viewcomponent-coder

Warn

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill recommends initialization with rails app:template LOCATION="https://railsbytes.com/script/zJosO5". This command fetches and executes a Ruby script from a remote community source within the application context.
  • [COMMAND_EXECUTION]: The skill provides instructions for installing gems and running shell-based Rails template commands.
  • [DYNAMIC_EXECUTION]: In references/patterns.md, the EditableFieldComponent uses the send method to dynamically access record attributes based on the field parameter (record.send(field)). This pattern facilitates dynamic method invocation which may be exploitable if the parameter is influenced by untrusted input.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface by defining components that ingest external data for rendering.
  • Ingestion points: Multiple components in SKILL.md and references/patterns.md (e.g., ButtonComponent, InputComponent, NotificationComponent) accept options like text, label, or message which are rendered in the UI.
  • Boundary markers: No specific delimiters or safety instructions are provided to isolate untrusted data within the templates.
  • Capability inventory: The skill enables UI rendering and provides instructions for shell-based environment configuration.
  • Sanitization: The patterns rely on standard Rails ERB output escaping.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 2, 2026, 11:17 PM
Security Audit — agent-trust-hub — viewcomponent-coder