rails-ai:security

Fail

Audited by Socket on Feb 22, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Destructive bash command detected (rm -rf, chmod 777) All findings: [CRITICAL] command_injection: Destructive bash command detected (rm -rf, chmod 777) (CI004) [AITech 9.1.4] [CRITICAL] command_injection: Pipe-to-shell or eval pattern detected (CI013) [AITech 9.1.4] [CRITICAL] command_injection: Destructive bash command detected (rm -rf, chmod 777) (CI004) [AITech 9.1.4] [CRITICAL] command_injection: Destructive bash command detected (rm -rf, chmod 777) (CI004) [AITech 9.1.4] [CRITICAL] command_injection: Pipe-to-shell or eval pattern detected (CI013) [AITech 9.1.4] [CRITICAL] command_injection: Destructive bash command detected (rm -rf, chmod 777) (CI004) [AITech 9.1.4] [CRITICAL] command_injection: Destructive bash command detected (rm -rf, chmod 777) (CI004) [AITech 9.1.4] [HIGH] hardcoded_secrets: Generic secret pattern detected (HS005) [AITech 8.2] [HIGH] supply_chain: Installation of third-party script detected (SC006) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] BENIGN: The skill fragment functions as an in-depth security guidance document for Rails applications, offering patterns, anti-patterns, examples, and testing guidance. It does not execute code, exfiltrate data, or perform network actions in isolation. When used as a reference for secure development, it supports robust security practices with moderate to high confidence. Suggested improvements include linking to official sources for each pattern, adding actionable automated checks, and clarifying version-specific Rails considerations. LLM verification: The file is a benign, well-constructed security guidance document for Rails that clearly labels insecure patterns and provides secure alternatives. There is no evidence of embedded malware, obfuscated code, or secret harvesting. The primary risk is human/automation misuse: many high-risk shell and destructive command examples appear verbatim in antipattern sections and were flagged by static scanners. To reduce supply-chain risk, remove or further contextualize literal 'curl | bash' and 'rm -rf'

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 22, 2026, 07:32 AM
Package URL
pkg:socket/skills-sh/zerobearing2%2Frails-ai%2Frails-aisecurity%2F@00eb071460568a969a2c8f187a5df652cbd4203a
Security Audit — socket — rails-ai:security