Agent skill

Rust Code Review

by apollographql in apollographql/rust-best-practices

Rust Code review checklist and decision framework for Rust PRs, derived from rust-best-practices.

Apache-2.0Auto-check passedDevelopment

Install Rust Code Review

skills CLI
$ npx skills add apollographql/rust-best-practices --skill rust-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install apollographql/rust-best-practices rust-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/apollographql/rust-best-practices.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/rust-code-review .claude/skills/rust-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rust-code-review
GitHub stars
157
Token cost
~1k tokens
SKILL.md length
490 words
Files
2
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

Rust Code review checklist and decision framework for Rust PRs, derived from rust-best-practices.

  • Tasks that involve Code review
  • SKILL.md covers Mandatory pre-merge checks, Severity matrix, Review skills and Quick rejection triggers
  • Calls cargo

What it does

Rust Code Review is an agent skill from apollographql/rust-best-practices. Rust Code review checklist and decision framework for Rust PRs, derived from rust-best-practices.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development, covering Code review. It works with Rust. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Code review

Example prompts

  • “/rust-code-review”

What it can do on your machine

Read from SKILL.md and the folder at commit eb485a5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rust Code Review loads about 1k tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 490 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from apollographql/rust-best-practices at commit eb485a5, republished under its Apache-2.0 licence (© apollographql). 490 words, ~1,015 tokens.

Download SKILL.mdSave it as .claude/skills/rust-code-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
rust-code-review
description
Rust Code review checklist and decision framework for Rust PRs, derived from rust-best-practices.
globs
**/*.rs
alwaysApply
true

Rust Code Review

Use this for Rust review work where consistency, safety, and maintainability matter.

Follow ths standards in https://github.com/apollographql/rust-best-practices

Mandatory pre-merge checks

  • Ownership and data flow are intentional.
  • Error handling is explicit and aligns with crate/binary boundaries.
  • Clippy and format quality are clean in touched files.
  • Performance changes are measured before acceptance.
  • Public APIs are documented; docs match runtime behavior.
  • Tests cover intended behavior and error paths.
  • Unsafe or raw-pointer usage is justified and constrained.

Severity matrix

  • P0: unsafe memory bug, panic in recoverable production path, silent data corruption.
  • P1: correctness bug, missing error propagation, invalid API contract.
  • P2: likely performance regression, missing public API docs, flaky tests.
  • P3: style/readability issues, avoidable clone/allocation, unnecessary complexity.

Review skills

Ownership-first coding
  • Prefer borrowing (&T, &mut T) over cloning.
  • Use Clone only when ownership is required or snapshots are explicitly needed.
  • Treat unnecessary clones (especially in loops) as likely regressions.
  • Reject clone on Copy types.
Value vs reference
  • Pass Copy/small POD types by value.
  • Pass large heap-backed or non-trivial objects by reference.
  • Surface ownership intent in function signatures.
  • Use Cow<'_, T> when input may be borrowed or owned.
Fallible control flow
  • Use let PATTERN = EXPR else { ... } for expected early exits.
  • Use if let ... else when divergence needs additional logic.
  • Prefer ? for bubbling errors.
  • Avoid unwrap/expect in production except when impossible-by-design cases are documented.
Allocation and allocation timing
  • Prefer _else APIs to avoid eager allocation (ok_or_else, map_or_else, etc.).
  • Keep iterator chains lazy; allocate only when required by terminal ops.
  • Do not collect and allocate only to throw away data.
Iterator vs loop
  • Use iterator chains for data transformation and composition.
  • Use for for early exits and side-effect-heavy or control-heavy loops.
  • Require readable formatting; avoid long unreadable chains.
Show full SKILL.md (206 more words)Show less
Lints and static checks
  • Run and fix warnings from:
    • cargo clippy --all-targets --all-feature --locked -- -D warnings
  • Do not globally silence useful lints.
  • Prefer #[expect(clippy::...)] with rationale instead of #[allow(...)] unless fully justified.
Error discipline
  • Libraries: prefer typed errors (thiserror and #[from] conversions).
  • Binaries: anyhow acceptable, but keep context rich and actionable.
  • Test both success and error behavior.
Tests as behavior docs
  • One behavior per test.
  • One core assertion per test where possible.
  • Names should be descriptive sentence-like statements.
  • Prefer unit tests for internals, integration tests for public behavior.
  • Use snapshot tests only for complex, stable structured outputs.
Documentation and comments
  • Use //////! for API behavior and constraints.
  • Use // for why, safety rationale, platform constraints, and assumptions.
  • Remove stale comments; prefer smaller functions over narrative comments.
  • Link TODOs to issues instead of leaving bare TODO:.
Pointers and concurrency
  • Prefer &/&mut before any heap pointer.
  • Use Arc for cross-thread shared ownership; Rc for single-threaded.
  • Use Box for recursive/heap allocation needs.
  • Review raw pointer usage as unsafe boundaries with explicit invariants.

Quick rejection triggers

  • Unnecessary clones in hot paths.
  • Unjustified allow(clippy::...).
  • Silent recovery from Err that discards root cause.
  • Copying large types by value without a proof of intent.
  • Comments that simply restate what code already expresses.
  • TODOs without ownership/context.

© apollographql, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .codex/skills/rust-code-review of apollographql/rust-best-practices.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit eb485a5

Compare with similar skills

Rust Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rust Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rust Code Review this skillapollographql/rust-best-practices157—~1kAutomated safety check: PassApache-2.0
Worktrunk Tend CI Guidancemax-sixty/worktrunk9k—~6.4kAutomated safety check: PassCustom licence
SeekDB Code Reviewoceanbase/seekdb3.1k—~2.1kAutomated safety check: PassApache-2.0
PR Reviewjaemk/self_update961—~1.5kAutomated safety check: NotesMIT
PR Reviewjaemk/cached2.1k—~2.5kAutomated safety check: NotesMIT
Cross-Language Coding Standardszereight/gitlab-mcp2k1 repos~1.4kAutomated safety check: PassMIT

Similar skills

  • Worktrunk Tend CI Guidance

    max-sixty/worktrunk

    Adds Worktrunk-specific rules to the tend CI workflows: Codecov polling, Rust test commands, labels and review criteria for pull requests handled in CI.

    9k GitHub stars~6.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • SeekDB Code Review

    oceanbase/seekdb

    Reviews seekdb pull requests and diffs for real defects in correctness, resources, concurrency, security and tests, reporting only Blocker or Major findings.

    3.1k GitHub stars~2.1k tokensUpdated today
    DevelopmentAuto-check passed
  • PR Review

    jaemk/self_update

    Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/self_update.

    961 GitHub stars~1.5k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • PR Review

    jaemk/cached

    Targeted, read-only review of a PR or checked-out branch. An agent skill from jaemk/cached.

    2.1k GitHub stars~2.5k tokensUpdated 7 days ago
    DevelopmentAuto-check: notes
  • Shared reference for naming, function size, complexity and error handling rules that reviewer agents apply across TypeScript, Python, Go, Rust, Java, C# and Swift.

    2k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Resolve PR Review

    shencangsheng/easydb_app

    Resolve pull request code review comments end-to-end. An agent skill from shencangsheng/easydb_app.

    590 GitHub stars~2.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed

Works with

Categories

Questions about Rust Code Review

What does Rust Code Review do?

Rust Code review checklist and decision framework for Rust PRs, derived from rust-best-practices. Rust Code Review is an agent skill from apollographql/rust-best-practices. Rust Code review checklist and decision framework for Rust PRs, derived from rust-best-practices.

When should I use Rust Code Review?

Rust Code Review fits situations like: tasks that involve Code review.

How do I install Rust Code Review in Claude Code?

Run `npx skills add apollographql/rust-best-practices --skill rust-code-review -a claude-code`. Or copy the skill folder (.codex/skills/rust-code-review in apollographql/rust-best-practices) into .claude/skills/rust-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Rust Code Review in Codex?

Run `npx skills add apollographql/rust-best-practices --skill rust-code-review -a codex`. Or copy the skill folder (.codex/skills/rust-code-review in apollographql/rust-best-practices) into .agents/skills/rust-code-review in your project. Codex loads it when a task matches its description.

Can I use Rust Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add apollographql/rust-best-practices --skill rust-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rust-code-review, .gemini/skills/rust-code-review, .github/skills/rust-code-review and .opencode/skills/rust-code-review in your project.

What does Rust Code Review need to run?

Going by SKILL.md and its folder, Rust Code Review needs the command-line tools its instructions call (cargo).

Does Rust Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Rust Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rust Code Review use?

Rust Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rust Code Review use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rust Code Review?

Skills that share tags, products or a category with Rust Code Review: Worktrunk Tend CI Guidance (max-sixty/worktrunk, 9k stars), SeekDB Code Review (oceanbase/seekdb, 3.1k stars), PR Review (jaemk/self_update, 961 stars) and PR Review (jaemk/cached, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rust Code Review?

apollographql (a GitHub organization) maintains it in apollographql/rust-best-practices, which has 157 GitHub stars. The repository was last updated on September 28, 2026.

Source: apollographql/rust-best-practices on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.