Back to skill

Security audit

ThinkPHP UI Restoration

Security checks for vulnerabilities and agentic risk

Overview

This is a narrow ThinkPHP UI helper that only instructs an agent to edit normal project templates, CSS, and related mock/controller data.

Install this only in ThinkPHP projects where you want an agent to modify templates, shared CSS, mock data, or controller view assignments. Review generated code changes before committing, especially changes to shared CSS or controller data that may affect multiple pages.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.