rails-expert
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill's primary workflow involves processing user-provided requirements to generate Rails code and execute system commands (e.g., migrations and specs). This creates an inherent surface for indirect prompt injection where malicious or untrusted input could attempt to influence the agent's implementation or execution environment.
- Ingestion points: User-provided application requirements for models, routes, and background jobs defined in
SKILL.md. - Boundary markers: Absent. The skill does not define specific delimiters or instructions to ignore embedded directives in the requirements.
- Capability inventory: The agent is instructed to perform file system writes (generating models/controllers) and execute shell commands (
rails db:migrate,bundle exec rspec) inSKILL.md. - Sanitization: No explicit validation or sanitization of the requirement input is described before it is used to drive code generation or command execution.
- [SAFE]: The skill demonstrates secure practices for API development and secret management. It correctly references
Rails.application.credentials.secret_key_basefor JWT operations and provides examples of query parameter sanitization usingsanitize_sql_likeinreferences/active-record.md.
Audit Metadata