rust-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to utilize standard Rust development tools including
cargo clippy,cargo fmt,cargo test, andcargo benchfor validating code quality and correctness. - [EXTERNAL_DOWNLOADS]: Examples and references mention standard community crates such as
tokio,reqwest,serde,sqlx, andthiserror. It also suggests the installation of well-known development utilities likecargo-tarpaulin,cargo-llvm-cov, andcargo-fuzzfrom official sources. - [DYNAMIC_EXECUTION]: The engineer's workflow involves generating Rust source code and performing runtime validation and benchmarking by executing the code via
cargo testandcargo bench. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external source code and configuration files, which presents a surface for processing untrusted data.
- Ingestion points: Reads and processes Rust source code files and
Cargo.tomlmanifest files. - Boundary markers: None explicitly defined in the instructions to separate untrusted code input from the agent's core instructions.
- Capability inventory: Includes the ability to execute toolchain commands (cargo), perform file system operations for code editing, and include network-capable code in generated output.
- Sanitization: Relies on the underlying platform's existing safety mechanisms and the agent's internal content filters.
Audit Metadata