serde-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill functions by ingesting and analyzing untrusted Rust source code and configuration files (Cargo.toml). This creates an inherent surface for indirect prompt injection, where an attacker could embed malicious instructions within the code being reviewed to influence the agent's output.
- Ingestion points: The skill workflow involves reading the Cargo.toml and relevant Rust source files as referenced in the Review Workflow and Gates sections.
- Boundary markers: There are no explicit boundary markers or instructions telling the agent to treat the code content purely as data to avoid executing instructions potentially contained within code comments or strings.
- Capability inventory: The skill is restricted to generating text findings based on its analysis and does not demonstrate capabilities for file writing, network access, or shell command execution.
- Sanitization: There is no evidence of input sanitization or filtering for the code content being processed.
Audit Metadata