ruby-dependency-injection

Warn

Audited by Gen Agent Trust Hub on Jun 27, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The file SKILL.md instructs the user to execute pip install ruby. Ruby is a standalone programming language and is not distributed as a Python package; therefore, this command refers to an unverifiable and potentially malicious package on PyPI.
  • Evidence: Step 1: Install: pip install ruby in SKILL.md.
  • [COMMAND_EXECUTION]: The skill directs the agent to execute shell commands for software installation and validation.
  • Evidence: pip install ruby and ruby --version in SKILL.md.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 27, 2026, 12:45 AM
Security Audit — agent-trust-hub — ruby-dependency-injection