rust
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill content is educational and focuses on secure systems programming in Rust. It explicitly addresses how to avoid common pitfalls like path traversal and command injection.
- [COMMAND_EXECUTION]: The skill provides code patterns for safe process execution using
Command::newwith explicit allowlists to mitigate risks like CVE-2024-24576. It correctly identifies the danger of shell-mediated execution. - [INDIRECT_PROMPT_INJECTION]: The skill describes methods for the agent to process untrusted data through Tauri IPC and file system operations.
- Ingestion points:
UserInputdata structures and path-joining parameters identified inSKILL.mdandreferences/advanced-patterns.md. - Boundary markers: Absent from the agent's high-level instructions, though implemented within the provided code examples.
- Capability inventory: Includes file system access and process execution through the Rust standard library.
- Sanitization: Strongly enforced through the recommended use of the
validatorcrate, regular expressions, and theduncecrate for safe path canonicalization.
Audit Metadata