generating-sorbet-inline

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses bundle exec srb tc (the Sorbet type checker) to validate the generated signatures. It also includes a command to remove a temporary tracking file (rm .sorbet-inline-generation-todo.tmp). These are standard, low-risk operations within a development environment and are necessary for the skill's stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents an indirect prompt injection surface because it reads and processes user-provided Ruby source files, which could contain malicious instructions in comments or string literals.
  • Ingestion points: Ruby source files are read during Step 1 (Analyze the Ruby Source) and Step 2 (Add Sorbet Signatures) as defined in SKILL.md.
  • Boundary markers: The skill uses a checklist and a tracking file to structure its operations, but does not implement specific delimiters for untrusted code content.
  • Capability inventory: The skill has file-write capabilities (updating Ruby files) and shell command execution (rm, srb tc).
  • Sanitization: No specific sanitization or escaping of the Ruby code content is mentioned.
  • Mitigation: The risk is significantly mitigated by a hard rule in the SKILL.md frontmatter: "You MUST NOT run Ruby code of the project."
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — generating-sorbet-inline