rails-dead-code-finder
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it reads and processes arbitrary content from the local codebase.
- Ingestion points: Source files across the application, including
app/,lib/, andconfig/directories. - Boundary markers: The instructions do not define boundary markers or safety wrappers to distinguish code content from instructions.
- Capability inventory: The skill uses file-reading, project-wide search (grep), and file-writing tools to generate its audit report.
- Sanitization: No sanitization or filtering of the ingested code content is performed before processing.
Audit Metadata