rails
Fail
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of
bin/rails runnerto execute arbitrary Ruby code within the application environment (e.g., inreferences/debugging.mdandreferences/rails-patterns.md). This allows for full access to the application context and database. If the agent incorporates unvalidated user input into these commands, it creates a vector for arbitrary code execution. - [EXTERNAL_DOWNLOADS]: In
references/sqlite-production.md, the skill provides instructions to download the Litestream binary directly from an individual's GitHub repository (github.com/benbjohnson/litestream). While the tool is known in the community, downloading binaries from personal repositories poses a supply chain risk. - [REMOTE_CODE_EXECUTION]: The skill provides a multi-step installation sequence (
wget ... | tar ... | sudo mv ...) for external software inreferences/sqlite-production.md. This represents remote code execution of a binary from an external source. - [COMMAND_EXECUTION]: The skill uses
sudo mvinreferences/sqlite-production.mdto install a downloaded binary into a system directory (/usr/local/bin/), which is a privilege escalation pattern. - [COMMAND_EXECUTION]: In
references/kamal-deployment.md, the skill useskamalcommands for server infrastructure management. This includes high-risk and potentially destructive operations such askamal setup,kamal app stop, andkamal remove, which gives the agent significant control over production environments. - [COMMAND_EXECUTION]: The skill utilizes a custom
bin/log-compressorscript inreferences/debugging.md. The use of shell arguments like--contextand--watchderived from user-provided data could lead to shell command injection if not properly sanitized by the underlying script.
Recommendations
- AI detected serious security threats
Audit Metadata