rust
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No evidence of prompt injection or safety bypass attempts was found. The instructions are educational and focused on best practices for Rust development.
- [DATA_EXFILTRATION]: No exfiltration patterns were detected. The skill correctly advises using environment variables for secrets and emphasizes secure handling of sensitive information like database credentials.
- [REMOTE_CODE_EXECUTION]: No unauthorized or suspicious remote code execution patterns were found. The provided shell script
scripts/verify.shexecutes standard Rust toolchain commands (cargo fmt,cargo clippy,cargo test,cargo audit) to maintain code quality. - [EXTERNAL_DOWNLOADS]: The skill references well-known and trusted Rust ecosystem tools and libraries (e.g.,
cargo-audit,sqlx,tokio). Thescripts/verify.shscript may trigger standard library downloads viacargo, which is expected behavior for the Rust toolchain. - [COMMAND_EXECUTION]: The shell script
scripts/verify.shis a utility for developers to run local checks. It is well-documented, follows shell scripting best practices (set -euo pipefail), and only invokes standard development tools. - [INDIRECT_PROMPT_INJECTION]: While the skill teaches how to build web services that process untrusted data, it includes strong security guidance, such as using
sqlxbind parameters to prevent SQL injection and avoiding panics on untrusted input. It advocates for the "parse, don't validate" pattern to ensure data is correctly typed before processing. - [OBFUSCATION]: No obfuscation techniques were detected in any of the analyzed files.
Audit Metadata