# Sast Cargo Audit

> Run cargo-audit and cargo-geiger on Rust code. Audits dependencies for known vulnerabilities and detects unsafe code usage for memory safety review.

- Skill: `vchirrav-eng/sast-cargo-audit` (Agent Skill)
- Install (CLI): `npx skillmds@latest add vchirrav-eng/sast-cargo-audit`
- Raw SKILL.md: https://api.skillmd.com/api/skills/vchirrav-eng/sast-cargo-audit/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: vchirrav-eng (https://skillmd.com/u/vchirrav-eng)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/vchirrav-eng/sast-cargo-audit

---


# SAST Scan with cargo-audit & cargo-geiger (Rust)

You are a security engineer running static analysis on Rust code using **cargo-audit** (dependency vulnerabilities) and **cargo-geiger** (unsafe code detection).

## When to use

Use this skill when asked to perform a SAST scan or security review on a Rust project.

## Prerequisites

- cargo-audit installed (`cargo install cargo-audit`)
- cargo-geiger installed (`cargo install cargo-geiger`)
- Verify: `cargo audit --version` and `cargo geiger --version`

## Instructions

### Dependency Vulnerability Audit

1. **Run cargo-audit:**
   ```bash
   cargo audit --json > cargo-audit-results.json
   ```
   - Fix automatically: `cargo audit fix`
   - Deny warnings: `cargo audit --deny warnings`

2. **Parse the results** — Present findings:

```
| # | Advisory ID | Severity | Crate | Installed | Patched | Description | Remediation |
|---|-------------|----------|-------|-----------|---------|-------------|-------------|
```

### Unsafe Code Detection

3. **Run cargo-geiger:**
   ```bash
   cargo geiger --output-format=json > cargo-geiger-results.json
   ```

4. **Parse the results** — Present unsafe usage summary:

```
| Crate | Unsafe Functions | Unsafe Expressions | Unsafe Impls | Unsafe Traits |
|-------|-----------------|-------------------|--------------|---------------|
```

5. **Summarize** — Provide:
   - Total vulnerabilities found and their severities
   - Unsafe code hotspots requiring manual review
   - Upgrade recommendations for vulnerable dependencies
   - Whether `#[forbid(unsafe_code)]` is used at crate level

