Agent skill

Rust Review

by liuyanghejerry in liuyanghejerry/Clausura

“Rust 服务审查:panic、SQL 注入、密钥、错误吞没、遗留标记”

— description from SKILL.md by liuyanghejerry
MITAuto-check passedSecurity

Install Rust Review

skills CLI
$ npx skills add liuyanghejerry/Clausura --skill rust-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install liuyanghejerry/Clausura rust-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/liuyanghejerry/Clausura.git skills-src && mkdir -p .claude/skills && cp -r skills-src/eval/scenarios/rust-service/workspace/.clausura/skills/rust-review .claude/skills/rust-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rust-review
GitHub stars
204
Token cost
~180 tokens
SKILL.md length
54 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

About this skill

Rust Review is a skill in liuyanghejerry/Clausura (204 stars). Its SKILL.md is about 180 tokens. Licence: MIT.

What it can do on your machine

Read from SKILL.md and the folder at commit 7653c87. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rust Review loads about 180 tokens when it runs. Until then it costs about 12 tokens; SKILL.md has 54 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~12
When it runs · the whole SKILL.md, loaded when a task matches
~180

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from liuyanghejerry/Clausura at commit 7653c87, republished under its MIT licence (© liuyanghejerry). 54 words, ~180 tokens.

Download SKILL.mdSave it as .claude/skills/rust-review/SKILL.md (or your agent's skills folder).
name
rust-review
description
Rust 服务审查:panic、SQL 注入、密钥、错误吞没、遗留标记

Rust 服务代码审查

先用 git_diff(参数 {"base": "HEAD~1"})查看本次变更。

规则

panic-unwrap(error)
  • 对可失败的输入使用 unwrap() / expect():用户输入解析、Option 解包等
  • 会导致服务 panic 的位置
  • 注意:同一个语句里的多个 unwrap 算一个 finding
  • rule_id: panic-unwrap
sql-injection(error)
  • 字符串拼接构造 SQL(format! 拼 SQL、+ 拼 SQL)
  • 应使用参数化查询
  • rule_id: sql-injection
hardcoded-secret(error)
  • 源码中硬编码的密码、连接串凭据、API key
  • rule_id: hardcoded-secret
swallowed-error(error)
  • 用 let _ = 静默丢弃 Result(无日志、无处理)
  • rule_id: swallowed-error
todo-marker(warning)
  • 生产代码中遗留的 todo!() / unimplemented!()
  • rule_id: todo-marker

每个 finding 附带 location(文件 + 行号)与证据(代码片段)。

© liuyanghejerry, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in eval/scenarios/rust-service/workspace/.clausura/skills/rust-review of liuyanghejerry/Clausura.

Open the folder on GitHubat commit 7653c87

Compare with similar skills

Rust Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rust Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rust Review this skillliuyanghejerry/Clausura204—~180Automated safety check: PassMIT
SQL Securitymizchi/skills360—~1.4kAutomated safety check: PassNone
Diesel Guardayarotsky/diesel-guard121—~3.1kAutomated safety check: PassMIT
Rust SQL Testshencangsheng/easydb_app590—~1.2kAutomated safety check: PassMIT
Querying Tempotempoxyz/tidx108—~3.1kAutomated safety check: PassMIT
Ron Databasebionic-gpt/bionic-gpt2.4k—~721Automated safety check: PassApache-2.0

Similar skills

  • SQL Security

    mizchi/skills

    SQL injection screening for host code (MoonBit / TS / Rust) plus secretlint setup notes.

    360 GitHub stars~1.4k tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Diesel Guard

    ayarotsky/diesel-guard

    Lints Diesel and SQLx Postgres migrations for unsafe schema changes that lock tables or cause downtime, and authors custom Rhai checks.

    121 GitHub stars~3.1k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Rust SQL Test

    shencangsheng/easydb_app

    Enforces unit test requirements for the Rust data-processing modules in src-tauri/src/sql/ (generator.rs, parse.rs) and src-tauri/src/reader/ (excel.rs and other readers).

    590 GitHub stars~1.2k tokensUpdated 1 mo ago
    Documents & OfficeAuto-check passed
  • Querying Tempo

    tempoxyz/tidx

    Query indexed Tempo chain data via tidx HTTP API and CLI. An agent skill from tempoxyz/tidx.

    108 GitHub stars~3.1k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Ron Database

    bionic-gpt/bionic-gpt

    Manage PostgreSQL migrations, typed SQL queries, generated Rust bindings, and database authorization in Rust on Nails applications.

    2.4k GitHub stars~721 tokensUpdated 4 days ago
    DatabasesAuto-check passed
  • Rust On Nails

    bionic-gpt/bionic-gpt

    Design Rust on Nails applications and cross-layer features using Axum, server-rendered Dioxus, PostgreSQL, and typed SQL.

    2.4k GitHub stars~706 tokensUpdated 4 days ago
    DatabasesAuto-check passed

More from liuyanghejerry/Clausura

  • Python Review

    liuyanghejerry/Clausura

    Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出. An agent skill from liuyanghejerry/Clausura.

    204 GitHub stars~164 tokensUpdated 11 days ago
    Auto-check passed
  • TS Review

    liuyanghejerry/Clausura

    TypeScript monorepo 审查:XSS、SQL 注入、密钥、any、console.log. An agent skill from liuyanghejerry/Clausura.

    204 GitHub stars~166 tokensUpdated 11 days ago
    Auto-check passed
  • Security Review

    liuyanghejerry/Clausura

    检查 SQL 注入、XSS、硬编码密钥

    204 GitHub stars~106 tokensUpdated 11 days ago
    Auto-check passed
  • Secret Sweep Scan

    liuyanghejerry/Clausura

    大规模扫描硬编码凭证,忽略占位符

    204 GitHub stars~125 tokensUpdated 11 days ago
    Auto-check passed

Works with

Questions about Rust Review

How do I install Rust Review in Claude Code?

Run `npx skills add liuyanghejerry/Clausura --skill rust-review -a claude-code`. Or copy the skill folder (eval/scenarios/rust-service/workspace/.clausura/skills/rust-review in liuyanghejerry/Clausura) into .claude/skills/rust-review in your project. Claude Code loads it when a task matches its description.

How do I install Rust Review in Codex?

Run `npx skills add liuyanghejerry/Clausura --skill rust-review -a codex`. Or copy the skill folder (eval/scenarios/rust-service/workspace/.clausura/skills/rust-review in liuyanghejerry/Clausura) into .agents/skills/rust-review in your project. Codex loads it when a task matches its description.

Can I use Rust Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add liuyanghejerry/Clausura --skill rust-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rust-review, .gemini/skills/rust-review, .github/skills/rust-review and .opencode/skills/rust-review in your project.

What does Rust Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Rust Review is instructions for the agent only.

Does Rust Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Rust Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rust Review use?

Rust Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rust Review use?

About 180 tokens (SKILL.md is roughly 720 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rust Review?

Skills that share tags, products or a category with Rust Review: SQL Security (mizchi/skills, 360 stars), Diesel Guard (ayarotsky/diesel-guard, 121 stars), Rust SQL Test (shencangsheng/easydb_app, 590 stars) and Querying Tempo (tempoxyz/tidx, 108 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rust Review?

liuyanghejerry (a GitHub user) maintains it in liuyanghejerry/Clausura, which has 204 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on September 29, 2026.

Source: liuyanghejerry/Clausura on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.