query-agent
Warn
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
bundle execandbin/railsto execute tests, linters, and the Rails console, allowing for arbitrary code execution within the development environment. - [DATA_EXFILTRATION]: The skill is instructed to read application source code from
app/models/,app/controllers/, andapp/services/for context, which exposes internal logic to the agent. - [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it ingests project code without sanitization or boundary markers while maintaining the ability to write files and execute shell commands.
- [SQL_INJECTION]: The
NearbyQueryexample inreferences/patterns.mduses string interpolation (#{lat},#{lng}) inside a raw SQL block. This pattern creates a risk of SQL injection if user-provided coordinates are not correctly cast to floats before being used in the query.
Audit Metadata