rust-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze, review, and refactor external Rust source code. This functionality creates an attack surface where malicious instructions embedded in the code files being processed could influence the agent's behavior during a review session.
- Ingestion points: The agent uses
Read,Glob, andGreptools to ingest content from project files. - Capability inventory: The skill allows the use of the
Bashtool to executecargo,rustc, and other development commands, providing a potential path for impact if the agent is misled by injected instructions. - Boundary markers: The skill does not provide explicit delimiters or instructions for the agent to ignore natural language commands found within the code comments or strings of the files it analyzes.
- Sanitization: No specific filtering or sanitization of ingested code content is implemented.
- [EXTERNAL_DOWNLOADS]: The reference materials provide instructions for installing common Rust development utilities, such as
flamegraphandcargo-insta, using the standardcargo installcommand to fetch packages from the official crates.io registry.
Audit Metadata