rust-review

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes various command-line tools for static analysis, including ripgrep (rg) and awk to scan for specific code patterns, and cargo for linting (clippy) and dependency auditing.\n- [COMMAND_EXECUTION]: The skill runs a local Python script (plugins/imbue/scripts/citation_verifier.py) to validate that analysis findings are grounded in the source code by verifying citations against line numbers and verbatim anchors.\n- [INDIRECT_PROMPT_INJECTION]: The skill has an indirect prompt injection surface due to its core function of reading and processing untrusted Rust source files (**/*.rs).\n
  • Ingestion points: Processes all files matching the .rs glob pattern within the repository.\n
  • Boundary markers: The skill requires findings to include verbatim anchors and citations verified by a script, providing a layer of validation, though it does not explicitly use delimiters like 'ignore embedded instructions' for the ingested code.\n
  • Capability inventory: The skill uses shell execution tools (rg, awk, cargo) and a local script execution environment (python).\n
  • Sanitization: The citation verifier script is used to ensure that findings correspond to actual source text rather than instructions embedded in code comments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:06 AM
Security Audit — agent-trust-hub — rust-review