Rust Security

mohitmishra786/low-level-dev-skills/skills/rust/rust-security

作者 mohitmishra786bdc58472fa9f無授權條款253 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫3 個月前更新

Rust security skill for supply chain safety and memory-safe development. Use when auditing dependencies with cargo-audit, enforcing policies with cargo-deny, reviewing RUSTSEC advisories, writing memory-safe FFI patterns, or integrating fuzzing and Miri into a security review pipeline. Activates on queries about cargo-audit, cargo-deny, RUSTSEC advisories, supply chain security, Rust CVEs, safe FFI, or fuzzing for security.

AI 產生的概覽

指導 Rust 安全工作:相依性稽核、政策強制、RUSTSEC 公告、安全 FFI、模糊測試與 Miri。

功能
此技能提供稽核 Rust 專案安全問題的操作說明。內容涵蓋使用 cargo-audit 掃描弱點、使用 cargo-deny 強制政策、查閱 RUSTSEC 公告資料庫、撰寫記憶體安全的 FFI 模式、使用 cargo-fuzz 與 honggfuzz 進行模糊測試,以及用 Miri 檢查健全性。也說明供應鏈強化步驟,例如鎖定 lockfile、使用 cargo-vet 審查,以及找出未使用的相依套件。它產出的是指引與指令範例,而非檔案或指令碼。
適用情境
適用於檢查 Rust 相依套件中的 CVE、在 CI 中強制相依政策、查閱 RUSTSEC 公告,或強化 Rust 程式碼庫。也適合對 unsafe 或 FFI 程式碼進行安全審查,以及在安全流程中設定模糊測試與 Miri。
執行需求
不隨附指令碼,僅為說明性內容。依指引操作需要 Rust 工具鏈與 Cargo,以及需另行安裝的選用工具:cargo-audit、cargo-deny、cargo-fuzz、honggfuzz、cargo-vet、cargo-machete,以及帶有 Miri 的 nightly 工具鏈。取得 crate、公告資料庫與 RUSTSEC 公告資料需要網路存取。

Rust Security

Purpose

Guide agents through Rust security practices: dependency auditing with cargo-audit, policy enforcement with cargo-deny, RUSTSEC advisory database, memory-safe patterns for FFI, and combining fuzzing with Miri for security review.

Triggers

  • "How do I check my Rust dependencies for CVEs?"
  • "How do I use cargo-audit?"
  • "How do I enforce dependency policies in CI?"
  • "What's the RUSTSEC advisory database?"
  • "How do I write memory-safe FFI in Rust?"
  • "How do I fuzz-test my Rust library for security bugs?"

Workflow

1. cargo-audit — vulnerability scanning

bash
# Installcargo install cargo-audit --locked
# Scan current projectcargo audit
# Full output including ignoredcargo audit --deny warnings
# Audit the lockfile (CI-friendly)cargo audit --file Cargo.lock
# JSON output for CI integrationcargo audit --json | jq '.vulnerabilities.list[].advisory.id'

Output format:

error[RUSTSEC-2023-0052]: Vulnerability in `vm-superio`    Severity: low       Title: MMIO Register Misuse    Solution: upgrade to `>= 0.7.0`

2. cargo-deny — policy enforcement

cargo-deny goes beyond audit: it enforces license policies, bans specific crates, checks source origins, and validates duplicate dependency versions.

bash
cargo install cargo-deny --locked
# Initialize deny.tomlcargo deny init
# Run all checkscargo deny check
# Run specific checkcargo deny check advisoriescargo deny check licensescargo deny check banscargo deny check sources

deny.toml configuration:

toml
[advisories]vulnerability = "deny"      # Deny known vulnerabilitiesunmaintained = "warn"       # Warn on unmaintained cratesyanked = "deny"             # Deny yanked versions
# Ignore specific advisoriesignore = [    "RUSTSEC-2021-0145",    # known false positive for our usage]
[licenses]unlicensed = "deny"allow = [    "MIT", "Apache-2.0", "Apache-2.0 WITH LLVM-exception",    "BSD-2-Clause", "BSD-3-Clause", "ISC", "Unicode-DFS-2016",]# Deny GPL for proprietary projectsdeny = ["GPL-2.0", "GPL-3.0"]
[bans]multiple-versions = "warn"  # Warn if same crate appears twicewildcards = "deny"          # Deny wildcard dependencies
[[bans.deny]]name = "openssl"            # Force rustls insteadwrappers = ["reqwest"]      # Allow if only required by these
[sources]unknown-registry = "deny"unknown-git = "deny"allow-git = [    "https://github.com/my-org/private-crate",]

GitHub Actions CI integration:

yaml
- name: Security audit  run: |    cargo install cargo-deny --locked    cargo deny check

3. RUSTSEC advisory database

The RUSTSEC database at https://rustsec.org/ tracks vulnerabilities, unmaintained crates, and unsound code.

bash
# Browse advisories from CLIcargo audit --db ~/.cargo/advisory-db fetchls ~/.cargo/advisory-db/crates/
# Check a specific advisorycurl https://rustsec.org/advisories/RUSTSEC-2023-0001.json | jq .
# Common categories# type: vulnerability — exploitable security bug# type: unmaintained — no longer maintained (supply chain risk)# type: unsound — documented unsoundness in safe API# type: yanked — crate version yanked from crates.io

4. Memory-safe FFI patterns

Common sources of unsafety at the Rust/C boundary:

rust
// UNSAFE pattern — raw pointer from C, no lifetimeextern "C" fn process_data(data: *const u8, len: usize) {    // Don't do this — no bounds check, no lifetime guarantee    let slice = unsafe { std::slice::from_raw_parts(data, len) };}
// SAFE pattern — validate before usingextern "C" fn process_data(data: *const u8, len: usize) -> i32 {    // Validate pointer and length    if data.is_null() || len == 0 || len > 1024 * 1024 {        return -1;    }    // Safety: non-null, len validated, called from C with valid buffer    let slice = unsafe { std::slice::from_raw_parts(data, len) };    do_work(slice);    0}
// Use safe wrapper crates for common patternsuse nix::unistd::read;   // safe POSIX wrappersuse windows::Win32::System::Memory::VirtualAlloc;  // safe Windows bindings

5. Fuzzing for security bugs

bash
# cargo-fuzz — libFuzzer-basedcargo install cargo-fuzz
# Initializecargo fuzz initcargo fuzz add my_target
# fuzz/fuzz_targets/my_target.rs# #![no_main]# use libfuzzer_sys::fuzz_target;# fuzz_target!(|data: &[u8]| {#     if let Ok(s) = std::str::from_utf8(data) {#         let _ = my_lib::parse(s);#     }# });
# Run fuzzing (long-running)cargo fuzz run my_target
# With sanitizers for security coveragecargo fuzz run my_target -- -sanitizer=address
# Reproduce a crashcargo fuzz run my_target artifacts/my_target/crash-xxxx
bash
# Honggfuzz — good for security targetscargo install honggfuzzcargo hfuzz run my_target

6. Miri for soundness

bash
# Install Mirirustup +nightly component add miri
# Run tests under Miricargo +nightly miri test
# Check for UB in unsafe codeMIRIFLAGS="-Zmiri-disable-isolation -Zmiri-backtrace=full" \  cargo +nightly miri test
# Miri detects:# - Use-after-free# - Dangling references# - Invalid pointer arithmetic# - Data races (with -Zmiri-tree-borrows)# - Uninitialized memory reads

7. Supply chain hardening

bash
# Pin Cargo.lock in applications (not libraries)# Always commit Cargo.lock for binaries
# Verify checksums (cargo already does this)cargo fetch --locked    # fails if Cargo.lock doesn't match
# Audit all dependencies including transitivecargo tree              # view full dependency treecargo tree -d           # show duplicate versions
# Use cargo-vet for peer review of new depscargo install cargo-vetcargo vet              # check all deps have been vetted
# Minimal dependency principlecargo machete          # finds unused dependencies

Related skills

  • Use skills/rust/rust-sanitizers-miri for Miri and sanitizer details
  • Use skills/runtimes/fuzzing for fuzzing strategy and corpus management
  • Use skills/rust/rust-unsafe for unsafe code audit patterns
  • Use skills/rust/cargo-workflows for Cargo.lock and workspace management

來源與署名

來源:mohitmishra786/low-level-dev-skills位於skills/rust/rust-security提交bdc5847

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架