37signals-style

Pass

Audited by Gen Agent Trust Hub on Mar 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as an educational resource for Rails developers, providing security-focused patterns such as DNS pinning and private IP blocking to prevent SSRF in webhook implementations.- [SAFE]: AI and LLM integration guides include mandatory security measures like user-scoping for tools, input pagination, and strict whitelisting of sort parameters to mitigate indirect prompt injection risks.- [SAFE]: The skill encourages the use of standard Rails security features, including CSRF protection, secure parameter handling via params.expect, and HTML sanitization.- [SAFE]: All mentioned external libraries (e.g., solid_queue, yabeda, prosopite) are reputable, well-known packages in the Ruby on Rails community.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 20, 2026, 10:24 AM