rails-code-review
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted code diffs and pull request data, which constitutes an attack surface for indirect prompt injection. Ingestion points: External Ruby on Rails source code and PR diffs as defined in SKILL.md and assets/checklist.md. Boundary markers: The instructions do not specify the use of delimiters or isolation protocols to separate the code being reviewed from the agent's core instructions. Capability inventory: The skill references potential system-level operations via integration with other skills for migration and refactoring. Sanitization: No sanitization, validation, or escaping of the external code input is mentioned in the review workflow.
Audit Metadata