Agent skill

Rust Dep Hygiene

by rocky-data in rocky-data/rocky

Dependency hygiene for the Rocky engine workspace — how to add/update deps via [workspace.dependencies], MSRV 1.88 policy, cargo-audit / cargo-deny / cargo-machete usage, and how the weekly security…

Apache-2.0Auto-check passedSecurity

Install Rust Dep Hygiene

skills CLI
$ npx skills add rocky-data/rocky --skill rust-dep-hygiene -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rocky-data/rocky rust-dep-hygiene --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rocky-data/rocky.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engine/.claude/skills/rust-dep-hygiene .claude/skills/rust-dep-hygiene && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rust-dep-hygiene
GitHub stars
304
Token cost
~2k tokens
SKILL.md length
969 words
Files
1
Skills in repo
22
Repo updated
First seen
Licence
Apache-2.0

At a glance

Dependency hygiene for the Rocky engine workspace — how to add/update deps via [workspace.dependencies], MSRV 1.88 policy, cargo-audit / cargo-deny / cargo-machete usage, and how the weekly security…

  • Works in 5 steps: Edit engine/Cargo.toml and add the dep… → In the specific crate that needs it, add… → Run cargo build -p to confirm resolution. → …
  • Tasks that involve Security review
  • SKILL.md covers Workspace-dep rule, MSRV (1.88, Rust 2024 edition), Security audit: cargo audit and License / supply-chain checks:…, plus 4 more sections
  • Calls cargo

What it does

Rust Dep Hygiene is an agent skill from rocky-data/rocky. Dependency hygiene for the Rocky engine workspace — how to add/update deps via [workspace.dependencies], MSRV 1.88 policy, cargo-audit / cargo-deny / cargo-machete usage, and how the weekly security audit surfaces advisories.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review. It works with Rust. The repository describes itself as: A SQL transformation engine that type-checks your whole pipeline and catches breaking changes before they run — branches, replay, column-level lineage, compile-time contracts… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Security review

Example prompts

  • “/rust-dep-hygiene”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Edit engine/Cargo.toml and add the dep to [workspace.dependencies] with the exact version and feature set you need.
  2. In the specific crate that needs it, add = { workspace = true } (plus a features = [...] override if the crate needs a narrower subset…
  3. Run cargo build -p to confirm resolution.
  4. Run cargo tree -d to check you haven't introduced a duplicate version of anything (see "Duplicates" below).
  5. Never cargo add inside a sub-crate without the --workspace or without editing [workspace.dependencies] first.

What it can do on your machine

Read from SKILL.md and the folder at commit 9c3d777. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rust Dep Hygiene loads about 2k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 969 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rocky-data/rocky at commit 9c3d777, republished under its Apache-2.0 licence (© rocky-data). 969 words, ~2,031 tokens.

Download SKILL.mdSave it as .claude/skills/rust-dep-hygiene/SKILL.md (or your agent's skills folder).
name
rust-dep-hygiene
description
Dependency hygiene for the Rocky engine workspace — how to add/update deps via [workspace.dependencies], MSRV 1.88 policy, cargo-audit / cargo-deny / cargo-machete usage, and how the weekly security audit surfaces advisories.

Dependency hygiene for the Rocky engine

Workspace-dep rule

All dependencies go through [workspace.dependencies] in engine/Cargo.toml. Individual crates under engine/crates/* inherit versions by referencing the workspace:

toml
# In crates/rocky-fivetran/Cargo.toml
[dependencies]
reqwest  = { workspace = true }
tokio    = { workspace = true }
thiserror = { workspace = true }

Never do this in a leaf crate:

toml
# DON'T — bypasses the workspace pin
[dependencies]
reqwest = "0.12"

Why: the workspace has dozens of crates. Per-crate version pins drift, cause duplicate dep compilations, and break the MSRV contract.

Adding a new workspace dependency
  1. Edit engine/Cargo.toml and add the dep to [workspace.dependencies] with the exact version and feature set you need.
  2. In the specific crate that needs it, add <dep> = { workspace = true } (plus a features = [...] override if the crate needs a narrower subset — it's allowed to turn features on, never off).
  3. Run cargo build -p <crate> to confirm resolution.
  4. Run cargo tree -d to check you haven't introduced a duplicate version of anything (see "Duplicates" below).
  5. Never cargo add inside a sub-crate without the --workspace or without editing [workspace.dependencies] first.
Upgrading a workspace dependency
bash
# From engine/
cargo update -p <crate_name>            # Minor/patch only — respects the Cargo.toml version req.
cargo update                            # Everything — use with care, always review Cargo.lock diff.

Major version bumps require editing engine/Cargo.toml directly and checking the changelog for breaking changes. Pin the version in [workspace.dependencies], not in individual crates.

MSRV (1.88, Rust 2024 edition)

engine/Cargo.toml declares:

toml
[workspace.package]
edition = "2024"
rust-version = "1.88"

Bumped 1.85.1 → 1.88 on 2026-05-24: the rocky-mcp crate's rmcp tree (rmcp-macros → darling 0.23, edition 2024) requires rustc 1.88, so the effective workspace MSRV was already 1.88. (The tree was rmcp 1.7 at the bump; it is rmcp 2.2 now — still darling 0.23 / edition 2024, so the 1.88 floor is unchanged.)

Rules:

  1. Don't use features newer than 1.88 in any engine crate. If a stable feature lands in 1.89+, either wait for the next MSRV bump or gate your usage behind something that compiles on 1.88.
  2. Dependencies can have their own MSRV. If a dep requires Rust 1.90 and Rocky is on 1.88, you have two choices: pin an older version of the dep (check cargo tree and the dep's changelog) or propose an MSRV bump.
  3. Bumping MSRV is a policy change. Don't do it unilaterally. Propose to Hugo, note the reason (typically: a dep dropped support for the old MSRV), and bump both the [workspace.package] line and the CI toolchain installer in .github/workflows/engine-ci.yml in the same PR.
  4. Edition bumps (2024 → 2027 when that exists) are separate from MSRV bumps and even rarer. Don't conflate them.

Security audit: cargo audit

Rocky runs cargo audit weekly, not on every PR. From .github/workflows/engine-weekly.yml:

yaml
schedule:
  - cron: '0 8 * * 1'   # Monday 08:00 UTC

- name: Run cargo audit
  run: cargo audit

The workflow is also manually dispatchable (workflow_dispatch) and marked continue-on-error: true, so advisories don't block PRs — they surface as a Monday morning report.

To run it locally:

bash
cargo install cargo-audit     # first time only
cd engine
cargo audit

When to react:

  • critical or high — fix this week. Either bump the transitive dep (via cargo update -p or a workspace bump) or vendor a patch.
  • medium — schedule a fix in the current iteration.
  • low / informational — note, don't drop everything.
  • unsound advisories on a library dep are different from vulnerabilities — they indicate soundness bugs in the dep, and the right fix is usually a version bump or a report upstream, not a workspace allowlist.

cargo audit does not currently have an allow-list for accepted advisories in Rocky. If you want to ignore a specific advisory with a reason, that's a policy change — propose it to Hugo first. (The mechanism is audit.toml with ignore = ["RUSTSEC-YYYY-NNNN"] and a reason = "..." line.)

Show full SKILL.md (438 more words)Show less

License / supply-chain checks: cargo-deny (not currently configured)

Rocky does not ship a deny.toml or run cargo-deny in CI as of this skill's authoring. The project's license is Apache-2.0 (engine/Cargo.toml → [workspace.package]). If you want to enforce license compatibility or a banned-deps policy, proposing cargo-deny adoption is the right move — but do it as a dedicated PR, not smuggled into an unrelated change. A minimal deny.toml for Rocky would cover:

  • licenses: allow Apache-2.0, MIT, BSD-3-Clause, ISC, Unicode-DFS-2016; deny GPL-* / AGPL-* (Rocky is Apache-2.0 and can't take copyleft deps).
  • bans: ban known-bad crates (e.g. openssl-sys when rustls is already the chosen TLS stack — Rocky uses reqwest = { features = ["rustls-tls"] }).
  • advisories: fail on unmaintained + unsound (beyond what cargo audit already catches).
  • sources: restrict to crates-io unless explicit git deps are reviewed.

Don't enable this without Hugo's sign-off — it's the kind of change that turns a clean workspace red on day one.

Unused deps: cargo-machete

cargo-machete finds unused dependencies per crate. Run it when you've done a large refactor and want to clean up:

bash
cargo install cargo-machete   # first time only
cd engine
cargo machete

Caveats:

  • cargo-machete looks at Cargo.toml vs. actual use statements. It sometimes false-positives on deps that are used only through macros (e.g. serde_json via json!) or only behind #[cfg(...)] feature gates.
  • Always review the diff before deleting a dep — especially if the dep is declared at workspace level; removing it from a leaf crate's Cargo.toml is fine, but removing it from [workspace.dependencies] may break another crate.
  • Run cargo build --all-targets after any deletion to confirm nothing broke.

Duplicates: cargo tree -d

bash
cd engine
cargo tree -d             # show duplicate versions of any transitive dep
cargo tree -d -e features # include feature-flag differences

Duplicates bloat compile time and binary size. The common causes:

  • A workspace dep and a git-pinned dep both pull the same transitive crate at different versions.
  • A feature flag causes two copies of a dep with different feature sets.
  • A sub-crate declared its own version of a dep that's already in [workspace.dependencies].

Fix by unifying on one version at the workspace level. Sometimes you can't — two upstreams depend on incompatible ranges of the same crate — in which case document it as a known duplicate and move on.

Dep policy cheatsheet

CheckFrequencyBlocking?Tool
Security advisoriesWeekly (Monday UTC)No (continue-on-error)cargo-audit
MSRV complianceEvery PRYes (via CI cargo build)Cargo built-in
Clippy on depsEvery PRYes (-D warnings)cargo clippy — see rust-clippy-triage
License compatibility—Not enforcedcargo-deny (not configured)
Unused depsAd hocNocargo-machete
Duplicate versionsAd hocNocargo tree -d
  • rust-clippy-triage — deprecated-API warnings from bumped deps often surface as clippy lints first.
  • rust-error-handling — when upgrading thiserror or anyhow specifically, read the release notes for breaking changes in derive syntax.
  • rocky-release (monorepo root) — release-time dep pinning and lockfile policy for the engine-v* tag.

© rocky-data, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in engine/.claude/skills/rust-dep-hygiene of rocky-data/rocky.

Open the folder on GitHubat commit 9c3d777

Compare with similar skills

Rust Dep Hygiene next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rust Dep Hygiene compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rust Dep Hygiene this skillrocky-data/rocky304—~2kAutomated safety check: PassApache-2.0
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Rust Security ChecklistJxck/sptth133—~318Automated safety check: PassMIT
Review Securitypydantic/monty8.6k—~852Automated safety check: PassMIT
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
SkepticRaoFoundation/subtensor389—~660Automated safety check: PassApache-2.0

Similar skills

  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Use before merging security-relevant Rust changes. An agent skill from Jxck/sptth.

    133 GitHub stars~318 tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • Review Security

    pydantic/monty

    Official

    Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses.

    8.6k GitHub stars~852 tokensUpdated yesterday
    SecurityAuto-check passed
  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Skeptic

    RaoFoundation/subtensor

    Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

    389 GitHub stars~660 tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Review

    deadlock-mod-manager/deadlock-mod-manager

    Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.

    477 GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed

More from rocky-data/rocky

All 22 skills in this repo
  • Fivetran

    rocky-data/rocky

    Fivetran REST API reference for Rocky's source adapter. An agent skill from rocky-data/rocky.

    304 GitHub stars~914 tokensUpdated yesterday
    Auto-check passed
  • Databricks

    rocky-data/rocky

    Databricks REST API and SQL reference for Rocky's warehouse adapter.

    304 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Rocky Codegen

    rocky-data/rocky

    Rocky CLI JSON-output schema cascade. An agent skill from rocky-data/rocky.

    304 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Rocky Dev

    rocky-data/rocky

    Top-level router for Rocky development tasks. An agent skill from rocky-data/rocky.

    304 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Rocky Dsl Change

    rocky-data/rocky

    Rocky DSL (.rocky file) cross-subproject cascade. An agent skill from rocky-data/rocky.

    304 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Rocky New Adapter

    rocky-data/rocky

    Adding a new warehouse or source adapter crate to the Rocky engine.

    304 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Rust Dep Hygiene

What does Rust Dep Hygiene do?

Dependency hygiene for the Rocky engine workspace — how to add/update deps via [workspace.dependencies], MSRV 1.88 policy, cargo-audit / cargo-deny / cargo-machete usage, and how the weekly security…. Rust Dep Hygiene is an agent skill from rocky-data/rocky.88 policy, cargo-audit / cargo-deny / cargo-machete usage, and how the weekly security audit surfaces advisories.

When should I use Rust Dep Hygiene?

Rust Dep Hygiene fits situations like: tasks that involve Security review.

How do I install Rust Dep Hygiene in Claude Code?

Run `npx skills add rocky-data/rocky --skill rust-dep-hygiene -a claude-code`. Or copy the skill folder (engine/.claude/skills/rust-dep-hygiene in rocky-data/rocky) into .claude/skills/rust-dep-hygiene in your project. Claude Code loads it when a task matches its description.

How do I install Rust Dep Hygiene in Codex?

Run `npx skills add rocky-data/rocky --skill rust-dep-hygiene -a codex`. Or copy the skill folder (engine/.claude/skills/rust-dep-hygiene in rocky-data/rocky) into .agents/skills/rust-dep-hygiene in your project. Codex loads it when a task matches its description.

Can I use Rust Dep Hygiene in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rocky-data/rocky --skill rust-dep-hygiene -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rust-dep-hygiene, .gemini/skills/rust-dep-hygiene, .github/skills/rust-dep-hygiene and .opencode/skills/rust-dep-hygiene in your project.

What does Rust Dep Hygiene need to run?

Going by SKILL.md and its folder, Rust Dep Hygiene needs the command-line tools its instructions call (cargo).

Does Rust Dep Hygiene access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Rust Dep Hygiene safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rust Dep Hygiene use?

Rust Dep Hygiene is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rust Dep Hygiene use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rust Dep Hygiene?

Skills that share tags, products or a category with Rust Dep Hygiene: Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Rust Security Checklist (Jxck/sptth, 133 stars), Review Security (pydantic/monty, 8.6k stars) and Pyspector Security Audit (ParzivalHack/PySpector, 151 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rust Dep Hygiene?

rocky-data (a GitHub organization) maintains it in rocky-data/rocky, which has 304 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 9, 2026.

Source: rocky-data/rocky on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.