[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"skill-rails-kr2s-was-i-exploited":3,"mdc--18lfjw-key":37,"related-org-rails-kr2s-was-i-exploited":102,"related-repo-rails-kr2s-was-i-exploited":126},{"slug":4,"name":4,"fn":5,"description":6,"org":7,"tags":11,"stars":27,"repoUrl":28,"updatedAt":29,"license":30,"forks":31,"topics":32,"repo":33,"sourceUrl":35,"mdContent":36},"kr2s-was-i-exploited","investigate Rails applications for CVE exploitation","Search a Rails application's Active Storage for evidence that CVE-2026-66066\nwas exploited against it, establish exactly what any crafted file read, and\ndecide whether that constitutes exfiltration. Requires an exposure window,\nwhich kr2s-was-i-vulnerable produces.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},"rails","Ruby on Rails","https:\u002F\u002Fpexgzepcugksgbtrxkhf.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Forg-logos\u002Frails.png",[12,16,19,22,25],{"name":13,"slug":14,"type":15},"Security","security","tag",{"name":17,"slug":18,"type":15},"Audit","audit",{"name":20,"slug":21,"type":15},"Code Analysis","code-analysis",{"name":23,"slug":24,"type":15},"Debugging","debugging",{"name":9,"slug":26,"type":15},"ruby-on-rails",15,"https:\u002F\u002Fgithub.com\u002Frails\u002Frails-forensics-CVE-2026-66066","2026-08-01T06:06:35.243268",null,1,[],{"repoUrl":28,"stars":27,"forks":31,"topics":34,"description":30},[],"https:\u002F\u002Fgithub.com\u002Frails\u002Frails-forensics-CVE-2026-66066\u002Ftree\u002FHEAD\u002Fskills\u002Fkr2s-was-i-exploited","---\nname: kr2s-was-i-exploited\ndescription: |\n  Search a Rails application's Active Storage for evidence that CVE-2026-66066\n  was exploited against it, establish exactly what any crafted file read, and\n  decide whether that constitutes exfiltration. Requires an exposure window,\n  which kr2s-was-i-vulnerable produces.\ntriggers:\n  - kr2s-was-i-exploited\n  - was i exploited\n  - were we exploited\n  - was this exploited\n  - did anyone exploit\n  - CVE-2026-66066 forensics\n  - GHSA-xr9x-r78c-5hrm forensics\n  - KindaRails2Shell forensics\n  - active storage forensics\n  - scan active storage for crafted files\n  - search for crafted mat files\n  - libvips arbitrary file read forensics\n  - matload arbitrary file read\n  - did anyone read our secrets\n  - check for exfiltration through active storage\n---\n\n# kr2s-was-i-exploited\n\nOpen `@references\u002Fguide.md` and follow it. Do not proceed without it.\n\nDetermines whether CVE-2026-66066 (GHSA-xr9x-r78c-5hrm) was exploited against a\nRails application's Active Storage, and if so, exactly what left the building.\n\nThis skill runs second. It cannot start without an exposure window, and\n`kr2s-was-i-vulnerable` is what produces one. If you do not have a start date\nand an end date, stop and run that skill first.\n\nIt produces a written analysis, not a verdict line. Finding crafted files is the\neasy half; establishing what they actually read, and whether that amounts to\nexfiltration or a researcher's harmless proof, is the half that takes judgment.\n",{"data":38,"body":54},{"name":4,"description":6,"triggers":39},[4,40,41,42,43,44,45,46,47,48,49,50,51,52,53],"was i exploited","were we exploited","was this exploited","did anyone exploit","CVE-2026-66066 forensics","GHSA-xr9x-r78c-5hrm forensics","KindaRails2Shell forensics","active storage forensics","scan active storage for crafted files","search for crafted mat files","libvips arbitrary file read forensics","matload arbitrary file read","did anyone read our secrets","check for exfiltration through active storage",{"type":55,"children":56},"root",[57,64,79,84,97],{"type":58,"tag":59,"props":60,"children":61},"element","h1",{"id":4},[62],{"type":63,"value":4},"text",{"type":58,"tag":65,"props":66,"children":67},"p",{},[68,70,77],{"type":63,"value":69},"Open ",{"type":58,"tag":71,"props":72,"children":74},"code",{"className":73},[],[75],{"type":63,"value":76},"@references\u002Fguide.md",{"type":63,"value":78}," and follow it. Do not proceed without it.",{"type":58,"tag":65,"props":80,"children":81},{},[82],{"type":63,"value":83},"Determines whether CVE-2026-66066 (GHSA-xr9x-r78c-5hrm) was exploited against a\nRails application's Active Storage, and if so, exactly what left the building.",{"type":58,"tag":65,"props":85,"children":86},{},[87,89,95],{"type":63,"value":88},"This skill runs second. It cannot start without an exposure window, and\n",{"type":58,"tag":71,"props":90,"children":92},{"className":91},[],[93],{"type":63,"value":94},"kr2s-was-i-vulnerable",{"type":63,"value":96}," is what produces one. If you do not have a start date\nand an end date, stop and run that skill first.",{"type":58,"tag":65,"props":98,"children":99},{},[100],{"type":63,"value":101},"It produces a written analysis, not a verdict line. Finding crafted files is the\neasy half; establishing what they actually read, and whether that amounts to\nexfiltration or a researcher's harmless proof, is the half that takes judgment.",{"items":103,"total":125},[104,112],{"slug":4,"name":4,"fn":5,"description":6,"org":105,"tags":106,"stars":27,"repoUrl":28,"updatedAt":29},{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[107,108,109,110,111],{"name":17,"slug":18,"type":15},{"name":20,"slug":21,"type":15},{"name":23,"slug":24,"type":15},{"name":9,"slug":26,"type":15},{"name":13,"slug":14,"type":15},{"slug":94,"name":94,"fn":113,"description":114,"org":115,"tags":116,"stars":27,"repoUrl":28,"updatedAt":124},"assess Rails application vulnerability to CVEs","Determine whether a Rails application was ever exposed to CVE-2026-66066, and\nif so produce the exposure window and the other facts a forensic sweep needs.\nRuns first; kr2s-was-i-exploited consumes its output.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[117,118,119,122,123],{"name":17,"slug":18,"type":15},{"name":20,"slug":21,"type":15},{"name":120,"slug":121,"type":15},"Risk Assessment","risk-assessment",{"name":9,"slug":26,"type":15},{"name":13,"slug":14,"type":15},"2026-08-01T06:06:33.131688",2,{"items":127,"total":125},[128,136],{"slug":4,"name":4,"fn":5,"description":6,"org":129,"tags":130,"stars":27,"repoUrl":28,"updatedAt":29},{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[131,132,133,134,135],{"name":17,"slug":18,"type":15},{"name":20,"slug":21,"type":15},{"name":23,"slug":24,"type":15},{"name":9,"slug":26,"type":15},{"name":13,"slug":14,"type":15},{"slug":94,"name":94,"fn":113,"description":114,"org":137,"tags":138,"stars":27,"repoUrl":28,"updatedAt":124},{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[139,140,141,142,143],{"name":17,"slug":18,"type":15},{"name":20,"slug":21,"type":15},{"name":120,"slug":121,"type":15},{"name":9,"slug":26,"type":15},{"name":13,"slug":14,"type":15}]