rails-guides

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of markdown-based reference material and documentation. There are no executable scripts or binary files included in the distribution.
  • [SAFE]: Security-related sections in references/security.md and references/active_record_querying.md include examples of cross-site scripting (XSS) and SQL injection payloads. These are provided as educational examples to help developers identify and mitigate such threats and are context-bound within the documentation text.
  • [SAFE]: All identified sensitive strings, such as API keys or passwords in references/active_record_encryption.md and references/active_record_multiple_databases.md, are either placeholders for environment variables (e.g., <%= ENV['ROOT_PASSWORD'] %>) or dummy values generated in example CLI outputs.
  • [SAFE]: External URL references point exclusively to official framework resources (rubyonrails.org), academic/informational sites (Wikipedia), or well-established open-source repositories on GitHub (github.com/rails/*).
  • [SAFE]: Base64 encoded strings in references/action_cable_overview.md and references/security.md represent framework-specific URI formats (GlobalIDs) or example attack vectors used for teaching security concepts, consistent with the skill's nature as a technical manual.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:21 PM
Security Audit — agent-trust-hub — rails-guides