ffi-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted Rust source code and configuration files.
- Ingestion points: The skill instructs the agent to open and read project files such as
Cargo.toml,build.rs, and source files likesrc/ffi.rs(evidence inSKILL.md). - Boundary markers: The skill includes a structured "Gates" workflow in
SKILL.mdto govern the review process, providing a sequence of verification steps. - Capability inventory: The skill analysis requires file reading access. No instructions were found directing the agent to perform network requests or execute arbitrary shell commands.
- Sanitization: There is no requirement in the instructions for the agent to sanitize or escape the content of the analyzed files prior to processing.
Audit Metadata