skills/ericrisco/rsc-harness/rust/Gen Agent Trust Hub

rust

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of prompt injection or safety bypass attempts was found. The instructions are educational and focused on best practices for Rust development.
  • [DATA_EXFILTRATION]: No exfiltration patterns were detected. The skill correctly advises using environment variables for secrets and emphasizes secure handling of sensitive information like database credentials.
  • [REMOTE_CODE_EXECUTION]: No unauthorized or suspicious remote code execution patterns were found. The provided shell script scripts/verify.sh executes standard Rust toolchain commands (cargo fmt, cargo clippy, cargo test, cargo audit) to maintain code quality.
  • [EXTERNAL_DOWNLOADS]: The skill references well-known and trusted Rust ecosystem tools and libraries (e.g., cargo-audit, sqlx, tokio). The scripts/verify.sh script may trigger standard library downloads via cargo, which is expected behavior for the Rust toolchain.
  • [COMMAND_EXECUTION]: The shell script scripts/verify.sh is a utility for developers to run local checks. It is well-documented, follows shell scripting best practices (set -euo pipefail), and only invokes standard development tools.
  • [INDIRECT_PROMPT_INJECTION]: While the skill teaches how to build web services that process untrusted data, it includes strong security guidance, such as using sqlx bind parameters to prevent SQL injection and avoiding panics on untrusted input. It advocates for the "parse, don't validate" pattern to ensure data is correctly typed before processing.
  • [OBFUSCATION]: No obfuscation techniques were detected in any of the analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — rust