rust-desktop-applications
Pass
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The documentation includes standard setup instructions for the Rust development environment and platform tools which involve fetching and executing remote scripts from well-known sources.
- Evidence:
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | shinreferences/tauri-framework.md. - Evidence:
wget -O appimagetool "https://github.com/AppImage/AppImageKit/releases/download/continuous/appimagetool-x86_64.AppImage"inreferences/testing-deployment.md. - Context: These are the official and widely accepted installation methods for the Rust toolchain and AppImage utilities. They target trusted domains and are not considered malicious in this context.
- [DYNAMIC_EXECUTION]: The skill provides code patterns for developers to interact with the host operating system by executing shell commands, which is a core feature of the desktop frameworks being documented.
- Evidence:
Command::new(program).args(args).spawn()inreferences/tauri-framework.md. - Evidence: Platform-specific command calls using
osascript(macOS) andnotify-send(Linux) inreferences/platform-integration.md. - Context: These examples are intended for educational purposes. The skill explicitly warns developers about the security risks of unvalidated input and provides patterns for safe path handling and input validation.
- [INDIRECT_PROMPT_INJECTION]: The skill documents methods for reading files and fetching data from URLs, which represents a surface for indirect prompt injection if the resulting applications process this data through an LLM without proper sanitization.
- Ingestion points:
read_file_safeinreferences/platform-integration.md,fetch_datainreferences/tauri-framework.md. - Boundary markers: Not present in raw code snippets, but the documentation includes specific warnings about minimizing command surface area and validating inputs.
- Capability inventory: The skill documents file system writes (
fs::write) and command execution (Command::new) across multiple reference files. - Sanitization: A dedicated
validate_pathfunction is provided as a best practice example inreferences/platform-integration.mdto prevent directory traversal attacks.
Audit Metadata