rails-dev
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses natural instructional language focused on development guidance. No patterns designed to override agent behavior, bypass safety filters, or extract system prompts were detected.
- [CREDENTIALS_UNSAFE]: No hardcoded credentials, API keys, or private keys were found. The skill does not contain any instructions that would lead to unsafe credential storage.
- [OBFUSCATION]: The skill's content is presented clearly in markdown. No Base64-encoded commands, zero-width characters, homoglyphs, or other obfuscation techniques were identified during analysis.
- [INDIRECT_PROMPT_INJECTION]: The skill documents how to handle untrusted user input in a Rails context and provides instructions for safe processing. 1. Ingestion points: The skill discusses handling request parameters (params) in controller and model contexts. 2. Boundary markers: The skill explicitly recommends using ActiveRecord's parameterized queries and strong parameters to define boundaries for untrusted data. 3. Capability inventory: The skill consists of instructional text and code snippets and does not possess active capabilities to execute commands or make network requests. 4. Sanitization: Explicit guidance on sanitizing user input and SQL queries is provided in security-focused reference files.
- [SAFE]: The skill serves as an educational guide for Ruby on Rails developers. All external links point to official documentation sites or reputable open-source projects.
Audit Metadata