rails-upgrade
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill performs network requests to
rubygems.orgto retrieve the latest patch versions for Rails series. This is a well-known service used for legitimate version discovery. - [DATA_EXFILTRATION]: The
workflows/gem-compatibility-workflow.mdinstructions guide the agent to POST the contents of the localGemfile.locktoapi.railsbump.org. This service is used to check for gem compatibility against target Rails versions. While the data transmitted consists of dependency metadata rather than credentials, it involves sending local project information to an external third-party service. - [COMMAND_EXECUTION]: The skill executes local shell commands such as
bundle exec rspec,bundle exec rails test, andrails app:updateto verify the application state and perform migrations. These are standard operations for the skill's primary purpose. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes the user's application code (Ruby files, YAML configurations, etc.) to detect breaking changes. This creates a vulnerability surface where malicious content embedded in the analyzed codebase could attempt to influence the agent's instructions.
- Ingestion points: Project files are searched and read using Grep and Read tools during the detection workflow.
- Boundary markers: The instructions do not explicitly define delimiters or "ignore embedded instructions" warnings for the agent when processing the results of file reads.
- Capability inventory: The skill possesses the capability to read files, write file changes, and execute arbitrary shell commands (e.g., test suites).
- Sanitization: No explicit sanitization or filtering of external code content is defined before the agent processes the findings.
Audit Metadata