ruby-pro

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and generate Ruby code, which creates a surface for indirect prompt injection if the data being processed contains hidden instructions meant to manipulate the agent.
  • Ingestion points: User-provided Ruby source files, Rails project structures, and third-party Gem documentation (e.g., via resources/implementation-playbook.md).
  • Boundary markers: The skill lacks explicit instructions for the agent to ignore or delimit instructions found within user-provided source code or data files.
  • Capability inventory: The skill body itself does not define direct shell commands or file-write operations, though the agent using it may have these capabilities separately.
  • Sanitization: No input validation or instruction sanitization logic is present in the skill.
  • [SAFE]: No instances of data exfiltration, credential exposure, obfuscation, or unauthorized command execution were detected in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 07:01 AM
Security Audit — agent-trust-hub — ruby-pro