rust-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to utilize standard Rust development tools including cargo clippy, cargo fmt, cargo test, and cargo bench for validating code quality and correctness.
  • [EXTERNAL_DOWNLOADS]: Examples and references mention standard community crates such as tokio, reqwest, serde, sqlx, and thiserror. It also suggests the installation of well-known development utilities like cargo-tarpaulin, cargo-llvm-cov, and cargo-fuzz from official sources.
  • [DYNAMIC_EXECUTION]: The engineer's workflow involves generating Rust source code and performing runtime validation and benchmarking by executing the code via cargo test and cargo bench.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external source code and configuration files, which presents a surface for processing untrusted data.
  • Ingestion points: Reads and processes Rust source code files and Cargo.toml manifest files.
  • Boundary markers: None explicitly defined in the instructions to separate untrusted code input from the agent's core instructions.
  • Capability inventory: Includes the ability to execute toolchain commands (cargo), perform file system operations for code editing, and include network-capable code in generated output.
  • Sanitization: Relies on the underlying platform's existing safety mechanisms and the agent's internal content filters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:49 PM
Security Audit — agent-trust-hub — rust-engineer