soc2-rails
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as an educational resource providing Ruby on Rails code templates and architectural advice for achieving SOC 2 compliance. The patterns described (audit logs, MFA, access reviews) follow industry best practices for security and compliance.
- [EXTERNAL_DOWNLOADS]: The skill references several well-known security and compliance services, including Drata, Vanta, Secureframe, and Snyk. These references are informative and point to established industry vendors, which is considered safe behavior.
- [COMMAND_EXECUTION]: The skill includes shell command snippets for deployment auditing and GitHub branch protection. These are provided as documentation for users to implement in their own CI/CD pipelines and do not involve any automated or hidden execution by the agent.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user queries regarding SOC 2 and produces code templates. While it lacks explicit boundary markers for user-provided data, the risk is negligible as it provides static boilerplate code for models and controllers without executing user-influenced logic at runtime.
Audit Metadata