Rails
PassAudited by VirusTotal on May 12, 2026.
Overview
Type: OpenClaw Skill Name: rails Version: 1.0.1 The skill bundle consists entirely of markdown documentation detailing common pitfalls and best practices in Rails development, including security vulnerabilities. While `security.md` discusses critical vulnerabilities like SQL injection, arbitrary method calls, and RCE via `YAML.load`, it presents them as educational examples of 'traps' to avoid, explicitly advising against their use and recommending secure alternatives. There is no executable code, no instructions for the AI agent to perform malicious actions, exfiltrate data, or engage in prompt injection. The `SKILL.md` metadata merely declares a dependency on the `rails` binary, which is a capability, not a command to execute maliciously.
