Security Audit
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
Dependency hygiene for the Rocky engine workspace — how to add/update deps via [workspace.dependencies], MSRV 1.88 policy, cargo-audit / cargo-deny / cargo-machete usage, and how the weekly security…
$ npx skills add rocky-data/rocky --skill rust-dep-hygiene -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install rocky-data/rocky rust-dep-hygiene --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/rocky-data/rocky.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engine/.claude/skills/rust-dep-hygiene .claude/skills/rust-dep-hygiene && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "rust-dep-hygiene" agent skill from https://github.com/rocky-data/rocky/tree/main/engine/.claude/skills/rust-dep-hygiene into .claude/skills/rust-dep-hygiene/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rust-dep-hygiene", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/rocky-data/rocky/tree/main/engine/.claude/skills/rust-dep-hygieneType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add rocky-data/rocky --skill rust-dep-hygiene -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install rocky-data/rocky rust-dep-hygiene --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rocky-data/rocky.git skills-src && mkdir -p .agents/skills && cp -r skills-src/engine/.claude/skills/rust-dep-hygiene .agents/skills/rust-dep-hygiene && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "rust-dep-hygiene" agent skill from https://github.com/rocky-data/rocky/tree/main/engine/.claude/skills/rust-dep-hygiene into .agents/skills/rust-dep-hygiene/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rust-dep-hygiene", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rocky-data/rocky --skill rust-dep-hygiene -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install rocky-data/rocky rust-dep-hygiene --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rocky-data/rocky.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/engine/.claude/skills/rust-dep-hygiene .cursor/skills/rust-dep-hygiene && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "rust-dep-hygiene" agent skill from https://github.com/rocky-data/rocky/tree/main/engine/.claude/skills/rust-dep-hygiene into .cursor/skills/rust-dep-hygiene/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rust-dep-hygiene", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/rocky-data/rocky.git --path engine/.claude/skills/rust-dep-hygiene--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add rocky-data/rocky --skill rust-dep-hygiene -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install rocky-data/rocky rust-dep-hygiene --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rocky-data/rocky.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/engine/.claude/skills/rust-dep-hygiene .gemini/skills/rust-dep-hygiene && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "rust-dep-hygiene" agent skill from https://github.com/rocky-data/rocky/tree/main/engine/.claude/skills/rust-dep-hygiene into .gemini/skills/rust-dep-hygiene/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rust-dep-hygiene", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install rocky-data/rocky rust-dep-hygieneInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add rocky-data/rocky --skill rust-dep-hygiene -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/rocky-data/rocky.git skills-src && mkdir -p .github/skills && cp -r skills-src/engine/.claude/skills/rust-dep-hygiene .github/skills/rust-dep-hygiene && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "rust-dep-hygiene" agent skill from https://github.com/rocky-data/rocky/tree/main/engine/.claude/skills/rust-dep-hygiene into .github/skills/rust-dep-hygiene/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rust-dep-hygiene", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rocky-data/rocky --skill rust-dep-hygiene -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install rocky-data/rocky rust-dep-hygiene --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rocky-data/rocky.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/engine/.claude/skills/rust-dep-hygiene .opencode/skills/rust-dep-hygiene && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "rust-dep-hygiene" agent skill from https://github.com/rocky-data/rocky/tree/main/engine/.claude/skills/rust-dep-hygiene into .opencode/skills/rust-dep-hygiene/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rust-dep-hygiene", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
rust-dep-hygieneDependency hygiene for the Rocky engine workspace — how to add/update deps via [workspace.dependencies], MSRV 1.88 policy, cargo-audit / cargo-deny / cargo-machete usage, and how the weekly security…
Rust Dep Hygiene is an agent skill from rocky-data/rocky. Dependency hygiene for the Rocky engine workspace — how to add/update deps via [workspace.dependencies], MSRV 1.88 policy, cargo-audit / cargo-deny / cargo-machete usage, and how the weekly security audit surfaces advisories.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security review. It works with Rust. The repository describes itself as: A SQL transformation engine that type-checks your whole pipeline and catches breaking changes before they run — branches, replay, column-level lineage, compile-time contracts… The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9c3d777. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
cargoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Rust Dep Hygiene loads about 2k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 969 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from rocky-data/rocky at commit 9c3d777, republished under its Apache-2.0 licence (© rocky-data). 969 words, ~2,031 tokens.
.claude/skills/rust-dep-hygiene/SKILL.md (or your agent's skills folder).All dependencies go through [workspace.dependencies] in engine/Cargo.toml. Individual crates under engine/crates/* inherit versions by referencing the workspace:
# In crates/rocky-fivetran/Cargo.toml
[dependencies]
reqwest = { workspace = true }
tokio = { workspace = true }
thiserror = { workspace = true }Never do this in a leaf crate:
# DON'T — bypasses the workspace pin
[dependencies]
reqwest = "0.12"Why: the workspace has dozens of crates. Per-crate version pins drift, cause duplicate dep compilations, and break the MSRV contract.
engine/Cargo.toml and add the dep to [workspace.dependencies] with the exact version and feature set you need.<dep> = { workspace = true } (plus a features = [...] override if the crate needs a narrower subset — it's allowed to turn features on, never off).cargo build -p <crate> to confirm resolution.cargo tree -d to check you haven't introduced a duplicate version of anything (see "Duplicates" below).cargo add inside a sub-crate without the --workspace or without editing [workspace.dependencies] first.# From engine/
cargo update -p <crate_name> # Minor/patch only — respects the Cargo.toml version req.
cargo update # Everything — use with care, always review Cargo.lock diff.Major version bumps require editing engine/Cargo.toml directly and checking the changelog for breaking changes. Pin the version in [workspace.dependencies], not in individual crates.
engine/Cargo.toml declares:
[workspace.package]
edition = "2024"
rust-version = "1.88"Bumped 1.85.1 → 1.88 on 2026-05-24: the
rocky-mcpcrate'srmcptree (rmcp-macros→darling 0.23, edition 2024) requires rustc 1.88, so the effective workspace MSRV was already 1.88. (The tree wasrmcp 1.7at the bump; it isrmcp 2.2now — stilldarling 0.23/ edition 2024, so the 1.88 floor is unchanged.)
Rules:
cargo tree and the dep's changelog) or propose an MSRV bump.[workspace.package] line and the CI toolchain installer in .github/workflows/engine-ci.yml in the same PR.cargo auditRocky runs cargo audit weekly, not on every PR. From .github/workflows/engine-weekly.yml:
schedule:
- cron: '0 8 * * 1' # Monday 08:00 UTC
- name: Run cargo audit
run: cargo auditThe workflow is also manually dispatchable (workflow_dispatch) and marked continue-on-error: true, so advisories don't block PRs — they surface as a Monday morning report.
To run it locally:
cargo install cargo-audit # first time only
cd engine
cargo auditWhen to react:
critical or high — fix this week. Either bump the transitive dep (via cargo update -p or a workspace bump) or vendor a patch.medium — schedule a fix in the current iteration.low / informational — note, don't drop everything.unsound advisories on a library dep are different from vulnerabilities — they indicate soundness bugs in the dep, and the right fix is usually a version bump or a report upstream, not a workspace allowlist.cargo audit does not currently have an allow-list for accepted advisories in Rocky. If you want to ignore a specific advisory with a reason, that's a policy change — propose it to Hugo first. (The mechanism is audit.toml with ignore = ["RUSTSEC-YYYY-NNNN"] and a reason = "..." line.)
cargo-deny (not currently configured)Rocky does not ship a deny.toml or run cargo-deny in CI as of this skill's authoring. The project's license is Apache-2.0 (engine/Cargo.toml → [workspace.package]). If you want to enforce license compatibility or a banned-deps policy, proposing cargo-deny adoption is the right move — but do it as a dedicated PR, not smuggled into an unrelated change. A minimal deny.toml for Rocky would cover:
licenses: allow Apache-2.0, MIT, BSD-3-Clause, ISC, Unicode-DFS-2016; deny GPL-* / AGPL-* (Rocky is Apache-2.0 and can't take copyleft deps).bans: ban known-bad crates (e.g. openssl-sys when rustls is already the chosen TLS stack — Rocky uses reqwest = { features = ["rustls-tls"] }).advisories: fail on unmaintained + unsound (beyond what cargo audit already catches).sources: restrict to crates-io unless explicit git deps are reviewed.Don't enable this without Hugo's sign-off — it's the kind of change that turns a clean workspace red on day one.
cargo-machetecargo-machete finds unused dependencies per crate. Run it when you've done a large refactor and want to clean up:
cargo install cargo-machete # first time only
cd engine
cargo macheteCaveats:
cargo-machete looks at Cargo.toml vs. actual use statements. It sometimes false-positives on deps that are used only through macros (e.g. serde_json via json!) or only behind #[cfg(...)] feature gates.Cargo.toml is fine, but removing it from [workspace.dependencies] may break another crate.cargo build --all-targets after any deletion to confirm nothing broke.cargo tree -dcd engine
cargo tree -d # show duplicate versions of any transitive dep
cargo tree -d -e features # include feature-flag differencesDuplicates bloat compile time and binary size. The common causes:
[workspace.dependencies].Fix by unifying on one version at the workspace level. Sometimes you can't — two upstreams depend on incompatible ranges of the same crate — in which case document it as a known duplicate and move on.
| Check | Frequency | Blocking? | Tool |
|---|---|---|---|
| Security advisories | Weekly (Monday UTC) | No (continue-on-error) | cargo-audit |
| MSRV compliance | Every PR | Yes (via CI cargo build) | Cargo built-in |
| Clippy on deps | Every PR | Yes (-D warnings) | cargo clippy — see rust-clippy-triage |
| License compatibility | — | Not enforced | cargo-deny (not configured) |
| Unused deps | Ad hoc | No | cargo-machete |
| Duplicate versions | Ad hoc | No | cargo tree -d |
rust-clippy-triage — deprecated-API warnings from bumped deps often surface as clippy lints first.rust-error-handling — when upgrading thiserror or anyhow specifically, read the release notes for breaking changes in derive syntax.rocky-release (monorepo root) — release-time dep pinning and lockfile policy for the engine-v* tag.© rocky-data, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in engine/.claude/skills/rust-dep-hygiene of rocky-data/rocky.
Open the folder on GitHubat commit 9c3d777
Rust Dep Hygiene next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Rust Dep Hygiene this skillrocky-data/rocky | 304 | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Security AuditTheDecipherist/claude-code-mastery | 550 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Rust Security ChecklistJxck/sptth | 133 | — | ~318 | Automated safety check: Pass | MIT | |
| Review Securitypydantic/monty | 8.6k | — | ~852 | Automated safety check: Pass | MIT | |
| Pyspector Security AuditParzivalHack/PySpector | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | |
| SkepticRaoFoundation/subtensor | 389 | — | ~660 | Automated safety check: Pass | Apache-2.0 |
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
Jxck/sptth
Use before merging security-relevant Rust changes. An agent skill from Jxck/sptth.
pydantic/monty
Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses.
ParzivalHack/PySpector
Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.
RaoFoundation/subtensor
Run the security-focused Skeptic persona on the local working tree's diff against a base branch.
deadlock-mod-manager/deadlock-mod-manager
Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.
rocky-data/rocky
Fivetran REST API reference for Rocky's source adapter. An agent skill from rocky-data/rocky.
rocky-data/rocky
Databricks REST API and SQL reference for Rocky's warehouse adapter.
rocky-data/rocky
Rocky CLI JSON-output schema cascade. An agent skill from rocky-data/rocky.
rocky-data/rocky
Top-level router for Rocky development tasks. An agent skill from rocky-data/rocky.
rocky-data/rocky
Rocky DSL (.rocky file) cross-subproject cascade. An agent skill from rocky-data/rocky.
rocky-data/rocky
Adding a new warehouse or source adapter crate to the Rocky engine.
Works with
Categories
Dependency hygiene for the Rocky engine workspace — how to add/update deps via [workspace.dependencies], MSRV 1.88 policy, cargo-audit / cargo-deny / cargo-machete usage, and how the weekly security…. Rust Dep Hygiene is an agent skill from rocky-data/rocky.88 policy, cargo-audit / cargo-deny / cargo-machete usage, and how the weekly security audit surfaces advisories.
Rust Dep Hygiene fits situations like: tasks that involve Security review.
Run `npx skills add rocky-data/rocky --skill rust-dep-hygiene -a claude-code`. Or copy the skill folder (engine/.claude/skills/rust-dep-hygiene in rocky-data/rocky) into .claude/skills/rust-dep-hygiene in your project. Claude Code loads it when a task matches its description.
Run `npx skills add rocky-data/rocky --skill rust-dep-hygiene -a codex`. Or copy the skill folder (engine/.claude/skills/rust-dep-hygiene in rocky-data/rocky) into .agents/skills/rust-dep-hygiene in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rocky-data/rocky --skill rust-dep-hygiene -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rust-dep-hygiene, .gemini/skills/rust-dep-hygiene, .github/skills/rust-dep-hygiene and .opencode/skills/rust-dep-hygiene in your project.
Going by SKILL.md and its folder, Rust Dep Hygiene needs the command-line tools its instructions call (cargo).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Rust Dep Hygiene is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Rust Dep Hygiene: Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Rust Security Checklist (Jxck/sptth, 133 stars), Review Security (pydantic/monty, 8.6k stars) and Pyspector Security Audit (ParzivalHack/PySpector, 151 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
rocky-data (a GitHub organization) maintains it in rocky-data/rocky, which has 304 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 9, 2026.
Source: rocky-data/rocky on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.