skills/ericrisco/rsc-harness/rails/Gen Agent Trust Hub

rails

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a shell script (scripts/verify.sh) intended for local project auditing.
  • Evidence: The script performs read-only operations using grep, rubocop, and bin/rails zeitwerk:check to identify anti-patterns such as N+1 queries or unsafe migrations.
  • Assessment: The script is self-contained, does not perform network operations, and does not require elevated privileges.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and modify existing Rails codebases, which serves as a potential attack surface for indirect prompt injection from malicious source code.
  • Ingestion points: The agent reads local project files including Gemfile, app/**/*.rb, and db/migrate/*.rb (identified in scripts/verify.sh and SKILL.md).
  • Boundary markers: None explicitly defined for project file ingestion.
  • Capability inventory: The skill allows the agent to generate/edit Rails models, controllers, and migrations, and execute the provided verify.sh script.
  • Sanitization: The verify.sh script uses grep patterns for static analysis rather than direct execution of untrusted content, and the instructions emphasize standard Rails security features like strong parameters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — rails