rust-best-practices

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze, review, and refactor external Rust source code. This functionality creates an attack surface where malicious instructions embedded in the code files being processed could influence the agent's behavior during a review session.
  • Ingestion points: The agent uses Read, Glob, and Grep tools to ingest content from project files.
  • Capability inventory: The skill allows the use of the Bash tool to execute cargo, rustc, and other development commands, providing a potential path for impact if the agent is misled by injected instructions.
  • Boundary markers: The skill does not provide explicit delimiters or instructions for the agent to ignore natural language commands found within the code comments or strings of the files it analyzes.
  • Sanitization: No specific filtering or sanitization of ingested code content is implemented.
  • [EXTERNAL_DOWNLOADS]: The reference materials provide instructions for installing common Rust development utilities, such as flamegraph and cargo-insta, using the standard cargo install command to fetch packages from the official crates.io registry.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:20 PM
Security Audit — agent-trust-hub — rust-best-practices