query-agent

Warn

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses bundle exec and bin/rails to execute tests, linters, and the Rails console, allowing for arbitrary code execution within the development environment.
  • [DATA_EXFILTRATION]: The skill is instructed to read application source code from app/models/, app/controllers/, and app/services/ for context, which exposes internal logic to the agent.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it ingests project code without sanitization or boundary markers while maintaining the ability to write files and execute shell commands.
  • [SQL_INJECTION]: The NearbyQuery example in references/patterns.md uses string interpolation (#{lat}, #{lng}) inside a raw SQL block. This pattern creates a risk of SQL injection if user-provided coordinates are not correctly cast to floats before being used in the query.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 17, 2026, 07:25 AM
Security Audit — agent-trust-hub — query-agent