soc2-rails

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as an educational resource providing Ruby on Rails code templates and architectural advice for achieving SOC 2 compliance. The patterns described (audit logs, MFA, access reviews) follow industry best practices for security and compliance.
  • [EXTERNAL_DOWNLOADS]: The skill references several well-known security and compliance services, including Drata, Vanta, Secureframe, and Snyk. These references are informative and point to established industry vendors, which is considered safe behavior.
  • [COMMAND_EXECUTION]: The skill includes shell command snippets for deployment auditing and GitHub branch protection. These are provided as documentation for users to implement in their own CI/CD pipelines and do not involve any automated or hidden execution by the agent.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user queries regarding SOC 2 and produces code templates. While it lacks explicit boundary markers for user-provided data, the risk is negligible as it provides static boilerplate code for models and controllers without executing user-influenced logic at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 03:48 AM
Security Audit — agent-trust-hub — soc2-rails