review-migration

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists exclusively of instructional Markdown documentation and Ruby code examples for database migrations. No executable scripts, network operations, or sensitive file access patterns are present.
  • [PROMPT_INJECTION]: The instructions contain 'HARD-GATE' rules and 'DO NOT' directives, which are legitimate task-specific safety guidelines intended to prevent production database outages, not attempts to bypass AI safety filters or override agent behavior.
  • [DATA_EXPOSURE]: No hardcoded credentials, sensitive file paths, or network exfiltration patterns were found. The skill does not perform any operations that could expose user data.
  • [REMOTE_CODE_EXECUTION]: The skill does not download or execute external code. All code provided consists of static examples intended for manual implementation or review within a Rails application environment.
  • [OBFUSCATION]: No obfuscation techniques such as Base64 encoding, zero-width characters, or homoglyph attacks were detected in the text or code snippets.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process external code (Rails migrations) during a review process, it serves as a set of logical constraints for the agent to follow. It does not contain capabilities that could be exploited via malicious data ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 05:22 PM
Security Audit — agent-trust-hub — review-migration