rust-agents-orchestrator
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [METADATA_POISONING]: The skill's metadata lists the author as 'OpenAEC-Foundation', which does not match the provided author context of 'impertio-studio'.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and run tools on user-provided Rust source code and Cargo.toml files. This creates a potential surface where malicious instructions embedded in the code (e.g., in comments or build.rs) could influence agent behavior or execute code during the quality check process.
- Ingestion points: Source code files (.rs), project manifest (Cargo.toml).
- Boundary markers: None identified.
- Capability inventory: Execution of cargo clippy, cargo test, and cargo doc via the agent's tool environment.
- Sanitization: No specific sanitization of code content before tool execution is mentioned.
- [COMMAND_EXECUTION]: The skill makes use of standard Rust toolchain commands to verify code quality, which is consistent with its stated purpose as an orchestrator and quality gate.
- [EXTERNAL_DOWNLOADS]: The skill references official Rust project documentation and widely used GitHub Actions for CI configuration. These are trusted resources for Rust development.
Audit Metadata