rivetkit-client-rust

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No malicious instructions or bypass attempts were detected. Regarding indirect injection surface: (1) Ingestion points: Actor responses and events are processed in SKILL.md. (2) Boundary markers: None defined for actor data. (3) Capability inventory: Cargo commands and network requests via the client. (4) Sanitization: The skill provides sanitization guidance for actor keys to prevent injection.\n- [COMMAND_EXECUTION]: Standard cargo commands for dependency management are used. No suspicious or privileged shell activity was found.\n- [EXTERNAL_DOWNLOADS]: The skill suggests adding the rivetkit crate, a resource from the vendor rivet-dev, along with standard Rust libraries via cargo. These are documented as routine development tasks.\n- [DATA_EXFILTRATION]: No unauthorized data access or credential harvesting was detected. The skill uses placeholders for tokens and local addresses for endpoints in code examples.\n- [SAFE]: The skill provides best practice guidance, specifically warning against string interpolation for actor keys to prevent injection vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:03 PM
Security Audit — agent-trust-hub — rivetkit-client-rust