laravel-releases

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection. Ingestion point: gh release view in SKILL.md. Boundary markers: Absent. Capability inventory: Bash, Read, Grep, Glob in SKILL.md. Sanitization: Absent. External content from Laravel release notes is processed without isolation, creating a surface for malicious instructions to influence the agent.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute system commands such as composer show and gh release to interact with the official Laravel framework repository. This capability is necessary for the skill's purpose but represents a tool that could be misused if the agent is compromised via injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 07:46 PM