ruby-pro
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and generate Ruby code, which creates a surface for indirect prompt injection if the data being processed contains hidden instructions meant to manipulate the agent.
- Ingestion points: User-provided Ruby source files, Rails project structures, and third-party Gem documentation (e.g., via
resources/implementation-playbook.md). - Boundary markers: The skill lacks explicit instructions for the agent to ignore or delimit instructions found within user-provided source code or data files.
- Capability inventory: The skill body itself does not define direct shell commands or file-write operations, though the agent using it may have these capabilities separately.
- Sanitization: No input validation or instruction sanitization logic is present in the skill.
- [SAFE]: No instances of data exfiltration, credential exposure, obfuscation, or unauthorized command execution were detected in the skill instructions.
Audit Metadata