Agent skill

Rust Rules

by softspark in softspark/ai-toolkit

Rust coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.

Apache-2.0Auto-check passed

Install Rust Rules

skills CLI
$ npx skills add softspark/ai-toolkit --skill rust-rules -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install softspark/ai-toolkit rust-rules --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/app/skills/rust-rules .claude/skills/rust-rules && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rust-rules
GitHub stars
179
Token cost
~3.1k tokens
SKILL.md length
1,489 words
Files
1
Skills in repo
112
Repo updated
First seen
Licence
Apache-2.0

At a glance

Rust coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.

  • SKILL.md covers Naming, Ownership, Types and Functions, plus 21 more sections
  • Calls cargo

What it does

Rust Rules is an agent skill from softspark/ai-toolkit. Rust coding rules: style, patterns, security, testing. Triggers: .rs, Cargo.toml, Cargo.lock, Tokio, Axum, Serde, clippy, cargo test.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Rust. The repository describes itself as: Professional-grade AI coding toolkit: 94 skills, 44 agents, multi-platform (Claude, Cursor, Windsurf, Copilot, Gemini, Cline, Roo Code, Aider, Augment, Antigravity, Codex CLI… The licence is Apache-2.0.

Example prompts

  • “/rust-rules”

Requirements

  • Docker
  • Pre-approved tools (allowed-tools): Read

What it can do on your machine

Read from SKILL.md and the folder at commit d64db2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rust Rules loads about 3.1k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 1,489 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from softspark/ai-toolkit at commit d64db2b, republished under its Apache-2.0 licence (© softspark). 1,489 words, ~3,110 tokens.

Download SKILL.mdSave it as .claude/skills/rust-rules/SKILL.md (or your agent's skills folder).
name
rust-rules
description
Rust coding rules: style, patterns, security, testing. Triggers: .rs, Cargo.toml, Cargo.lock, Tokio, Axum, Serde, clippy, cargo test.
allowed-tools
Read
effort
medium
user-invocable
false

Rust Rules

These rules come from app/rules/rust/ in ai-toolkit. They cover the project's standards for coding style, frameworks, patterns, security, and testing in Rust. Apply them when writing or reviewing Rust code.

Rust Coding Style

Naming

  • snake_case: functions, methods, variables, modules, crates.
  • PascalCase: types, traits, enums, structs, type parameters.
  • SCREAMING_SNAKE: constants and statics.
  • Short lifetimes: 'a, 'b. Descriptive only when multiple coexist: 'input, 'output.
  • Crate names: kebab-case in Cargo.toml, snake_case in code.

Ownership

  • Borrow (&T) when you only need to read. Own (T) when storing or consuming.
  • Use &str over String in function parameters when possible.
  • Use Cow<'_, str> when you sometimes need to allocate.
  • Avoid .clone() as a first resort -- restructure ownership instead.
  • Use Arc<T> only when shared ownership across threads is required.

Types

  • Use newtypes for domain primitives: struct UserId(Uuid).
  • Use #[derive(Debug, Clone, PartialEq)] on data types.
  • Implement Display for user-facing output, Debug for developer output.
  • Use #[non_exhaustive] on public enums and structs for future compatibility.
  • Prefer enums over boolean flags for state representation.

Functions

  • Return Result<T, E> for operations that can fail. Avoid panicking.
  • Use impl Trait in argument position for flexibility, return position for simplicity.
  • Use where clauses for complex bounds instead of inline.
  • Prefer iterators over index-based loops.
  • Use let-else (1.65+) for early-exit pattern matching.

Modules

  • Use mod.rs or filename-based modules. Be consistent within the project.
  • Re-export public API from lib.rs for a clean surface.
  • Keep modules focused. One major type or concept per module.
  • Use pub(crate) for internal-only visibility.

Formatting

  • Use rustfmt with default settings. Do not fight the formatter.
  • Use clippy with -D warnings in CI. Fix all warnings.
  • Set MSRV (Minimum Supported Rust Version) in Cargo.toml.

Cargo

  • Use workspace dependencies to unify versions across crates.
  • Use feature flags for optional functionality.
  • Set edition = "2021" (or latest stable edition).
  • Use [profile.release] with lto = true and codegen-units = 1 for production.

Rust Frameworks

Axum

  • Use extractors for typed request parsing: Path, Query, Json, State.
  • Use Router::new().route("/path", get(handler)) for route definitions.
  • Share state via State(Arc<AppState>) extractor.
  • Implement IntoResponse on error types for clean error handling.
  • Use Tower middleware layers for auth, logging, tracing, rate limiting.

Actix-web

  • Use extractors: web::Path, web::Json, web::Data.
  • Use App::new().service() for route configuration.
  • Share state with web::Data<Arc<State>>.
  • Use actix-web::middleware for logging and error handling.

Tokio

  • Use #[tokio::main] for the entry point. Use tokio::spawn for tasks.
  • Use tokio::select! for waiting on multiple futures.
  • Use tokio::time::timeout() for operation deadlines.
  • Use tokio::sync::broadcast for pub/sub, mpsc for work queues.
  • Use tokio::task::spawn_blocking() for CPU-intensive work in async context.

SQLx

  • Use compile-time checked queries: sqlx::query_as!(User, "SELECT ...").
  • Use PgPool for connection pooling. Pass as shared state.
  • Use migrations: sqlx migrate add and sqlx migrate run.
  • Use sqlx::FromRow derive for automatic struct mapping.
  • Set DATABASE_URL for compile-time query verification.

Serde

  • Use #[derive(Serialize, Deserialize)] on all DTOs.
  • Use #[serde(rename_all = "camelCase")] for JSON API compatibility.
  • Use #[serde(deny_unknown_fields)] for strict deserialization.
  • Use #[serde(default)] for optional fields with defaults.
  • Use #[serde(skip_serializing_if = "Option::is_none")] for clean output.

Clap

  • Use #[derive(Parser)] for CLI argument parsing.
  • Use subcommands with enum variants: #[derive(Subcommand)].
  • Use #[arg(env = "VAR_NAME")] for env var fallback.
  • Use value_parser for custom validation of arguments.

Tracing

  • Use tracing crate over log for structured, async-aware logging.
  • Use #[instrument] attribute on functions for automatic span creation.
  • Use tracing_subscriber with EnvFilter for runtime log level control.
  • Add trace_id to all log entries for distributed tracing correlation.

Testing Crates

  • mockall: auto-generate mocks from traits.
  • wiremock: HTTP mock server for integration tests.
  • testcontainers: Docker containers for database tests.
  • proptest / quickcheck: property-based testing.

Rust Patterns

Error Handling

  • Use thiserror for library error types (structured, typed enums).
  • Use anyhow for application/binary code (flexible, context-rich).
  • Wrap errors with context: .with_context(|| format!("loading {path}"))?.
  • Use #[from] attribute for automatic error conversion in thiserror enums.
  • Map domain errors to HTTP/gRPC errors at API boundaries only.

Builder Pattern

  • Use builder for structs with many optional fields.
  • Return Result from build() when validation is needed.
  • Use #[derive(Default)] + TypedBuilder derive macro for compile-time safety.
  • Chain setter methods returning Self for ergonomic API.

Newtype Pattern

  • Wrap primitive types for type safety: struct Email(String).
  • Validate in constructor: Email::new(raw) -> Result<Self, ValidationError>.
  • Implement Deref only when the inner type's full API is appropriate.
  • Use #[repr(transparent)] for zero-cost newtypes in FFI.

Trait Design

  • Keep traits small and focused. Compose with supertraits.
  • Use associated types for output types: type Output;.
  • Use default method implementations for common behavior.
  • Use extension traits to add methods to foreign types.

Async Patterns

  • Use tokio as the async runtime for most applications.
  • Use tokio::spawn for concurrent tasks, tokio::select! for racing.
  • Use tokio::sync::mpsc for channels, tokio::sync::Mutex for async locks.
  • Prefer async fn in traits (Rust 1.75+) over manual Pin<Box<dyn Future>>.
  • Use tower middleware pattern for layered request processing.

Iterator Patterns

  • Use .iter() / .into_iter() / .iter_mut() appropriately.
  • Chain: filter().map().collect() instead of manual loops.
  • Use collect::<Result<Vec<_>, _>>() to short-circuit on first error.
  • Implement IntoIterator for custom collections.

State Machine

  • Use enums with data variants for state machines.
  • Use match exhaustively -- compiler prevents missing states.
  • Encode valid transitions in the type system when possible.
  • Use typestate pattern for compile-time state transition enforcement.

Anti-Patterns

  • .unwrap() in library code -- return Result or Option.
  • .clone() to fix borrow checker -- restructure ownership.
  • Arc<Mutex<T>> as first approach -- consider channels or actors.
  • Box<dyn Error> in libraries -- use typed error enums.
  • Ignoring #[must_use] warnings -- handle or explicitly discard with let _ =.

Rust Security

Memory Safety

  • Rust's ownership system prevents most memory bugs. Do not circumvent it.
  • Minimize unsafe blocks. Document every safety invariant with // SAFETY:.
  • Use #![forbid(unsafe_code)] in library crates when possible.
  • Audit all unsafe code during review. Treat it as a security boundary.
  • Use miri in CI for detecting undefined behavior in unsafe code.
Show full SKILL.md (571 more words)Show less

Input Validation

  • Validate all external input before processing. Use newtypes with validation.
  • Use serde with #[serde(deny_unknown_fields)] for strict deserialization.
  • Set size limits on deserialized data: #[serde(deserialize_with = "...")].
  • Validate string lengths, numeric ranges, and formats at API boundaries.

SQL Injection

  • Use sqlx parameterized queries: sqlx::query!("SELECT * WHERE id = $1", id).
  • Never build SQL strings with format!() using user input.
  • Use sqlx::query_builder::QueryBuilder for dynamic query construction.
  • Type-check queries at compile time with sqlx::query! macro.

Cryptography

  • Use ring or rustcrypto crates for cryptographic operations.
  • Use argon2 crate for password hashing.
  • Use subtle::ConstantTimeEq for timing-safe comparisons.
  • Use rand crate with OsRng for cryptographically secure random values.
  • Never implement custom cryptographic algorithms.

Dependencies

  • Run cargo audit in CI to check for known vulnerabilities.
  • Run cargo deny check for license compliance and advisory checking.
  • Use cargo tree -d to find duplicate dependencies.
  • Review build.rs scripts in dependencies -- they execute at compile time.
  • Minimize dependency count. Each crate is a potential attack surface.

Secrets

  • Load secrets from environment: std::env::var("SECRET").
  • Use secrecy crate for values that should not be logged or displayed.
  • Zeroize sensitive data after use with zeroize crate.
  • Never hardcode secrets, tokens, or keys in source code.

Panic Safety

  • Use Result and Option instead of panicking in library code.
  • Use catch_unwind at FFI boundaries to prevent unwinding across languages.
  • Set panic = "abort" in release profile to prevent panic exploitation.
  • Avoid unwrap() and expect() on user-controlled data.

Network Security

  • Use rustls over OpenSSL for TLS (pure Rust, memory-safe).
  • Set timeouts on all network operations.
  • Implement rate limiting on public endpoints.
  • Validate and sanitize URLs before making outbound requests.

Supply Chain

  • Use cargo-vet to track third-party audit status.
  • Use cargo-crev for community code reviews.
  • Enable Cargo.lock in version control for applications (not libraries).
  • Prefer well-maintained crates with recent activity and security audits.

Rust Testing

Unit Tests

  • Place unit tests in #[cfg(test)] mod tests at the bottom of each file.
  • Use #[test] attribute. Use #[tokio::test] for async tests.
  • Name tests descriptively: fn rejects_invalid_email().
  • Access private items directly -- unit test modules are inside the parent module.

Integration Tests

  • Place in tests/ directory. Each file compiles as a separate crate.
  • Test only the public API from integration tests.
  • Use tests/common/mod.rs for shared test utilities.
  • Name files by feature area: tests/api_test.rs, tests/auth_test.rs.

Assertions

  • Use assert_eq!(actual, expected) with the actual value first.
  • Use assert!(matches!(result, Ok(_))) for pattern matching in assertions.
  • Use custom error messages: assert_eq!(x, 5, "expected x to be 5, got {x}").
  • Use #[should_panic(expected = "message")] for testing panics.

Result Testing

  • Use -> Result<(), Box<dyn Error>> return type in tests for ? support.
  • Test error variants: assert!(matches!(result, Err(AppError::NotFound(_)))).
  • Use .unwrap() in tests when failure means a bug in the test.

Mocking

  • Use mockall crate with #[automock] on trait definitions.
  • Use expect_* methods to set expectations on mock behavior.
  • Prefer trait-based DI for testability. Accept impl Trait in constructors.
  • Use fake crate for generating realistic test data.

Property Testing

  • Use proptest for property-based testing on parsing and validation.
  • Define strategies: prop::string::string_regex("[a-z]+@[a-z]+\\.[a-z]{2,4}").
  • Use proptest! macro for concise property test definitions.
  • Test invariants: serialization roundtrips, ordering consistency.

Benchmarks

  • Use criterion crate for statistical benchmarks (not built-in #[bench]).
  • Use black_box() to prevent compiler optimization of benchmark code.
  • Run benchmarks before and after optimization to measure impact.
  • Use cargo bench with -- --save-baseline for regression tracking.

CI Pipeline

  • Minimum: cargo fmt --check && cargo clippy -- -D warnings && cargo test.
  • Add cargo audit for vulnerability scanning.
  • Use cargo nextest for parallel test execution and better output.
  • Enable -Z randomize-layout in nightly CI to catch layout-dependent code.

© softspark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in app/skills/rust-rules of softspark/ai-toolkit.

Open the folder on GitHubat commit d64db2b

Compare with similar skills

Rust Rules next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rust Rules compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rust Rules this skillsoftspark/ai-toolkit179—~3.1kAutomated safety check: PassApache-2.0
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0
Firecrawl Page Scrape Integrationfirecrawl/firecrawl190k1 repos~944Automated safety check: PassISC
Migrate Core Code to Submodulestinyhumansai/openhuman42k—~2.6kAutomated safety check: PassGPL-3.0
Rust TDD Workflowrtk-ai/rtk83k—~753Automated safety check: NotesApache-2.0
Rust Best Practicesfarm-fe/farm5.6k3 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • Adds Firecrawl's /scrape endpoint to application code to pull markdown, HTML, links, screenshots or structured data from a single known URL.

    190k GitHub starsUsed in 1 repo~944 tokens
    Data & AnalyticsAuto-check passed
  • Migrate Core Code to Submodules

    tinyhumansai/openhuman

    Plans and carries out moving non-host-specific code and its tests from the OpenHuman core into vendored tiny submodule libraries, then releases the submodule and re-pins the host.

    42k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Enforces red-green-refactor for Rust work, with idiomatic test patterns, a naming convention and a pre-commit gate of cargo fmt, clippy and test.

    83k GitHub stars~753 tokensUpdated today
    Testing & QAAuto-check: notes
  • Guide for writing idiomatic Rust code based on Apollo GraphQL's best practices handbook.

    5.6k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Decides whether an OpenLogi device problem on macOS is a privacy-permission (TCC) problem, using agent log lines, and says which identity needs which grant.

    23k GitHub stars~2.5k tokensUpdated 4 days ago
    DevelopmentAuto-check: notes

More from softspark/ai-toolkit

All 112 skills in this repo
  • Prepare Test Env

    softspark/ai-toolkit

    Prepare or verify a project QA environment with source identity, readiness, browser access, evidence paths and owned cleanup.

    179 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check: notes
  • A11y Validate

    softspark/ai-toolkit

    Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.8k tokensUpdated yesterday
    Auto-check: notes
  • Analyze

    softspark/ai-toolkit

    Analyzes code quality, complexity, patterns across codebase.

    179 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Autonomous Dev

    softspark/ai-toolkit

    Drives a brief, specification, issue or existing PR through implementation, review, tests and QA to a ready PR.

    179 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check: notes
  • Brand Voice

    softspark/ai-toolkit

    Direct technical voice for docs, README, user-facing text. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • CI

    softspark/ai-toolkit

    Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).

    179 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check: notes

Works with

Questions about Rust Rules

What does Rust Rules do?

Rust coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit. Rust Rules is an agent skill from softspark/ai-toolkit. Rust coding rules: style, patterns, security, testing.

How do I install Rust Rules in Claude Code?

Run `npx skills add softspark/ai-toolkit --skill rust-rules -a claude-code`. Or copy the skill folder (app/skills/rust-rules in softspark/ai-toolkit) into .claude/skills/rust-rules in your project. Claude Code loads it when a task matches its description.

How do I install Rust Rules in Codex?

Run `npx skills add softspark/ai-toolkit --skill rust-rules -a codex`. Or copy the skill folder (app/skills/rust-rules in softspark/ai-toolkit) into .agents/skills/rust-rules in your project. Codex loads it when a task matches its description.

Can I use Rust Rules in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add softspark/ai-toolkit --skill rust-rules -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rust-rules, .gemini/skills/rust-rules, .github/skills/rust-rules and .opencode/skills/rust-rules in your project.

What does Rust Rules need to run?

Going by SKILL.md and its folder, Rust Rules needs the command-line tools its instructions call (cargo). Our summary lists: Docker. Its frontmatter pre-approves these tools: Read.

Does Rust Rules access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Rust Rules safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rust Rules use?

Rust Rules is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rust Rules use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rust Rules?

Skills that share tags, products or a category with Rust Rules: Update V8 Version (openinterpreter/openinterpreter, 69k stars), Firecrawl Page Scrape Integration (firecrawl/firecrawl, 190k stars), Migrate Core Code to Submodules (tinyhumansai/openhuman, 42k stars) and Rust TDD Workflow (rtk-ai/rtk, 83k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rust Rules?

softspark (a GitHub user) maintains it in softspark/ai-toolkit, which has 179 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on October 7, 2026.

Source: softspark/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.