rails-expert

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill analyzes external requirements and project files to generate code and run tests, which represents an ingestion surface for potentially untrusted data. Although no specific boundary markers are used in the prompts, the skill mandates secure coding practices such as SQL sanitization to mitigate risks in the resulting application.\n
  • Ingestion points: Requirement analysis (Step 1) and spec validation (Step 5) in SKILL.md.\n
  • Boundary markers: Not explicitly defined in the workflow instructions.\n
  • Capability inventory: Shell command execution (bundle exec), file system modification (rails generate), and database migration execution (rails db:migrate).\n
  • Sanitization: Instructions explicitly require the use of sanitize_sql or parameterized queries for database operations.\n- [EXTERNAL_DOWNLOADS]: The skill includes references to documentation and the author's profile hosted on well-known and established platforms.\n
  • Evidence: Hyperlinks to jeffallan.github.io and github.com/Jeffallan are present in the documentation section of SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — rails-expert