rust-best-practices

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8) because its primary function involves processing untrusted source code provided by users for review or refactoring tasks.
  • Ingestion points: User-provided Rust source code, documentation comments, and project configuration files (e.g., Cargo.toml) which are ingested by the agent to provide architectural feedback and refactoring suggestions.
  • Boundary markers: The instructions do not specify the use of boundary markers (like XML tags or specific delimiters) to separate user code from agent instructions, nor do they include explicit warnings for the agent to ignore any natural language instructions embedded within comments or strings in the reviewed code.
  • Capability inventory: The skill environment permits powerful capabilities including Bash(cargo:*) (which can execute arbitrary code via build scripts or tests), Read, Write, and Edit operations on the local filesystem.
  • Sanitization: There is no documented process for the agent to sanitize or validate the content of user-provided code before analysis or execution (e.g., when running cargo test or cargo clippy as suggested in the testing and linting guidelines).
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 02:51 AM
Security Audit — agent-trust-hub — rust-best-practices