Agent skill

Rust Unsafe

by rocky-data in rocky-data/rocky

unsafe conventions in the Rocky engine — SAFETY comment rules, the legitimate unsafe categories (a memory-map, a repr(transparent) cast, and serialised test env-var mutation), and when to push back…

Apache-2.0Auto-check passedData & Analytics

Install Rust Unsafe

skills CLI
$ npx skills add rocky-data/rocky --skill rust-unsafe -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rocky-data/rocky rust-unsafe --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rocky-data/rocky.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engine/.claude/skills/rust-unsafe .claude/skills/rust-unsafe && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rust-unsafe
GitHub stars
304
Token cost
~1.8k tokens
SKILL.md length
809 words
Files
1
Skills in repo
22
Repo updated
First seen
Licence
Apache-2.0

At a glance

unsafe conventions in the Rocky engine — SAFETY comment rules, the legitimate unsafe categories (a memory-map, a repr(transparent) cast, and serialised test env-var mutation), and when to push back…

  • Works in 3 steps: States the invariant the unsafe call… → Justifies why that invariant holds here… → Mentions the fallback if the invariant…
  • Adding any unsafe block/function in the engine crates
  • SKILL.md covers Reality check, The SAFETY: comment rule, Module-level safety docs and When to push back on new unsafe, plus 2 more sections
  • Calls rg and cargo

What it does

Rust Unsafe is an agent skill from rocky-data/rocky. unsafe conventions in the Rocky engine — SAFETY comment rules, the legitimate unsafe categories (a memory-map, a repr(transparent) cast, and serialised test env-var mutation), and when to push back on new unsafe. Use when auditing, reviewing, or adding any unsafe block/function in the engine crates.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Data & Analytics, covering Linting and formatting. It works with Rust. The repository describes itself as: A SQL transformation engine that type-checks your whole pipeline and catches breaking changes before they run — branches, replay, column-level lineage, compile-time contracts… The licence is Apache-2.0.

When your agent uses it

  • Adding any unsafe block/function in the engine crates
  • Tasks that involve Linting and formatting

Example prompts

  • “/rust-unsafe”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. States the invariant the unsafe call depends on (not the API's contract — the thing the caller is promising).
  2. Justifies why that invariant holds here (data shape, locking, single-threaded context, read-only guarantee, etc.).
  3. Mentions the fallback if the invariant is violated, when possible (e.g. "worst case is a parse error, not UB").

What it can do on your machine

Read from SKILL.md and the folder at commit 46be77e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rust Unsafe loads about 1.8k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 809 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rocky-data/rocky at commit 46be77e, republished under its Apache-2.0 licence (© rocky-data). 809 words, ~1,846 tokens.

Download SKILL.mdSave it as .claude/skills/rust-unsafe/SKILL.md (or your agent's skills folder).
name
rust-unsafe
description
`unsafe` conventions in the Rocky engine — SAFETY comment rules, the legitimate unsafe categories (a memory-map, a repr(transparent) cast, and serialised test env-var mutation), and when to push back on new unsafe. Use when auditing, reviewing, or adding any `unsafe` block/function in the engine crates.

unsafe in the Rocky engine

Reality check

Rocky keeps unsafe minimal and boring on purpose. It falls into two buckets — get the live list with rg -n '\bunsafe\b' crates/ from engine/ rather than trusting a hardcoded count (the set drifts as tests are added):

Production unsafe — two sites, both in rocky-core:

SiteWhat's unsafeWhy it's justified
rocky-core/src/mmap.rsmemmap2::Mmap::map(&file) for project filesReading many SQL/TOML files during compile wants mmap for throughput; the mapped bytes are read-only project source — worst case is a garbled read → parse error, not UB.
rocky-core/src/column_map.rs&*(s as *const str as *const CiStr) — cast to a #[repr(transparent)] case-insensitive str newtypeLayout-compatible by repr(transparent); the borrow never outlives the input str.

Test-only unsafe — the majority of sites: std::env::{set_var, remove_var} inside #[cfg(test)] modules across many crates (config.rs, models.rs, pipes.rs, object_store.rs, rocky-observe, rocky-server/src/lsp.rs, several rocky-cli commands, and integration tests). Env mutation became unsafe in the 2024 edition because it races with concurrent reads; every one is serialised under a module ENV_LOCK (or a single-threaded test) and restores state before returning.

There is no FFI unsafe. The duckdb crate, jsonwebtoken, and rsa all wrap their C / crypto surfaces in safe APIs — Rocky calls those and never reaches into duckdb_sys or similar. If you find yourself writing an FFI binding from scratch, stop and check whether the upstream crate already has a safe wrapper.

Keep this list short. Every new unsafe site is a reviewer tax and a future soundness bug waiting to happen.

The SAFETY: comment rule

Every unsafe block, function, impl, or trait must be accompanied by a SAFETY: comment that states the invariant the caller/author is relying on. This is non-negotiable and matches the convention across the Rocky codebase.

The comment format:

rust
// SAFETY: <one-sentence invariant>.
//         <optional follow-up: why the invariant holds here, or the fallback if it doesn't>.
unsafe { ... }

Two real examples from the codebase (rg "SAFETY:" engine/crates/ to see them live):

rust
// rocky-core/src/mmap.rs:39
// SAFETY: We only read project files that are not being modified
// concurrently during compilation. Worst case: garbled read → parse error.
let mmap = unsafe { memmap2::Mmap::map(&file)? };
rust
// rocky-core/src/config.rs:1088 (test code)
// SAFETY: test-only, no concurrent reads of this variable
unsafe { std::env::set_var("ROCKY_TEST_VAR", "hello_world") };

What a good SAFETY: comment does:

  1. States the invariant the unsafe call depends on (not the API's contract — the thing the caller is promising).
  2. Justifies why that invariant holds here (data shape, locking, single-threaded context, read-only guarantee, etc.).
  3. Mentions the fallback if the invariant is violated, when possible (e.g. "worst case is a parse error, not UB").

What a bad SAFETY: comment looks like:

  • // SAFETY: this is safe — useless; delete and re-write.
  • // SAFETY: the docs say so — where? Cite the exact contract.
  • // SAFETY: tested — tests don't prove memory safety.
  • No comment at all — blocks review.

Module-level safety docs

If an entire module's purpose is to wrap unsafe primitives behind a safe interface, document that at the module level using //! # Safety. rocky-core/src/mmap.rs is the reference:

rust
//! Memory-mapped file I/O for efficient project loading.
//!
//! # Safety
//!
//! `memmap2::Mmap` is `unsafe` because another process could modify the
//! file while it's mapped. We accept this risk for read-only project
//! loading because:
//! 1. Project files are not modified during compilation.
//! 2. The worst case is a garbled read that fails parsing (not UB).
//! 3. The performance benefit at scale (50k+ files) justifies the trade-off.

Follow this shape whenever you introduce a new module containing unsafe. The doc-level section complements the inline SAFETY: comments — the module-level explains why this module needs unsafe at all, the inline explains why each specific site is sound.

Public unsafe fn declarations also need a # Safety section in their doc comment — see the rust-doc skill.

Show full SKILL.md (330 more words)Show less

When to push back on new unsafe

Before merging a PR that adds new unsafe, ask:

  1. Is there a safe alternative? Most of the time there is — std::cell::UnsafeCell → RefCell, raw pointer arithmetic → slice::split_at, manual bit-twiddling → bytemuck, hand-rolled FFI → a safe crate wrapper.
  2. Is the performance win measured? mmap.rs justifies itself with "50k+ files"; speculative performance claims are not enough.
  3. Is the invariant stable? An invariant that holds today but could be invalidated by an unrelated refactor is a soundness bomb. If you can't describe a test or type-level property that will break loudly when the invariant fails, reconsider.
  4. Who else reads this? rocky-core is the library that everything else links against. A bug there is a bug everywhere — the bar for new unsafe in rocky-core is higher than in a leaf adapter crate.

If you can't answer all four, leave the safe implementation in place and open a perf issue instead.

Linting and auditing

grep surface
bash
# Find every unsafe site in the engine — run from engine/
rg -n '\bunsafe\b' crates/

# Find every SAFETY: comment (should roughly match the count above)
rg -n 'SAFETY:' crates/

# Find unsafe sites without an adjacent SAFETY: comment (needs human review)
rg -nB1 '\bunsafe\s*\{' crates/ | rg -v 'SAFETY:'

If the last command shows a site that doesn't have a SAFETY: comment within the surrounding 1-2 lines, that's a bug to fix before merge.

Lints

Rocky runs cargo clippy --all-targets -- -D warnings. The relevant clippy lints for unsafe are:

  • clippy::undocumented_unsafe_blocks — fires on unsafe { ... } without a SAFETY: comment. Not in the default set, so it currently doesn't enforce the rule at CI level — but it's the right lint to consider if you want to make the rule a machine-checkable policy. (Adding it to [workspace.lints] is a policy change — see the rust-clippy-triage skill for the rule on workspace lint changes.)
  • clippy::multiple_unsafe_ops_per_block — fires if one unsafe { ... } block does more than one unsafe operation. Splitting them makes each SAFETY: comment tighter.
  • rust-doc — public unsafe fn needs a # Safety section in its doc comment.
  • rust-clippy-triage — how to react when an unsafe-related lint fires, and why workspace-level lint changes need Hugo review.
  • rust-style — the wildcard-match rule is load-bearing around unsafe too: every enum variant you forget is one you're silently assuming doesn't exist.

© rocky-data, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in engine/.claude/skills/rust-unsafe of rocky-data/rocky.

Open the folder on GitHubat commit 46be77e

Compare with similar skills

Rust Unsafe next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rust Unsafe compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rust Unsafe this skillrocky-data/rocky304—~1.8kAutomated safety check: PassApache-2.0
Clippy CIlakeops-org/queryflux144—~458Automated safety check: PassApache-2.0
Diesel Guardayarotsky/diesel-guard121—~3.1kAutomated safety check: PassMIT
Rust Best Practicesfarm-fe/farm5.6k3 repos~1.1kAutomated safety check: PassMIT
Doc Commentsbiomejs/biome26k—~3kAutomated safety check: PassApache-2.0
Rust Hygiene Audittsz-org/tsz577—~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • Clippy CI

    lakeops-org/queryflux

    Run QueryFlux Clippy the same way CI does (-D warnings, workspace, exclude queryflux-bench) and fix failures before opening or updating a PR.

    144 GitHub stars~458 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Diesel Guard

    ayarotsky/diesel-guard

    Lints Diesel and SQLx Postgres migrations for unsafe schema changes that lock tables or cause downtime, and authors custom Rhai checks.

    121 GitHub stars~3.1k tokensUpdated 9 days ago
    DatabasesAuto-check passed
  • Guide for writing idiomatic Rust code based on Apollo GraphQL's best practices handbook.

    5.6k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Doc Comments

    biomejs/biome

    Official

    A skill your agent uses whenever writing or editing Rust //, ///, or //!

    26k GitHub stars~3k tokensUpdated today
    DevelopmentAuto-check passed
  • Run a deep DRY + code-hygiene audit of the Rust workspace and turn the findings into verified, deduplicated, hierarchical GitHub tech-debt issues.

    577 GitHub stars~1.5k tokensUpdated 28 days ago
    DevelopmentAuto-check passed
  • Release

    xin2017338/lynx-proxy

    Publish a new release version of Lynx Proxy. An agent skill from xin2017338/lynx-proxy.

    502 GitHub stars~1.1k tokensUpdated 23 days ago
    DevelopmentAuto-check passed

More from rocky-data/rocky

All 22 skills in this repo
  • Fivetran

    rocky-data/rocky

    Fivetran REST API reference for Rocky's source adapter. An agent skill from rocky-data/rocky.

    304 GitHub stars~914 tokensUpdated today
    Auto-check passed
  • Databricks

    rocky-data/rocky

    Databricks REST API and SQL reference for Rocky's warehouse adapter.

    304 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Rocky Codegen

    rocky-data/rocky

    Rocky CLI JSON-output schema cascade. An agent skill from rocky-data/rocky.

    304 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Rocky Dev

    rocky-data/rocky

    Top-level router for Rocky development tasks. An agent skill from rocky-data/rocky.

    304 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Rocky Dsl Change

    rocky-data/rocky

    Rocky DSL (.rocky file) cross-subproject cascade. An agent skill from rocky-data/rocky.

    304 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Rocky New Adapter

    rocky-data/rocky

    Adding a new warehouse or source adapter crate to the Rocky engine.

    304 GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Rust Unsafe

What does Rust Unsafe do?

unsafe conventions in the Rocky engine — SAFETY comment rules, the legitimate unsafe categories (a memory-map, a repr(transparent) cast, and serialised test env-var mutation), and when to push back…. Rust Unsafe is an agent skill from rocky-data/rocky. unsafe conventions in the Rocky engine — SAFETY comment rules, the legitimate unsafe categories (a memory-map, a repr(transparent) cast, and serialised test env-var mutation), and when to push back on new unsafe.

When should I use Rust Unsafe?

Rust Unsafe fits situations like: adding any unsafe block/function in the engine crates; tasks that involve Linting and formatting.

How do I install Rust Unsafe in Claude Code?

Run `npx skills add rocky-data/rocky --skill rust-unsafe -a claude-code`. Or copy the skill folder (engine/.claude/skills/rust-unsafe in rocky-data/rocky) into .claude/skills/rust-unsafe in your project. Claude Code loads it when a task matches its description.

How do I install Rust Unsafe in Codex?

Run `npx skills add rocky-data/rocky --skill rust-unsafe -a codex`. Or copy the skill folder (engine/.claude/skills/rust-unsafe in rocky-data/rocky) into .agents/skills/rust-unsafe in your project. Codex loads it when a task matches its description.

Can I use Rust Unsafe in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rocky-data/rocky --skill rust-unsafe -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rust-unsafe, .gemini/skills/rust-unsafe, .github/skills/rust-unsafe and .opencode/skills/rust-unsafe in your project.

What does Rust Unsafe need to run?

Going by SKILL.md and its folder, Rust Unsafe needs the command-line tools its instructions call (rg and cargo).

Does Rust Unsafe access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Rust Unsafe safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rust Unsafe use?

Rust Unsafe is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rust Unsafe use?

About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rust Unsafe?

Skills that share tags, products or a category with Rust Unsafe: Clippy CI (lakeops-org/queryflux, 144 stars), Diesel Guard (ayarotsky/diesel-guard, 121 stars), Rust Best Practices (farm-fe/farm, 5.6k stars) and Doc Comments (biomejs/biome, 26k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rust Unsafe?

rocky-data (a GitHub organization) maintains it in rocky-data/rocky, which has 304 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 8, 2026.

Source: rocky-data/rocky on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.