rust-service-scaffold
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill performs build and test verification using standard Rust toolchain commands (
cargo build --locked,cargo test --locked,cargo clippy,cargo fmt). These operations are conducted on the generated service scaffold to ensure code quality and build integrity, which is expected and safe behavior for a development-focused skill. - [DATA_EXPOSURE]: The instructions mandate a 'Secure by default' posture, specifically forbidding the inclusion of hardcoded secrets in configuration files and requiring the use of environment-variable-based secret management.
- [SAFE]: The skill incorporates robust security defaults for the generated output, including non-root Docker runtime users, mandatory request timeouts, body-size limits, and the explicit prohibition of
unsafeblocks in request handlers.
Audit Metadata