skills/testland/qa/bundle-audit-ruby/Gen Agent Trust Hub

bundle-audit-ruby

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Executes shell commands to manage the auditing environment, including gem install bundler-audit and bundle-audit check --update.
  • [EXTERNAL_DOWNLOADS]: Downloads the bundler-audit gem from the RubyGems registry and clones the ruby-advisory-db from the RubySec GitHub organization.
  • [PROMPT_INJECTION]: Vulnerable to indirect prompt injection through the ingestion of external data.
  • Ingestion points: Processes local Gemfile.lock and .bundler-audit.yml files, and remote YAML advisories from ruby-advisory-db.
  • Boundary markers: Absent; there are no delimiters separating external content from agent instructions.
  • Capability inventory: Includes shell command execution and filesystem access.
  • Sanitization: No sanitization or validation of the ingested file content is performed prior to processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 10:53 AM
Security Audit — agent-trust-hub — bundle-audit-ruby