Agent skill

Rust Review

by athola in athola/claude-night-market

Audits Rust code for unsafe blocks, ownership issues, and Cargo dependency risks.

MITAuto-check passedDevelopment

Install Rust Review

skills CLI
$ npx skills add athola/claude-night-market --skill rust-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install athola/claude-night-market rust-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/pensive/skills/rust-review .claude/skills/rust-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rust-review
GitHub stars
341
Token cost
~2.2k tokens
SKILL.md length
607 words
Files
28
Skills in repo
152
Repo updated
First seen
Licence
MIT

At a glance

Audits Rust code for unsafe blocks, ownership issues, and Cargo dependency risks.

  • Works in 12 steps: rust-review:ownership-analysis → rust-review:error-handling → rust-review:concurrency → …
  • Reviewing Rust code
  • SKILL.md covers Quick Start, When To Use, When NOT To Use and Required TodoWrite Items, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Rust Review is an agent skill from athola/claude-night-market. Audits Rust code for unsafe blocks, ownership issues, and Cargo dependency risks. Use when reviewing Rust code or before merging Rust changes.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 28 other files (for example `modules/async-slop.md`, `modules/builtin-preference.md` and `modules/cargo-dependencies.md`).

It sits in Development. It works with Rust. The repository describes itself as: 23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context… The licence is MIT.

When your agent uses it

  • Reviewing Rust code
  • Before merging Rust changes

Example prompts

  • “Use the rust-review skill to audit Rust code for unsafe blocks, ownership issues, and Cargo dependency risks”
  • “/rust-review”

Workflow steps

12 steps, taken from the first numbered list in SKILL.md.

  1. rust-review:ownership-analysis
  2. rust-review:error-handling
  3. rust-review:concurrency
  4. rust-review:unsafe-audit
  5. rust-review:cargo-deps
  6. rust-review:native-modeling
  7. rust-review:idiomatic-elision
  8. rust-review:coercion-params
  9. rust-review:conversion-traits
  10. rust-review:numeric-cast-safety
  11. rust-review:mutable-static-audit
  12. rust-review:match-wildcard

What it can do on your machine

Read from SKILL.md and the folder at commit 9f3eb00. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rust Review loads about 2.2k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 607 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from athola/claude-night-market at commit 9f3eb00, republished under its MIT licence (© athola). 607 words, ~2,173 tokens.

Download SKILL.mdSave it as .claude/skills/rust-review/SKILL.md (or your agent's skills folder). This skill also uses 27 other files; get the full folder from GitHub.
name
rust-review
description
Audits Rust code for unsafe blocks, ownership issues, and Cargo dependency risks. Use when reviewing Rust code or before merging Rust changes.
globs
**/*.rs
alwaysApply
false
category
code-review
tags
rust, ownership, concurrency, unsafe, traits, cargo
usage_patterns
rust-audit, unsafe-review, dependency-audit, concurrency-analysis
complexity
advanced
model_hint
deep
estimated_tokens
400
progressive_loading
true
dependencies
imbue:proof-of-work, imbue:review-core, imbue:structured-output

Rust Review Workflow

Expert-level Rust code audits with focus on safety, correctness, and idiomatic patterns.

Quick Start

bash
/rust-review

Verification: Run the command with --help flag to verify availability.

When To Use

  • Reviewing Rust code changes
  • Auditing unsafe blocks
  • Analyzing concurrency patterns
  • Dependency security review
  • Performance optimization review

When NOT To Use

  • General code review without Rust - use unified-review
  • Performance profiling - use parseltongue:python-performance pattern

Required TodoWrite Items

  1. rust-review:ownership-analysis
  2. rust-review:error-handling
  3. rust-review:concurrency
  4. rust-review:unsafe-audit
  5. rust-review:cargo-deps
  6. rust-review:native-modeling
  7. rust-review:idiomatic-elision
  8. rust-review:coercion-params
  9. rust-review:conversion-traits
  10. rust-review:numeric-cast-safety
  11. rust-review:mutable-static-audit
  12. rust-review:match-wildcard
  13. rust-review:transmute-audit
  14. rust-review:float-equality
  15. rust-review:mem-forget-audit
  16. rust-review:repr-packed-audit
  17. rust-review:evidence-log
  18. rust-review:findings-verified

Progressive Loading

Load modules as needed based on review scope:

Quick Review (ownership and errors):

  • See modules/ownership-analysis.md for borrowing and lifetime analysis
  • See modules/error-handling.md for Result/Option patterns

Concurrency Focus:

  • See modules/concurrency-patterns.md for async and sync primitives

Safety Audit:

  • See modules/unsafe-audit.md for unsafe block documentation
  • See modules/mutable-static-audit.md for static mut globals and their thread-safe replacements
  • See modules/numeric-cast-safety.md for truncating and precision-losing as casts
  • See modules/match-wildcard.md for catch-all arms that defeat enum exhaustiveness
  • See modules/transmute-audit.md for mem::transmute/transmute_copy calls that reinterpret bytes with no layout check
  • See modules/repr-packed-audit.md for #[repr(packed)] layouts whose field borrows become unaligned references

Correctness Audit:

  • See modules/float-equality.md for ==/!= against float literals
  • See modules/mem-forget-audit.md for mem::forget leaks and no-op drop(&x) reference drops

Dependency Review:

  • See modules/cargo-dependencies.md for vulnerability scanning

Idiomatic Patterns:

  • See modules/builtin-preference.md for conversion traits and builtin preference
  • See modules/native-type-modeling.md for enums-over-primitives, newtype, type-state, and derived ordering
  • See modules/idiomatic-elision.md for lifetime elision, expression-oriented returns, and explicit -> () unit returns
  • See modules/coercion-params.md for &String/&Vec<T>/&PathBuf parameters that defeat deref coercion (prefer &str/&[T]/&Path)
  • See modules/conversion-traits.md for impl Into that should be impl From, and discarded try_into().unwrap() conversion errors

Core Workflow

  1. Ownership Analysis: Check borrowing, lifetimes, clone patterns
  2. Error Handling: Verify Result/Option usage, propagation
  3. Concurrency: Review async patterns, sync primitives
  4. Unsafe Audit: Document invariants, FFI contracts
  5. Dependencies: Scan for vulnerabilities, updates
  6. Evidence Log: Record commands and findings

Rust Quality Checklist

Safety
  • All unsafe blocks documented with SAFETY comments
  • FFI boundaries properly wrapped
  • Memory safety invariants maintained
  • No static mut globals; shared state uses OnceLock/LazyLock, atomics, or a Mutex/RwLock
  • No mem::transmute/transmute_copy; bytes converted with from_le_bytes/from_bits/bytemuck or pointers with .cast()
  • #[repr(packed)] fields copied out before borrowing (no unaligned references)
  • No mem::forget leaks (use ManuallyDrop/scope) and no no-op drop(&x) reference drops
  • mlock/munlock calls: RLIMIT verified, page-aligned, ENOMEM handled
Show full SKILL.md (219 more words)Show less
Correctness
  • Error handling complete
  • Concurrency patterns sound
  • Lossy as casts (length truncation, as u8/i8, as f32) replaced with TryFrom/From
  • Enum matches exhaustive; no _ => unreachable!()/panic!/{} catch-alls
  • Floats compared with a tolerance, not exact ==/!= against a float literal
  • Tests cover critical paths
Performance
  • No unnecessary allocations
  • Borrowing preferred over cloning
  • Async properly non-blocking
Idioms
  • Standard traits implemented
  • Conversion traits preferred over helper functions
  • Stringly-typed values and boolean flags modeled as enums
  • Domain invariants encoded with newtypes (private field + validating constructor) or type-state where warranted
  • Comparison/ordering traits derived, not hand-written
  • Lifetimes elided where elision rules apply; '_ in paths
  • Trailing return dropped in favor of the tail expression
  • Explicit -> () unit returns dropped (default is elided)
  • Parameters take &str/&[T]/&Path, not &String/&Vec<T>/ &PathBuf (deref coercion accepts both, so the slice is more general)
  • Conversions implement From/TryFrom, not Into/TryInto; a fallible conversion's error is propagated, not unwrap()ped
  • Error types well-designed
  • Documentation complete

Output Format

markdown
## Summary
Rust audit findings

## Ownership Analysis
[borrowing and lifetime issues]

## Error Handling
[error patterns and issues]

## Concurrency
[async and sync patterns]

## Unsafe Audit
### [U1] file:line
- Invariants: [documented]
- Anchor: `verbatim source text at file:line`
- Risk: [assessment]
- Recommendation: [action]

## Native Type Modeling
[stringly-typed comparisons, boolean blindness, newtype/type-state notes]

## Idiomatic Elision
[needless lifetimes, trailing returns, explicit `-> ()` unit returns]

## Coercion Params
[`&String`/`&Vec<T>`/`&PathBuf` params that should be borrowed slices]

## Conversion Traits
[`impl Into` over `impl From`; discarded `try_into().unwrap()` errors]

## Numeric Cast Safety
[length-truncating, byte-narrowing, and f32 precision-losing `as` casts]

## Mutable Static Audit
[`static mut` globals and their thread-safe replacements]

## Match Wildcard
[catch-all `_ =>` arms that defeat enum exhaustiveness]

## Transmute Audit
[`mem::transmute`/`transmute_copy` calls and their typed replacements]

## Float Equality
[exact `==`/`!=` comparisons against float literals]

## Mem Forget Audit
[`mem::forget` leaks and no-op `drop(&x)` reference drops]

## Repr Packed Audit
[`#[repr(packed)]` layouts whose field borrows become unaligned]

## Dependencies
[cargo audit results]

## Recommendation
Approve / Approve with actions / Block

Verification: Run the command with --help flag to verify availability.

Verify Findings Are Grounded (rust-review:findings-verified)

Write findings to .review/findings.json, run the citation verifier (Skill(imbue:review-core) Step 5), and drop or label UNVERIFIED any the verifier rejects.

Exit Criteria

  • All unsafe blocks audited
  • Concurrency patterns verified
  • Dependencies scanned
  • Evidence logged
  • Action items assigned
  • Every reported finding carries a Location + verbatim Anchor confirmed by citation_verifier.py (exit 0), or unverified findings were dropped or labeled UNVERIFIED

© athola, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 27 other files in plugins/pensive/skills/rust-review of athola/claude-night-market.

  • SKILL.md
  • modules/async-slop.md
  • modules/builtin-preference.md
  • modules/cargo-dependencies.md
  • modules/cfg-test-misuse.md
  • modules/coercion-params.md
  • modules/collection-types.md
  • modules/concurrency-patterns.md
  • modules/conversion-traits.md
  • modules/duplicate-validators.md
  • modules/error-handling.md
  • modules/error-messages.md
  • modules/float-equality.md
  • modules/idiomatic-elision.md
  • modules/iterator-and-allocation-slop.md
  • modules/match-wildcard.md
  • modules/mem-forget-audit.md
  • modules/model-specific-tells.md
  • modules/mutable-static-audit.md
  • modules/native-type-modeling.md
  • … and 8 more

Open the folder on GitHubat commit 9f3eb00

Compare with similar skills

Rust Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rust Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rust Review this skillathola/claude-night-market341—~2.2kAutomated safety check: PassMIT
Migrate Core Code to Submodulestinyhumansai/openhuman42k—~2.6kAutomated safety check: PassGPL-3.0
OpenLogi macOS Permissions TriageAprilNEA/OpenLogi23k—~2.5kAutomated safety check: NotesApache-2.0
Rust Best Practicesfarm-fe/farm5.6k3 repos~1.1kAutomated safety check: PassMIT
RTK Rust Design Patternsrtk-ai/rtk83k—~1.9kAutomated safety check: PassApache-2.0
Release Skillsnexmoe/eve4213 repos~3.3kAutomated safety check: PassNone

Similar skills

  • Migrate Core Code to Submodules

    tinyhumansai/openhuman

    Plans and carries out moving non-host-specific code and its tests from the OpenHuman core into vendored tiny submodule libraries, then releases the submodule and re-pins the host.

    42k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Decides whether an OpenLogi device problem on macOS is a privacy-permission (TCC) problem, using agent log lines, and says which identity needs which grant.

    23k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Guide for writing idiomatic Rust code based on Apollo GraphQL's best practices handbook.

    5.6k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Describes seven Rust design patterns for the RTK CLI filter modules, with when to use each, RTK examples, and notes on when a pattern is overkill.

    83k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Release Skills

    nexmoe/eve

    Universal release workflow. An agent skill from nexmoe/eve.

    421 GitHub starsUsed in 3 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Pnpm Engine

    teambit/bit

    Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed

More from athola/claude-night-market

All 152 skills in this repo
  • Night Market Diagnostics Toolkit

    athola/claude-night-market

    Run and interpret repo diagnostic scripts (ratchets, validators, token stats).

    341 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Skills Eval

    athola/claude-night-market

    Evaluate Claude skill quality through auditing. An agent skill from athola/claude-night-market.

    341 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Agent Teams

    athola/claude-night-market

    Coordinates Claude agent teams via filesystem protocol. An agent skill from athola/claude-night-market.

    341 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Delegation Core

    athola/claude-night-market

    Delegates execution to eight CLIs (Gemini, Qwen, MiniMax, GLM, Muse, Codex, OpenCode, Glimmer).

    341 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Elegant Code

    athola/claude-night-market

    Guide minimal code via a decision ladder with full safety, edge, and negative-case coverage.

    341 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Skill Library Mission

    athola/claude-night-market

    Build a project skill library in .claude/skills/ via discovery, parallel authoring, and review.

    341 GitHub stars~1.6k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Rust Review

What does Rust Review do?

Audits Rust code for unsafe blocks, ownership issues, and Cargo dependency risks. Rust Review is an agent skill from athola/claude-night-market. Audits Rust code for unsafe blocks, ownership issues, and Cargo dependency risks.

When should I use Rust Review?

Rust Review fits situations like: reviewing Rust code; before merging Rust changes.

How do I install Rust Review in Claude Code?

Run `npx skills add athola/claude-night-market --skill rust-review -a claude-code`. Or copy the skill folder (plugins/pensive/skills/rust-review in athola/claude-night-market) into .claude/skills/rust-review in your project. Claude Code loads it when a task matches its description.

How do I install Rust Review in Codex?

Run `npx skills add athola/claude-night-market --skill rust-review -a codex`. Or copy the skill folder (plugins/pensive/skills/rust-review in athola/claude-night-market) into .agents/skills/rust-review in your project. Codex loads it when a task matches its description.

Can I use Rust Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add athola/claude-night-market --skill rust-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rust-review, .gemini/skills/rust-review, .github/skills/rust-review and .opencode/skills/rust-review in your project.

What does Rust Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Rust Review is instructions for the agent only.

Does Rust Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Rust Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rust Review use?

Rust Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rust Review use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rust Review?

Skills that share tags, products or a category with Rust Review: Migrate Core Code to Submodules (tinyhumansai/openhuman, 42k stars), OpenLogi macOS Permissions Triage (AprilNEA/OpenLogi, 23k stars), Rust Best Practices (farm-fe/farm, 5.6k stars) and RTK Rust Design Patterns (rtk-ai/rtk, 83k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rust Review?

athola (a GitHub user) maintains it in athola/claude-night-market, which has 341 GitHub stars. The repository holds 152 skills in this directory. The repository was last updated on October 9, 2026.

Source: athola/claude-night-market on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.