skills/ericrisco/rsc-harness/tauri/Gen Agent Trust Hub

tauri

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to analyze and modify local project files such as tauri.conf.json, capabilities JSON files, and Rust source code. This introduces a vulnerability surface where malicious content within a user's repository could potentially influence the agent's behavior.
  • Ingestion points: src-tauri/ directory, project source files, and configuration JSONs.
  • Boundary markers: The skill advocates for application-level security boundaries like CSP and the isolation pattern to mitigate risks from untrusted code.
  • Capability inventory: The agent performs file system operations and executes a local linting script.
  • Sanitization: The skill relies on standard agent safety filters when processing user-controlled files.
  • [COMMAND_EXECUTION]: The skill provides a shell script (scripts/verify.sh) for static linting of Tauri projects.
  • Evidence: The script uses standard Unix utilities like find, grep, awk, and sed to identify configuration errors. It is a read-only tool that does not perform network operations or unauthorized file modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — tauri