rust-patterns

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONOBFUSCATIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [OBFUSCATION]: The skill provides detailed instructions for implementing reverse-engineering resistance and hiding intent from security analysts.
  • Evidence includes recommendations in references/offensive-lowlevel.md for using obfstr and litcrypt to perform compile-time XOR encryption of strings such as URLs, mutexes, and file paths to hide Indicators of Compromise (IOCs).
  • It suggests using garble (a rustc-driver obfuscator) for control-flow and identifier renaming.
  • It recommends a release profile that strips all symbols and aborts on panic to minimize the diagnostic information available to analysts.
  • [DYNAMIC_EXECUTION]: The skill describes several methods for executing code dynamically, including patterns that bypass traditional filesystem monitoring.
  • references/dynamic-dispatch-and-plugins.md details "in-memory loading" via manual mapping on Windows, which involves manual allocation of memory, copying PE sections, and resolving import tables without using standard Windows loaders.
  • It describes file-less loading on Linux using memfd_create to create an anonymous file descriptor for an ELF binary and loading it via /proc/self/fd/.
  • [PERSISTENCE]: The skill explicitly includes persistence as a core module in its recommended architecture for offensive tooling.
  • In references/offensive-lowlevel.md, the "Offensive architecture patterns" section describes a modular monolith where "persistence" is listed alongside "encrypt, spread, and exfil" as standard capabilities.
  • [COMMAND_EXECUTION]: The skill encourages the use of direct syscalls to bypass operating system security APIs.
  • references/offensive-lowlevel.md details "Hell's Gate" family patterns for resolving syscall numbers at runtime by walking the PEB/export table and issuing syscalls via inline assembly to avoid detection by security software monitoring standard library calls.
  • [PRIVILEGE_ESCALATION]: The skill describes methods for manipulating memory protections that are commonly used in exploit development and shellcode execution.
  • references/offensive-lowlevel.md provides patterns for flipping page permissions (e.g., RW to RX) using VirtualProtect on Windows or mprotect on Linux to execute code in memory regions that were previously non-executable.
  • [EXTERNAL_DOWNLOADS]: The skill suggests mechanisms for binaries to download and execute code from remote sources.
  • references/dynamic-dispatch-and-plugins.md recommends self_update for pulling releases from GitHub, GitLab, and other platforms to automatically swap the running binary with a remote version.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a broad attack surface as it is designed to process and review arbitrary Rust source code.
  • Ingestion points: The skill ingests untrusted code during PR reviews or refactoring tasks as specified in SKILL.md.
  • Boundary markers: There are no instructions provided to the agent to treat code blocks as untrusted data or to ignore embedded instructions within processed files.
  • Capability inventory: The skill has access to extensive high-risk capabilities including FFI boundaries, unsafe blocks, subprocess execution (Command::new), and network operations for self-updating.
  • Sanitization: There are no described mechanisms for sanitizing or escaping the content of Rust files before they are processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — rust-patterns