unsafe-rust-review-experimental

Warn

Audited by Socket on Sep 26, 2026

12 alerts found:

Anomalyx8Securityx4
AnomalyLOW
evals/unsafe-rust/fixtures/v5-diagnostic-prequalification/e_semantics/src/lib.rs

No evidence of malicious behavior or obfuscation. `boundary_or` contains a serious unsafe indexing bug: for every nonempty slice it performs an out-of-bounds unchecked access, causing undefined behavior. Avoid calling it until corrected, for example by using `len - 1` or checked indexing as appropriate.

Confidence: 99%Severity: 68%
SecurityMEDIUM
evals/unsafe-rust/fixtures/v3-targeted/k_regression/lib.rs

No malicious behavior is evident. The main issue is memory unsafety: the safe `callback_index` APIs permit out-of-bounds unchecked access through a caller-provided `Position` implementation. The `Lane` API also relies on an undocumented unsafe implementation contract. Validate indices or use checked indexing.

Confidence: 99%Severity: 78%
AnomalyLOW
evals/unsafe-rust/fixtures/pilot/synthetic-vulnerable/src/lib.rs

No evidence of malicious behavior or obfuscation. The code does contain several memory-safety hazards involving invalid boolean transmutation, unchecked raw-pointer reads, and unchecked slice indexing. These can cause undefined behavior if callers violate implicit pointer or bounds assumptions.

Confidence: 99%Severity: 68%
AnomalyLOW
evals/unsafe-rust/fixtures/v2-forward/i_producer/lib.rs

No evidence of malicious behavior. The code contains a memory-safety defect: the safe from_static/overwrite path permits writing to immutable static storage through a cast mutable pointer, causing undefined behavior. The unsafe raw-pointer constructor also relies on caller-provided validity guarantees.

Confidence: 99%Severity: 63%
SecurityMEDIUM
evals/unsafe-rust/fixtures/v5-diagnostic-prequalification/q_metamorphic/src/lib.rs

No clear malicious behavior is present. local_text(false) creates an invalid &str using unchecked UTF-8 conversion, resulting in undefined behavior and a significant memory-safety defect. The delegated decoder relies on its documented unsafe caller precondition.

Confidence: 99%Severity: 72%
AnomalyLOW
evals/unsafe-rust/fixtures/v3-targeted/x_cross/src/lib.rs

No evidence of malicious behavior. There is a configuration-specific memory-safety defect: callers can pass zero in burst/aarch64/arena builds, causing undefined behavior through `new_unchecked`. Validate the input in every configuration or make the API enforce the nonzero invariant.

Confidence: 98%Severity: 62%
AnomalyLOW
evals/unsafe-rust/fixtures/v5-diagnostic-prequalification/b_build/src/lib.rs

No malicious behavior is evident. There is a configuration-specific unsafe correctness flaw: a caller can pass zero in the `burst` + `aarch64` + arena configuration, violating the `new_unchecked` precondition and causing undefined behavior. Validate the input in that branch or use the checked constructor.

Confidence: 99%Severity: 62%
SecurityMEDIUM
evals/unsafe-rust/fixtures/v5-diagnostic-prequalification/v_valid_use/src/lib.rs

The code contains a concrete unsafe-trait contract violation that causes undefined behavior when `owned` is called. This is a serious memory-safety defect, but the snippet provides no evidence of malware or intentional data theft.

Confidence: 99%Severity: 72%
AnomalyLOW
evals/unsafe-rust/fixtures/abstraction-design-v1/e_configuration_domain/lib.rs

No malicious behavior is present. The compact implementation has a memory-safety issue: release builds may pass surrogate values to char::from_u32_unchecked, violating its safety contract. Validate the value in all builds or use the checked conversion.

Confidence: 99%Severity: 55%
SecurityMEDIUM
evals/unsafe-rust/fixtures/abstraction-design-v1/i_new_snapshot/lib.rs

This code is not indicative of malware, but its safe API is unsound: get_mut can produce aliased mutable references, and get can overlap with a later mutable reference. This is a memory-safety vulnerability that should be corrected by tying returned reference lifetimes to the method borrow or otherwise enforcing exclusivity.

Confidence: 99%Severity: 78%
AnomalyLOW
evals/unsafe-rust/fixtures/v5-diagnostic-prequalification/r_redesign/lib.rs

No evidence of malware or obfuscation. The function has a memory-safety flaw: because Slot is public and externally implementable, an out-of-range index can trigger undefined behavior through unchecked indexing. Validate the index or constrain the trait/API so the range is guaranteed.

Confidence: 99%Severity: 63%
AnomalyLOW
evals/unsafe-rust/fixtures/v2-forward/u_behavior/lib.rs

No malicious behavior is evident. The function has a serious unsafe correctness defect: passing 0 reaches `unreachable_unchecked()` and causes undefined behavior. Callers must not rely on this function being safe for arbitrary u8 inputs unless the zero case is fixed or ruled out by a sound precondition.

Confidence: 99%Severity: 62%
Audit Metadata
Analyzed At
Sep 26, 2026, 06:54 PM
Package URL
pkg:socket/skills-sh/google%2Frust-skills%2Funsafe-rust-review-experimental%2F@97749979b59be2e8c9f7db5f45764f9f3198a7189efa1ac5c10fc7fdff1d3559
Security Audit — socket — unsafe-rust-review-experimental