rails-review
Pass
Audited by Gen Agent Trust Hub on Apr 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection due to its core function of analyzing untrusted code changes while having access to high-privilege tools.\n- Ingestion points: The agent is instructed to read and analyze code diffs, commits, and repository files using tools like
Read,Grep, andGlob(SKILL.md).\n- Boundary markers: The instructions do not specify a way to distinguish between executable code logic and potentially malicious natural language instructions embedded within code comments or data strings in the reviewed files.\n- Capability inventory: The skill permits the use ofBash,Write, andEdittools, which provide the ability to execute shell commands or modify the file system if the agent is manipulated (SKILL.md).\n- Sanitization: No validation or sanitization process for the ingested code content is described in the guidelines.
Audit Metadata