Run cargo-audit and cargo-geiger on Rust code. Audits dependencies for known vulnerabilities and detects unsafe code usage for memory safety review.
Install
npx skillscat add vchirrav/product-security-ai-skills/sast-cargo-audit Install via the SkillsCat registry.
This skill runs cargo-audit and cargo-geiger to perform static analysis on Rust projects, identifying known dependency vulnerabilities and detecting unsafe code usage for memory safety review. It addresses security auditing needs by scanning for vulnerable crates and flagging unsafe Rust code that requires manual inspection. Developers should use it when conducting SAST scans or security reviews of Rust codebases.
SAST Scan with cargo-audit & cargo-geiger (Rust)
You are a security engineer running static analysis on Rust code using cargo-audit (dependency vulnerabilities) and cargo-geiger (unsafe code detection).
When to use
Use this skill when asked to perform a SAST scan or security review on a Rust project.
Prerequisites
- cargo-audit installed (
cargo install cargo-audit) - cargo-geiger installed (
cargo install cargo-geiger) - Verify:
cargo audit --versionandcargo geiger --version
Instructions
Dependency Vulnerability Audit
Run cargo-audit:
cargo audit --json > cargo-audit-results.json- Fix automatically:
cargo audit fix - Deny warnings:
cargo audit --deny warnings
- Fix automatically:
Parse the results — Present findings:
| # | Advisory ID | Severity | Crate | Installed | Patched | Description | Remediation |
|---|-------------|----------|-------|-----------|---------|-------------|-------------|Unsafe Code Detection
Run cargo-geiger:
cargo geiger --output-format=json > cargo-geiger-results.jsonParse the results — Present unsafe usage summary:
| Crate | Unsafe Functions | Unsafe Expressions | Unsafe Impls | Unsafe Traits |
|-------|-----------------|-------------------|--------------|---------------|- Summarize — Provide:
- Total vulnerabilities found and their severities
- Unsafe code hotspots requiring manual review
- Upgrade recommendations for vulnerable dependencies
- Whether
#[forbid(unsafe_code)]is used at crate level