Clippy CI
lakeops-org/queryflux
Run QueryFlux Clippy the same way CI does (-D warnings, workspace, exclude queryflux-bench) and fix failures before opening or updating a PR.
unsafe conventions in the Rocky engine — SAFETY comment rules, the legitimate unsafe categories (a memory-map, a repr(transparent) cast, and serialised test env-var mutation), and when to push back…
$ npx skills add rocky-data/rocky --skill rust-unsafe -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install rocky-data/rocky rust-unsafe --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/rocky-data/rocky.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engine/.claude/skills/rust-unsafe .claude/skills/rust-unsafe && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "rust-unsafe" agent skill from https://github.com/rocky-data/rocky/tree/main/engine/.claude/skills/rust-unsafe into .claude/skills/rust-unsafe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rust-unsafe", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/rocky-data/rocky/tree/main/engine/.claude/skills/rust-unsafeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add rocky-data/rocky --skill rust-unsafe -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install rocky-data/rocky rust-unsafe --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rocky-data/rocky.git skills-src && mkdir -p .agents/skills && cp -r skills-src/engine/.claude/skills/rust-unsafe .agents/skills/rust-unsafe && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "rust-unsafe" agent skill from https://github.com/rocky-data/rocky/tree/main/engine/.claude/skills/rust-unsafe into .agents/skills/rust-unsafe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rust-unsafe", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rocky-data/rocky --skill rust-unsafe -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install rocky-data/rocky rust-unsafe --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rocky-data/rocky.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/engine/.claude/skills/rust-unsafe .cursor/skills/rust-unsafe && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "rust-unsafe" agent skill from https://github.com/rocky-data/rocky/tree/main/engine/.claude/skills/rust-unsafe into .cursor/skills/rust-unsafe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rust-unsafe", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/rocky-data/rocky.git --path engine/.claude/skills/rust-unsafe--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add rocky-data/rocky --skill rust-unsafe -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install rocky-data/rocky rust-unsafe --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rocky-data/rocky.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/engine/.claude/skills/rust-unsafe .gemini/skills/rust-unsafe && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "rust-unsafe" agent skill from https://github.com/rocky-data/rocky/tree/main/engine/.claude/skills/rust-unsafe into .gemini/skills/rust-unsafe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rust-unsafe", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install rocky-data/rocky rust-unsafeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add rocky-data/rocky --skill rust-unsafe -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/rocky-data/rocky.git skills-src && mkdir -p .github/skills && cp -r skills-src/engine/.claude/skills/rust-unsafe .github/skills/rust-unsafe && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "rust-unsafe" agent skill from https://github.com/rocky-data/rocky/tree/main/engine/.claude/skills/rust-unsafe into .github/skills/rust-unsafe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rust-unsafe", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rocky-data/rocky --skill rust-unsafe -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install rocky-data/rocky rust-unsafe --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rocky-data/rocky.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/engine/.claude/skills/rust-unsafe .opencode/skills/rust-unsafe && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "rust-unsafe" agent skill from https://github.com/rocky-data/rocky/tree/main/engine/.claude/skills/rust-unsafe into .opencode/skills/rust-unsafe/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "rust-unsafe", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
rust-unsafeunsafe conventions in the Rocky engine — SAFETY comment rules, the legitimate unsafe categories (a memory-map, a repr(transparent) cast, and serialised test env-var mutation), and when to push back…
Rust Unsafe is an agent skill from rocky-data/rocky. unsafe conventions in the Rocky engine — SAFETY comment rules, the legitimate unsafe categories (a memory-map, a repr(transparent) cast, and serialised test env-var mutation), and when to push back on new unsafe. Use when auditing, reviewing, or adding any unsafe block/function in the engine crates.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Data & Analytics, covering Linting and formatting. It works with Rust. The repository describes itself as: A SQL transformation engine that type-checks your whole pipeline and catches breaking changes before they run — branches, replay, column-level lineage, compile-time contracts… The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 46be77e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
rgcargoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Rust Unsafe loads about 1.8k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 809 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from rocky-data/rocky at commit 46be77e, republished under its Apache-2.0 licence (© rocky-data). 809 words, ~1,846 tokens.
.claude/skills/rust-unsafe/SKILL.md (or your agent's skills folder).unsafe in the Rocky engineRocky keeps unsafe minimal and boring on purpose. It falls into two buckets — get the live list with rg -n '\bunsafe\b' crates/ from engine/ rather than trusting a hardcoded count (the set drifts as tests are added):
Production unsafe — two sites, both in rocky-core:
| Site | What's unsafe | Why it's justified |
|---|---|---|
rocky-core/src/mmap.rs | memmap2::Mmap::map(&file) for project files | Reading many SQL/TOML files during compile wants mmap for throughput; the mapped bytes are read-only project source — worst case is a garbled read → parse error, not UB. |
rocky-core/src/column_map.rs | &*(s as *const str as *const CiStr) — cast to a #[repr(transparent)] case-insensitive str newtype | Layout-compatible by repr(transparent); the borrow never outlives the input str. |
Test-only unsafe — the majority of sites: std::env::{set_var, remove_var} inside #[cfg(test)] modules across many crates (config.rs, models.rs, pipes.rs, object_store.rs, rocky-observe, rocky-server/src/lsp.rs, several rocky-cli commands, and integration tests). Env mutation became unsafe in the 2024 edition because it races with concurrent reads; every one is serialised under a module ENV_LOCK (or a single-threaded test) and restores state before returning.
There is no FFI unsafe. The duckdb crate, jsonwebtoken, and rsa all wrap their C / crypto surfaces in safe APIs — Rocky calls those and never reaches into duckdb_sys or similar. If you find yourself writing an FFI binding from scratch, stop and check whether the upstream crate already has a safe wrapper.
Keep this list short. Every new unsafe site is a reviewer tax and a future soundness bug waiting to happen.
SAFETY: comment ruleEvery unsafe block, function, impl, or trait must be accompanied by a SAFETY: comment that states the invariant the caller/author is relying on. This is non-negotiable and matches the convention across the Rocky codebase.
The comment format:
// SAFETY: <one-sentence invariant>.
// <optional follow-up: why the invariant holds here, or the fallback if it doesn't>.
unsafe { ... }Two real examples from the codebase (rg "SAFETY:" engine/crates/ to see them live):
// rocky-core/src/mmap.rs:39
// SAFETY: We only read project files that are not being modified
// concurrently during compilation. Worst case: garbled read → parse error.
let mmap = unsafe { memmap2::Mmap::map(&file)? };// rocky-core/src/config.rs:1088 (test code)
// SAFETY: test-only, no concurrent reads of this variable
unsafe { std::env::set_var("ROCKY_TEST_VAR", "hello_world") };What a good SAFETY: comment does:
unsafe call depends on (not the API's contract — the thing the caller is promising).What a bad SAFETY: comment looks like:
// SAFETY: this is safe — useless; delete and re-write.// SAFETY: the docs say so — where? Cite the exact contract.// SAFETY: tested — tests don't prove memory safety.If an entire module's purpose is to wrap unsafe primitives behind a safe interface, document that at the module level using //! # Safety. rocky-core/src/mmap.rs is the reference:
//! Memory-mapped file I/O for efficient project loading.
//!
//! # Safety
//!
//! `memmap2::Mmap` is `unsafe` because another process could modify the
//! file while it's mapped. We accept this risk for read-only project
//! loading because:
//! 1. Project files are not modified during compilation.
//! 2. The worst case is a garbled read that fails parsing (not UB).
//! 3. The performance benefit at scale (50k+ files) justifies the trade-off.Follow this shape whenever you introduce a new module containing unsafe. The doc-level section complements the inline SAFETY: comments — the module-level explains why this module needs unsafe at all, the inline explains why each specific site is sound.
Public unsafe fn declarations also need a # Safety section in their doc comment — see the rust-doc skill.
unsafeBefore merging a PR that adds new unsafe, ask:
std::cell::UnsafeCell → RefCell, raw pointer arithmetic → slice::split_at, manual bit-twiddling → bytemuck, hand-rolled FFI → a safe crate wrapper.mmap.rs justifies itself with "50k+ files"; speculative performance claims are not enough.rocky-core is the library that everything else links against. A bug there is a bug everywhere — the bar for new unsafe in rocky-core is higher than in a leaf adapter crate.If you can't answer all four, leave the safe implementation in place and open a perf issue instead.
# Find every unsafe site in the engine — run from engine/
rg -n '\bunsafe\b' crates/
# Find every SAFETY: comment (should roughly match the count above)
rg -n 'SAFETY:' crates/
# Find unsafe sites without an adjacent SAFETY: comment (needs human review)
rg -nB1 '\bunsafe\s*\{' crates/ | rg -v 'SAFETY:'If the last command shows a site that doesn't have a SAFETY: comment within the surrounding 1-2 lines, that's a bug to fix before merge.
Rocky runs cargo clippy --all-targets -- -D warnings. The relevant clippy lints for unsafe are:
clippy::undocumented_unsafe_blocks — fires on unsafe { ... } without a SAFETY: comment. Not in the default set, so it currently doesn't enforce the rule at CI level — but it's the right lint to consider if you want to make the rule a machine-checkable policy. (Adding it to [workspace.lints] is a policy change — see the rust-clippy-triage skill for the rule on workspace lint changes.)clippy::multiple_unsafe_ops_per_block — fires if one unsafe { ... } block does more than one unsafe operation. Splitting them makes each SAFETY: comment tighter.rust-doc — public unsafe fn needs a # Safety section in its doc comment.rust-clippy-triage — how to react when an unsafe-related lint fires, and why workspace-level lint changes need Hugo review.rust-style — the wildcard-match rule is load-bearing around unsafe too: every enum variant you forget is one you're silently assuming doesn't exist.© rocky-data, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in engine/.claude/skills/rust-unsafe of rocky-data/rocky.
Open the folder on GitHubat commit 46be77e
Rust Unsafe next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Rust Unsafe this skillrocky-data/rocky | 304 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Clippy CIlakeops-org/queryflux | 144 | — | ~458 | Automated safety check: Pass | Apache-2.0 | |
| Diesel Guardayarotsky/diesel-guard | 121 | — | ~3.1k | Automated safety check: Pass | MIT | |
| Rust Best Practicesfarm-fe/farm | 5.6k | 3 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Doc Commentsbiomejs/biome | 26k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Rust Hygiene Audittsz-org/tsz | 577 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 |
lakeops-org/queryflux
Run QueryFlux Clippy the same way CI does (-D warnings, workspace, exclude queryflux-bench) and fix failures before opening or updating a PR.
ayarotsky/diesel-guard
Lints Diesel and SQLx Postgres migrations for unsafe schema changes that lock tables or cause downtime, and authors custom Rhai checks.
farm-fe/farm
Guide for writing idiomatic Rust code based on Apollo GraphQL's best practices handbook.
biomejs/biome
A skill your agent uses whenever writing or editing Rust //, ///, or //!
tsz-org/tsz
Run a deep DRY + code-hygiene audit of the Rust workspace and turn the findings into verified, deduplicated, hierarchical GitHub tech-debt issues.
xin2017338/lynx-proxy
Publish a new release version of Lynx Proxy. An agent skill from xin2017338/lynx-proxy.
rocky-data/rocky
Fivetran REST API reference for Rocky's source adapter. An agent skill from rocky-data/rocky.
rocky-data/rocky
Databricks REST API and SQL reference for Rocky's warehouse adapter.
rocky-data/rocky
Rocky CLI JSON-output schema cascade. An agent skill from rocky-data/rocky.
rocky-data/rocky
Top-level router for Rocky development tasks. An agent skill from rocky-data/rocky.
rocky-data/rocky
Rocky DSL (.rocky file) cross-subproject cascade. An agent skill from rocky-data/rocky.
rocky-data/rocky
Adding a new warehouse or source adapter crate to the Rocky engine.
Works with
Categories
unsafe conventions in the Rocky engine — SAFETY comment rules, the legitimate unsafe categories (a memory-map, a repr(transparent) cast, and serialised test env-var mutation), and when to push back…. Rust Unsafe is an agent skill from rocky-data/rocky. unsafe conventions in the Rocky engine — SAFETY comment rules, the legitimate unsafe categories (a memory-map, a repr(transparent) cast, and serialised test env-var mutation), and when to push back on new unsafe.
Rust Unsafe fits situations like: adding any unsafe block/function in the engine crates; tasks that involve Linting and formatting.
Run `npx skills add rocky-data/rocky --skill rust-unsafe -a claude-code`. Or copy the skill folder (engine/.claude/skills/rust-unsafe in rocky-data/rocky) into .claude/skills/rust-unsafe in your project. Claude Code loads it when a task matches its description.
Run `npx skills add rocky-data/rocky --skill rust-unsafe -a codex`. Or copy the skill folder (engine/.claude/skills/rust-unsafe in rocky-data/rocky) into .agents/skills/rust-unsafe in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rocky-data/rocky --skill rust-unsafe -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rust-unsafe, .gemini/skills/rust-unsafe, .github/skills/rust-unsafe and .opencode/skills/rust-unsafe in your project.
Going by SKILL.md and its folder, Rust Unsafe needs the command-line tools its instructions call (rg and cargo).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Rust Unsafe is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Rust Unsafe: Clippy CI (lakeops-org/queryflux, 144 stars), Diesel Guard (ayarotsky/diesel-guard, 121 stars), Rust Best Practices (farm-fe/farm, 5.6k stars) and Doc Comments (biomejs/biome, 26k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
rocky-data (a GitHub organization) maintains it in rocky-data/rocky, which has 304 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 8, 2026.
Source: rocky-data/rocky on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.