rust-dev
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The guide instructs users to download and execute the official Rust toolchain installer from a remote server using a piped shell command. This is the standard installation procedure for the Rust programming language.
- Evidence (SKILL.md):
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh - [EXTERNAL_DOWNLOADS]: The skill recommends installing
kache, a third-party build cache utility, from an unverified GitHub repository (kunobi-ninja/kache) using themiseversion manager or a Homebrew tap. - Evidence (references/dev-environment.md):
mise use -g github:kunobi-ninja/kache@latest,brew install kunobi-ninja/kunobi/kache - [EXTERNAL_DOWNLOADS]: The documentation suggests installing the
baconutility crate via the Rust package manager for background background task execution. - Evidence (SKILL.md, references/dev-environment.md):
cargo install --locked bacon
Recommendations
- HIGH: Downloads and executes remote code from: https://sh.rustup.rs - DO NOT USE without thorough review
Audit Metadata