unsafe-rust-review-experimental

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to analyze Rust source code and accompanying safety documentation provided by users. This creates a surface where malicious instructions could be embedded in code comments or safety rationale to attempt to manipulate the auditor's conclusions. The skill mitigates this by explicitly instructing the agent to treat safety comments as theorems requiring independent proof and to reject any assertions that cannot be derived from authoritative language semantics.
  • Use of Trusted Technical Resources: The skill relies on and provides links to official Rust documentation hosted on doc.rust-lang.org. These references are used to ground the analysis in verified language facts and represent a standard practice for technical auditing tools.
  • Evaluation Fixture Context: The inclusion of historical snapshots and evaluation fixtures containing known code defects is used exclusively for benchmarking agent performance. These materials are properly isolated from the runtime package and are part of the skill's development infrastructure rather than executable code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 06:52 PM
Security Audit — agent-trust-hub — unsafe-rust-review-experimental