rails-expert
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill links to documentation hosted on jeffallan.github.io. This is a vendor resource belonging to the skill's author and serves as a legitimate site for extended usage guidance.
- [INDIRECT_PROMPT_INJECTION]: The skill functions as a code generator based on user requirements, which establishes an attack surface for indirect prompt injection. 1. Ingestion points: User-provided application requirements and schema descriptions in SKILL.md. 2. Boundary markers: Detailed 'Constraints' and 'Core Workflow' sections delimit agent behavior. 3. Capability inventory: The skill generates Ruby source code, migrations, and CLI command instructions. 4. Sanitization: Explicitly mandates the use of sanitize_sql and strong parameters in all generated code.
- [COMMAND_EXECUTION]: The documentation includes instructions for standard Rails CLI operations such as rails db:migrate, bundle exec rspec, and rails generate, which are intended for use within a standard development lifecycle.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata