rails-8-setup

Fail

Audited by Snyk on Jun 17, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The setup script intentionally creates/commits a .claude/settings.json that grants an external assistant broad, auto-approved privileges (project_eval, execute_sql_query, get_logs, WebFetch/WebSearch, enableAllProjectMcpServers etc.), effectively enabling remote code execution into the Rails runtime and access to database/logs and network I/O—allowing easy data exfiltration and a backdoor into the project.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 17, 2026, 10:17 AM
Issues
1
Security Audit — snyk — rails-8-setup