capability inventory: The agent is instructed to execute shell commands and Docker containers, which could be misused if instructions were successfully injected.
- Sanitization: No sanitization of project file content is mentioned before processing.
- [COMMAND_EXECUTION]: The skill guides the user and agent to perform system checks and project management using command-line tools.
- Evidence: Instructions use commands like
php bin/console about,php bin/console debug:container --deprecations, andcomposer update. - [DYNAMIC_EXECUTION]: The skill utilizes a Docker container to execute Rector, a tool for automated code transformation.
- Evidence:
SKILL.mdprovides a command to runrectorvia thejakzal/phpqaDocker image:docker run --rm -v "$PWD":/project ... jakzal/phpqa:1.125.1-php8.4-alpine rector .... - [EXTERNAL_DOWNLOADS]: The skill facilitates the updating of Symfony Flex recipes from an external source.
- Evidence:
composer recipes:updatefetches updated recipe files from the official Symfony recipes repository on GitHub.
Audit Metadata