code-review-ruby
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides guidelines for analyzing untrusted Ruby/Rails source code, Gemfiles, and configuration files. This processing of external data represents an indirect prompt injection attack surface.
- Ingestion points: Ruby source files (.rb), Gemfile, config/routes.rb, and other application source files.
- Boundary markers: The reference does not specify explicit boundary markers for the data it analyzes.
- Capability inventory: The skill suggests using analysis tools like brakeman, semgrep, and ripgrep.
- Sanitization: Not explicitly defined within this reference guide.
Audit Metadata