rust-pro
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill configuration allows access to the
Bashtool. While necessary for Rust development (compilation, testing), it grants the agent capability to execute arbitrary shell commands. - [EXTERNAL_DOWNLOADS]: The skill is instructed to fetch documentation and package information from external sources such as crates.io and library repositories via the Context7 MCP server.
- [INDIRECT_PROMPT_INJECTION]: By design, the skill ingests data from external library documentation. This creates a surface for indirect prompt injection if an attacker-controlled library contains malicious instructions within its documentation or README files.
Audit Metadata