skills/aladac/claude-plugins/Ruby/Gen Agent Trust Hub

Ruby

Fail

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: HIGHCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The ruby.sh script is vulnerable to shell command injection when executing Ruby commands on remote machines (fuji and junkpile).
  • Evidence: The functions run_fuji and run_junkpile in ruby.sh use SSH to execute commands: ssh f "$FUJI_RUBY $" and ssh j "$JUNKPILE_RUBY $".
  • The use of "$*" inside the SSH command string concatenates all arguments into a single string that is passed to and interpreted by the remote shell. This allows for the injection of arbitrary shell commands via metacharacters like semicolons (;), ampersands (&), or subshell invocations ($()).
  • Impact: This allows an attacker to execute arbitrary code on the remote target machines by manipulating the arguments passed to the Ruby skill.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 16, 2026, 06:02 AM
Security Audit — agent-trust-hub — Ruby