rails-security-review
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is composed entirely of Markdown documentation (SKILL.md and PITFALLS.md). It contains no executable scripts, system commands, or network-enabled tools.
- [PROMPT_INJECTION]: The instructions include a 'HARD-GATE' section which mandates a specific output format for the security review. This is a benign organizational constraint for the AI's output and does not attempt to subvert safety filters or hijack the agent's underlying system prompt.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for analyzing external code, which is a potential source of indirect prompt injection. However, the instructions are inherently defensive, advising the agent to 'Assume any untrusted input can be abused' and focusing solely on static code review without providing capabilities for executing the analyzed code.
Audit Metadata