rails-bug-triage

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to capture bug reports and reproduction steps from a user and use that information to create failing RSpec tests. This creates a vulnerability surface where a malicious user could provide a bug report containing hidden instructions or code meant to be executed when the agent runs the generated test.
  • Ingestion points: Untrusted bug reports, error logs, and reproduction steps provided by users, as outlined in the 'Process' section of SKILL.md.
  • Boundary markers: None. The skill does not suggest using delimiters or 'ignore' instructions for the embedded content.
  • Capability inventory: The skill facilitates the creation of Ruby script files (.rb) and the execution of shell commands (bundle exec rspec) as seen in SKILL.md and assets/examples.md.
  • Sanitization: The instructions do not include any steps for sanitizing or escaping the content captured from the user report before interpolating it into the test files.
  • [DYNAMIC_EXECUTION]: The skill generates and executes Ruby code at runtime based on user input and provided skeletons.
  • Evidence: In SKILL.md, the agent is instructed to create reproduction tests based on a 'Skeleton failing spec' and then execute them using bundle exec rspec. assets/spec-skeletons/reproduction_spec.rb provides a template for this dynamic code generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:20 PM
Security Audit — agent-trust-hub — rails-bug-triage