tokio-async-code-review
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted user-provided content (Rust source code and project configuration files) without providing instructions for the agent to isolate or sanitize this data. This creates an attack surface where malicious instructions embedded within the reviewed code could potentially influence the agent's behavior.
- Ingestion points: Rust source files and Cargo.toml project configuration files.
- Boundary markers: None identified; the instructions do not specify the use of delimiters for untrusted content.
- Capability inventory: File system read access and text-based code analysis.
- Sanitization: None identified; the skill does not instruct the agent to sanitize or ignore instructions found within the data.
Audit Metadata