rails-expert

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill's primary workflow involves processing user-provided requirements to generate Rails code and execute system commands (e.g., migrations and specs). This creates an inherent surface for indirect prompt injection where malicious or untrusted input could attempt to influence the agent's implementation or execution environment.
  • Ingestion points: User-provided application requirements for models, routes, and background jobs defined in SKILL.md.
  • Boundary markers: Absent. The skill does not define specific delimiters or instructions to ignore embedded directives in the requirements.
  • Capability inventory: The agent is instructed to perform file system writes (generating models/controllers) and execute shell commands (rails db:migrate, bundle exec rspec) in SKILL.md.
  • Sanitization: No explicit validation or sanitization of the requirement input is described before it is used to drive code generation or command execution.
  • [SAFE]: The skill demonstrates secure practices for API development and secret management. It correctly references Rails.application.credentials.secret_key_base for JWT operations and provides examples of query parameter sanitization using sanitize_sql_like in references/active-record.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 08:51 PM
Security Audit — agent-trust-hub — rails-expert