review-rust
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external Rust source code and git diffs. This ingestion of untrusted data represents an attack surface where malicious instructions in the code could attempt to influence the agent.
- Ingestion points:
SKILL.md(Step 1, Step 4) usesgit diffandgrepto read project files. - Boundary markers: Absent. The skill does not use specific delimiters to isolate file content from instructions.
- Capability inventory: Executes
git,grep, andcargocommands. - Sanitization: Absent; standard for code analysis tools.
- [COMMAND_EXECUTION]: The skill utilizes standard Rust development tools (
cargo,clippy) and shell utilities (git,grep) to perform its analysis. This includes runningcargo test, which compiles and executes the code being reviewed as part of the verification process. - [EXTERNAL_DOWNLOADS]: The skill uses
cargo, which interacts with the official Rust package registry (crates.io) to manage dependencies.
Audit Metadata