rails-guides
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of markdown-based reference material and documentation. There are no executable scripts or binary files included in the distribution.
- [SAFE]: Security-related sections in
references/security.mdandreferences/active_record_querying.mdinclude examples of cross-site scripting (XSS) and SQL injection payloads. These are provided as educational examples to help developers identify and mitigate such threats and are context-bound within the documentation text. - [SAFE]: All identified sensitive strings, such as API keys or passwords in
references/active_record_encryption.mdandreferences/active_record_multiple_databases.md, are either placeholders for environment variables (e.g.,<%= ENV['ROOT_PASSWORD'] %>) or dummy values generated in example CLI outputs. - [SAFE]: External URL references point exclusively to official framework resources (
rubyonrails.org), academic/informational sites (Wikipedia), or well-established open-source repositories on GitHub (github.com/rails/*). - [SAFE]: Base64 encoded strings in
references/action_cable_overview.mdandreferences/security.mdrepresent framework-specific URI formats (GlobalIDs) or example attack vectors used for teaching security concepts, consistent with the skill's nature as a technical manual.
Audit Metadata