Agent skill

Rust Hygiene Audit

by tsz-org in tsz-org/tsz

Run a deep DRY + code-hygiene audit of the Rust workspace and turn the findings into verified, deduplicated, hierarchical GitHub tech-debt issues.

Apache-2.0Auto-check passedDevelopment

Install Rust Hygiene Audit

skills CLI
$ npx skills add tsz-org/tsz --skill rust-hygiene-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tsz-org/tsz rust-hygiene-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tsz-org/tsz.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/rust-hygiene-audit .claude/skills/rust-hygiene-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rust-hygiene-audit
GitHub stars
577
Token cost
~1.5k tokens
SKILL.md length
637 words
Files
7 (incl. scripts, references)
Skills in repo
12
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run a deep DRY + code-hygiene audit of the Rust workspace and turn the findings into verified, deduplicated, hierarchical GitHub tech-debt issues.

  • Works in 4 steps: Measure the Clippy posture (prevention… → Fan out the audit (find + verify) → Create the issue hierarchy → …
  • Asks to find duplication
  • SKILL.md covers The four phases, What good output looks like and What to avoid
  • Runs Python scripts from its folder; calls python3, gh and cargo

What it does

Rust Hygiene Audit is an agent skill from tsz-org/tsz. Run a deep DRY + code-hygiene audit of the Rust workspace and turn the findings into verified, deduplicated, hierarchical GitHub tech-debt issues. Use this whenever the user asks to find duplication, code smells, derive/boilerplate bloat, oversized files, or "tech debt"; to tighten the Clippy/lint posture; to mass-file or triage hygiene issues; or to assign Priority/Effort issue Fields across the backlog. Reach for it even when the user only says "clean up the codebase", "find DRY violations", "what should we…

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/github-fields-api.md`, `references/issue-template.md` and `references/lint-triage.md`).

It sits in Development, covering Refactoring, Technical debt and Linting and formatting. It works with Rust and GitHub. The repository describes itself as: An experiment in fully hand-off software engineering: A performance-first TypeScript checker. The licence is Apache-2.0.

When your agent uses it

  • Asks to find duplication
  • Derive/boilerplate bloat
  • Oversized files
  • Tighten the Clippy/lint posture

Example prompts

  • “tech debt”
  • “clean up the codebase”
  • “find DRY violations”
  • “/rust-hygiene-audit”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Measure the Clippy posture (prevention evidence)
  2. Fan out the audit (find + verify)
  3. Create the issue hierarchy
  4. Assign Priority / Effort Fields

What it can do on your machine

Read from SKILL.md and the folder at commit 153b25a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • gh
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rust Hygiene Audit loads about 1.5k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 164 tokens; SKILL.md has 637 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~164
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from tsz-org/tsz at commit 153b25a, republished under its Apache-2.0 licence (© tsz-org). 637 words, ~1,455 tokens.

Download SKILL.mdSave it as .claude/skills/rust-hygiene-audit/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
rust-hygiene-audit
description
Run a deep DRY + code-hygiene audit of the Rust workspace and turn the findings into verified, deduplicated, hierarchical GitHub tech-debt issues. Use this whenever the user asks to find duplication, code smells, derive/boilerplate bloat, oversized files, or "tech debt"; to tighten the Clippy/lint posture; to mass-file or triage hygiene issues; or to assign Priority/Effort issue Fields across the backlog. Reach for it even when the user only says "clean up the codebase", "find DRY violations", "what should we refactor", or "make issues for the cruft" — it is the right tool for evidence-backed, non-spammy hygiene issue creation.

Rust Hygiene Audit

Turn a fuzzy "clean up the codebase" request into a set of evidence-backed, deduplicated, parent/child GitHub issues — without flooding the tracker with smells. The guiding principle: every issue must cite real file:line evidence that survived an adversarial check, and must not duplicate an open issue.

This skill is for hygiene/DRY/lint work, not behavior changes. It produces issues and field assignments; it does not edit compiler logic. Keep parity work (tsc matching) in the owner skills.

The four phases

Run them in order. Phases 1–2 are analysis; 3–4 are writes — confirm scope with the user before mass-creating issues unless they already said "create them".

1. Measure the Clippy posture (prevention evidence)

The cheapest lever against future debt is a tighter lint floor, so quantify what the current floor lets through before proposing changes.

bash
python3 .agents/skills/rust-hygiene-audit/scripts/measure_clippy.py --worktree . --out /tmp/hygiene

This runs cargo clippy --workspace --lib -- -W clippy::pedantic -W clippy::nursery (no files touched), aggregates warnings per lint, and prints a promote vs defer triage. Read references/lint-triage.md for the rationale behind which lints are worth promoting in a compiler (numeric casts and must_use/doc pedantry are mostly intentional; idiom/ownership lints are high-signal). The count and triage become the body of the clippy-posture epic.

Disk note: a cold workspace clippy build needs ~8–12GB. If low, reclaim merged worktree caches first (see tsz-disk-cache-hygiene).

2. Fan out the audit (find + verify)

Drive the bundled workflow, which fans out per-crate DRY auditors and cross-cutting concern auditors, dedups against open issues, then adversarially verifies every candidate against the real source before authoring full issue bodies:

Workflow({ scriptPath: "scripts/agents/hygiene-audit-workflow.mjs" })

Before launching, snapshot the open issues the auditors dedup against:

bash
gh issue list -R <owner>/<repo> --state open --limit 300 --json number,title,labels > /tmp/hygiene/open-issues.json

The workflow returns { epics, children, dropped, stats }. children carry verified evidence and full body_md. dropped records findings that overlapped an existing issue — surface these so the user sees the dedup worked. Tune the auditor list (crates + concerns) in the workflow's CRATES/CONCERNS arrays for the target repo. The verify stage defaults to reject on weak evidence — that is the anti-spam gate; do not weaken it.

3. Create the issue hierarchy

Author epic body_md (summarize the theme + bake in the measured clippy data for the lint epic), then create epics and children with native sub-issue links:

bash
python3 .agents/skills/rust-hygiene-audit/scripts/create_issues.py \
  --repo <owner>/<repo> --specs /tmp/hygiene/result.json --apply

Match the repo's existing issue conventions. For tsz that is the techdebt(scope): title + the template in references/issue-template.md (## Summary with a structural rule → ## Evidence → ## Why it matters → ## Proposed fix (sized S/M/L) → ## Risks / coordination). The script writes a ## Child issue map into each epic as a durable fallback even when native linking succeeds.

Show full SKILL.md (229 more words)Show less
4. Assign Priority / Effort Fields
bash
python3 .agents/skills/rust-hygiene-audit/scripts/assign_fields.py \
  --repo <owner>/<repo> --specs /tmp/hygiene/result.json --apply

Discovers the repo's Priority/Effort single-select issue Fields by name, then assigns by rule. Default priority ranking is correctness > speed > tech-debt (map to High/Medium/Low; reserve Urgent for urgent/panic labels). Effort comes from the audit size (S/M/L → Low/Medium/High) and epic-scale → the top level. See references/github-fields-api.md for the API gotchas — they are easy to get wrong:

  • Sub-issues: gh api -X POST .../issues/<parent>/sub_issues -F sub_issue_id=<db_id> — -F (integer) not -f (string); the id is the issue database id, not its number.
  • setIssueFieldValue works with repo scope, but createIssueField / updateIssueField (changing a field's options) need admin:org. If you must add an option and lack the scope, ask the user to add it in the UI or fall back to the existing options.

What good output looks like

  • Issues cite ≥2 real sites for any DRY claim and name the structural rule.
  • Duplication that already drifted into a parity bug is flagged as such — that is the highest-value finding, not a cosmetic one.
  • Nothing duplicates an open issue (the dropped list proves the check ran).
  • A small number of strong epics, each with actionable PR-sized children.

What to avoid

  • Smell-only issues with no file:line evidence.
  • Mass-creating before the user has agreed to issue creation.
  • Architecture-boundary refactors that overlap an active campaign — check open issues first and let the auditors dedup.
  • Fixture-name / rendered-output string checks in any proposed fix (repo anti-hardcoding gate).

© tsz-org, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in .agents/skills/rust-hygiene-audit of tsz-org/tsz.

  • SKILL.md
  • references/github-fields-api.md
  • references/issue-template.md
  • references/lint-triage.md
  • scripts/assign_fields.py
  • scripts/create_issues.py
  • scripts/measure_clippy.py

Open the folder on GitHubat commit 153b25a

Compare with similar skills

Rust Hygiene Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rust Hygiene Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rust Hygiene Audit this skilltsz-org/tsz577—~1.5kAutomated safety check: PassApache-2.0
Rust Best Practicesfarm-fe/farm5.6k3 repos~1.1kAutomated safety check: PassMIT
Unslop CodeJCarterJohnson/vibecoded-design-tells513—~2.5kAutomated safety check: PassCustom licence
Code Quality Gatefengshao1227/ccg-workflow5.9k—~593Automated safety check: NotesMIT
Warp Feature Flag Removalwarpdotdev/warp65k1 repos~1.1kAutomated safety check: PassAGPL-3.0
Code RefinerMathews-Tom/armory328—~3.1kAutomated safety check: PassMIT

Similar skills

  • Guide for writing idiomatic Rust code based on Apollo GraphQL's best practices handbook.

    5.6k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Unslop Code

    JCarterJohnson/vibecoded-design-tells

    Strips the tells that make source code read as AI-generated and forces code that fits the project instead of the model's default average.

    513 GitHub stars~2.5k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Code Quality Gate

    fengshao1227/ccg-workflow

    Scans code for complexity, long functions, duplicated blocks, naming problems and code smells with a Node script, then reports and suggests refactors.

    5.9k GitHub stars~593 tokensUpdated 24 days ago
    DevelopmentAuto-check: notes
  • Removes a Warp feature flag once it is stable for everyone, deleting the definition, the Cargo entries and every conditional check.

    65k GitHub starsUsed in 1 repo~1.1k tokens
    DevelopmentAuto-check passed
  • Code Refiner

    Mathews-Tom/armory

    Deep code simplification and refactoring preserving behavior across Python, Go, TypeScript, Rust.

    328 GitHub stars~3.1k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Cosmwasm Contract

    axone-protocol/contracts

    Axone contract structure and Abstract SDK patterns. An agent skill from axone-protocol/contracts.

    123 GitHub stars~1.2k tokensUpdated 14 days ago
    DevelopmentAuto-check passed

More from tsz-org/tsz

All 12 skills in this repo
  • Audit TSZ repo iteration speed and quality. An agent skill from tsz-org/tsz.

    577 GitHub stars~557 tokensUpdated 1 mo ago
    Auto-check passed
  • A skill your agent uses when planning, implementing, reviewing, or interpreting TSZ performance work, including benchmark regressions, cache/residency changes, timing claims, perf counters, hotspot…

    577 GitHub stars~746 tokensUpdated 1 mo ago
    Auto-check passed
  • Create, refresh, and publish TSZ pull requests with correct body and state.

    577 GitHub stars~555 tokensUpdated 1 mo ago
    Auto-check passed
  • Start TSZ work safely in a crowded multi-agent checkout. An agent skill from tsz-org/tsz.

    577 GitHub stars~518 tokensUpdated 1 mo ago
    Auto-check passed
  • Tsz Architecture

    tsz-org/tsz

    Preserve TSZ architecture boundaries while changing checker, solver, binder, emitter, LSP, WASM, or CLI code.

    577 GitHub stars~547 tokensUpdated 1 mo ago
    Auto-check passed
  • Tsz CI PR

    tsz-org/tsz

    Drive TSZ GitHub PRs through review, CI, and the merge queue.

    577 GitHub stars~633 tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Rust Hygiene Audit

What does Rust Hygiene Audit do?

Run a deep DRY + code-hygiene audit of the Rust workspace and turn the findings into verified, deduplicated, hierarchical GitHub tech-debt issues. Rust Hygiene Audit is an agent skill from tsz-org/tsz. Run a deep DRY + code-hygiene audit of the Rust workspace and turn the findings into verified, deduplicated, hierarchical GitHub tech-debt issues.

When should I use Rust Hygiene Audit?

Rust Hygiene Audit fits situations like: asks to find duplication; derive/boilerplate bloat; oversized files; tighten the Clippy/lint posture.

How do I install Rust Hygiene Audit in Claude Code?

Run `npx skills add tsz-org/tsz --skill rust-hygiene-audit -a claude-code`. Or copy the skill folder (.agents/skills/rust-hygiene-audit in tsz-org/tsz) into .claude/skills/rust-hygiene-audit in your project. Claude Code loads it when a task matches its description.

How do I install Rust Hygiene Audit in Codex?

Run `npx skills add tsz-org/tsz --skill rust-hygiene-audit -a codex`. Or copy the skill folder (.agents/skills/rust-hygiene-audit in tsz-org/tsz) into .agents/skills/rust-hygiene-audit in your project. Codex loads it when a task matches its description.

Can I use Rust Hygiene Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tsz-org/tsz --skill rust-hygiene-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rust-hygiene-audit, .gemini/skills/rust-hygiene-audit, .github/skills/rust-hygiene-audit and .opencode/skills/rust-hygiene-audit in your project.

What does Rust Hygiene Audit need to run?

Going by SKILL.md and its folder, Rust Hygiene Audit needs Python for the scripts in its folder and the command-line tools its instructions call (python3, gh and cargo). Our summary lists: Python 3.

Does Rust Hygiene Audit access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Rust Hygiene Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Rust Hygiene Audit use?

Rust Hygiene Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rust Hygiene Audit use?

About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.

What are the alternatives to Rust Hygiene Audit?

Skills that share tags, products or a category with Rust Hygiene Audit: Rust Best Practices (farm-fe/farm, 5.6k stars), Unslop Code (JCarterJohnson/vibecoded-design-tells, 513 stars), Code Quality Gate (fengshao1227/ccg-workflow, 5.9k stars) and Warp Feature Flag Removal (warpdotdev/warp, 65k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rust Hygiene Audit?

tsz-org (a GitHub organization) maintains it in tsz-org/tsz, which has 577 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on September 9, 2026.

Source: tsz-org/tsz on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.