rails-bug-triage
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to capture bug reports and reproduction steps from a user and use that information to create failing RSpec tests. This creates a vulnerability surface where a malicious user could provide a bug report containing hidden instructions or code meant to be executed when the agent runs the generated test.
- Ingestion points: Untrusted bug reports, error logs, and reproduction steps provided by users, as outlined in the 'Process' section of
SKILL.md. - Boundary markers: None. The skill does not suggest using delimiters or 'ignore' instructions for the embedded content.
- Capability inventory: The skill facilitates the creation of Ruby script files (
.rb) and the execution of shell commands (bundle exec rspec) as seen inSKILL.mdandassets/examples.md. - Sanitization: The instructions do not include any steps for sanitizing or escaping the content captured from the user report before interpolating it into the test files.
- [DYNAMIC_EXECUTION]: The skill generates and executes Ruby code at runtime based on user input and provided skeletons.
- Evidence: In
SKILL.md, the agent is instructed to create reproduction tests based on a 'Skeleton failing spec' and then execute them usingbundle exec rspec.assets/spec-skeletons/reproduction_spec.rbprovides a template for this dynamic code generation.
Audit Metadata