OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Fail5 providerslatest audit Apr 16, 2026
Independent checks from skills.sh's audit partners.
The skill provides Rust code navigation via LSP and is legitimate in its core functionality. However, it is inherently vulnerable to indirect prompt injection because it ingests and processes untrusted source code from a user's workspace without sanitization. An automated scan flagged 'main.rs' as a malicious URL; while 'main.rs' is a filename in this context, the alert highlights the risk of the tool processing compromised project files.
Detected behaviors
No alerts
No issues
1/1 file flagged
Score: 93/100 · 2 sections analyzed