rails-upgrade-6-to-7

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation includes examples for running standard Rails generator commands like 'bin/rails turbo:install'. These are standard development tasks used to configure official gems and do not involve arbitrary command execution or shell injection risks.
  • [EXTERNAL_DOWNLOADS]: The skill correctly references official documentation from the Ruby on Rails guides and the official Rails GitHub organization for project dependencies. These downloads originate from trusted industry sources and are necessary for the stated purpose of a framework upgrade.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to respond to user-provided details about their codebase. It mitigates potential injection risks by providing specific, structured migration paths and referencing official documentation, rather than dynamically executing instructions found within the user's input.
  • [SAFE]: The skill performs no network exfiltration, persistence, or privilege escalation. The instructions are purely educational and focused on helping developers navigate a complex software upgrade safely.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 03:48 AM
Security Audit — agent-trust-hub — rails-upgrade-6-to-7