rust-review
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes various command-line tools for static analysis, including
ripgrep(rg) andawkto scan for specific code patterns, andcargofor linting (clippy) and dependency auditing.\n- [COMMAND_EXECUTION]: The skill runs a local Python script (plugins/imbue/scripts/citation_verifier.py) to validate that analysis findings are grounded in the source code by verifying citations against line numbers and verbatim anchors.\n- [INDIRECT_PROMPT_INJECTION]: The skill has an indirect prompt injection surface due to its core function of reading and processing untrusted Rust source files (**/*.rs).\n - Ingestion points: Processes all files matching the
.rsglob pattern within the repository.\n - Boundary markers: The skill requires findings to include verbatim anchors and citations verified by a script, providing a layer of validation, though it does not explicitly use delimiters like 'ignore embedded instructions' for the ingested code.\n
- Capability inventory: The skill uses shell execution tools (
rg,awk,cargo) and a local script execution environment (python).\n - Sanitization: The citation verifier script is used to ensure that findings correspond to actual source text rather than instructions embedded in code comments.
Audit Metadata