rust-desktop-applications

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The documentation includes standard setup instructions for the Rust development environment and platform tools which involve fetching and executing remote scripts from well-known sources.
  • Evidence: curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh in references/tauri-framework.md.
  • Evidence: wget -O appimagetool "https://github.com/AppImage/AppImageKit/releases/download/continuous/appimagetool-x86_64.AppImage" in references/testing-deployment.md.
  • Context: These are the official and widely accepted installation methods for the Rust toolchain and AppImage utilities. They target trusted domains and are not considered malicious in this context.
  • [DYNAMIC_EXECUTION]: The skill provides code patterns for developers to interact with the host operating system by executing shell commands, which is a core feature of the desktop frameworks being documented.
  • Evidence: Command::new(program).args(args).spawn() in references/tauri-framework.md.
  • Evidence: Platform-specific command calls using osascript (macOS) and notify-send (Linux) in references/platform-integration.md.
  • Context: These examples are intended for educational purposes. The skill explicitly warns developers about the security risks of unvalidated input and provides patterns for safe path handling and input validation.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents methods for reading files and fetching data from URLs, which represents a surface for indirect prompt injection if the resulting applications process this data through an LLM without proper sanitization.
  • Ingestion points: read_file_safe in references/platform-integration.md, fetch_data in references/tauri-framework.md.
  • Boundary markers: Not present in raw code snippets, but the documentation includes specific warnings about minimizing command surface area and validating inputs.
  • Capability inventory: The skill documents file system writes (fs::write) and command execution (Command::new) across multiple reference files.
  • Sanitization: A dedicated validate_path function is provided as a best practice example in references/platform-integration.md to prevent directory traversal attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 02:30 PM
Security Audit — agent-trust-hub — rust-desktop-applications