37signals-implement
Pass
Audited by Gen Agent Trust Hub on Apr 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's instructions are functional and focused on standard Rails development workflows. No suspicious shell commands, network requests, or sensitive file access patterns were identified.
- [PROMPT_INJECTION]: The skill processes user feature requirements to generate code, creating a surface for indirect prompt injection. 1. Ingestion points: User feature requests in SKILL.md. 2. Boundary markers: Explicit 'Boundaries' section with 'Always', 'Ask First', and 'Never' rules. 3. Capability inventory: Orchestrates file generation and task execution across the Rails stack. 4. Sanitization: Relies on the host agent's safety guardrails. As this is the primary intended function, the risk is considered low and does not escalate the verdict.
- [SAFE]: Metadata attribution to '37signals' and references to the 'ThibautBaissac/rails_ai_agents' repository are consistent with the skill's purpose and represent attribution to the source patterns rather than deceptive metadata poisoning.
Audit Metadata