rust-testing-code-review

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from project files, including Cargo.toml, source files (_test.rs), and integration test directories.
  • Ingestion points: Cargo.toml (SKILL.md) and source code files are read to identify the Rust edition and test patterns.
  • Boundary markers: There are no instructions to use delimiters or specific "ignore embedded instructions" warnings when reading these external files.
  • Capability inventory: The skill assumes capabilities to read the file system and perform complex code analysis; the instructions involve recommending or using tools like cargo test and cargo miri test (SKILL.md, advanced-testing.md, concurrency-testing.md).
  • Sanitization: No sanitization or escaping of the ingested content is described before the agent processes it for its review report.
  • [EXTERNAL_DOWNLOADS]: The skill references and encourages the use of standard Rust ecosystem tools and libraries such as cargo-fuzz, cargo-insta, rstest, sqlx, tokio, loom, miri, and criterion. These are well-known, established community resources used in standard development workflows.
  • [COMMAND_EXECUTION]: The skill provides numerous examples of command-line operations for testing, benchmarking, and tool installation, such as cargo install cargo-fuzz, RUSTFLAGS="--cfg loom" cargo test, and cargo +nightly miri test. These are standard and expected actions for a code review and testing automation tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:49 PM
Security Audit — agent-trust-hub — rust-testing-code-review