rails-8-setup
Fail
Audited by Snyk on Jun 17, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The setup script intentionally creates/commits a .claude/settings.json that grants an external assistant broad, auto-approved privileges (project_eval, execute_sql_query, get_logs, WebFetch/WebSearch, enableAllProjectMcpServers etc.), effectively enabling remote code execution into the Rails runtime and access to database/logs and network I/O—allowing easy data exfiltration and a backdoor into the project.
Issues (1)
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata