Agent skill

Binding Audit

by xberg-io in xberg-io/alef

Audit bindings for coverage gaps — verify every public Rust item is exposed across all generated language bindings.

MITAuto-check passedTesting & QA

Install Binding Audit

skills CLI
$ npx skills add xberg-io/alef --skill binding-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install xberg-io/alef binding-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/xberg-io/alef.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.ai-rulez/skills/binding-audit .claude/skills/binding-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
binding-audit
GitHub stars
100
Token cost
~2.9k tokens
SKILL.md length
990 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Audit bindings for coverage gaps — verify every public Rust item is exposed across all generated language bindings.

  • Works in 7 steps: Gather config → Scan source for attributes → Enumerate public items → …
  • Tasks that involve Test coverage
  • SKILL.md covers When to apply, Hard rules, Procedure and Anti-patterns, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Binding Audit is an agent skill from xberg-io/alef. Audit bindings for coverage gaps — verify every public Rust item is exposed across all generated language bindings. Use this skill any time you need to check that a function/type is present in every target language, audit intentional exclusions, or investigate missing bindings in one or more languages. Covers the full audit flow: config review, attribute scan, item enumeration, cross-binding diff, gap reporting, and triage (alef vs Alef-owned workflow/action vs consumer config).

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering Test coverage. It works with Rust. The repository describes itself as: Generate fully-typed, lint-clean language bindings for Rust libraries across 16 languages. The licence is MIT.

When your agent uses it

  • Tasks that involve Test coverage

Example prompts

  • “/binding-audit”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Gather config
  2. Scan source for attributes
  3. Enumerate public items
  4. Walk each generated binding
  5. Diff and report gaps
  6. Triage
  7. Document and commit

What it can do on your machine

Read from SKILL.md and the folder at commit fc04366. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Binding Audit loads about 2.9k tokens when it runs. Until then it costs about 124 tokens; SKILL.md has 990 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~124
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from xberg-io/alef at commit fc04366, republished under its MIT licence (© xberg-io). 990 words, ~2,881 tokens.

Download SKILL.mdSave it as .claude/skills/binding-audit/SKILL.md (or your agent's skills folder).
name
binding-audit
description
Audit bindings for coverage gaps — verify every public Rust item is exposed across all generated language bindings. Use this skill any time you need to check that a function/type is present in every target language, audit intentional exclusions, or investigate missing bindings in one or more languages. Covers the full audit flow: config review, attribute scan, item enumeration, cross-binding diff, gap reporting, and triage (alef vs Alef-owned workflow/action vs consumer config).
license
MIT

Binding Audit

Verify that every public Rust item has a corresponding binding in all target languages. Identify coverage gaps and triage them upstream.

When to apply

  • User asks to audit bindings or check coverage
  • A function or type is missing from one or more generated bindings
  • Preparing to release — confirm all public items are bound
  • Investigating a "why isn't X available in language Y?" question
  • After adding a new public Rust item — verify it appears everywhere

Hard rules

  1. No guessing about intentional removals. The real surfaces: [crates.exclude] (types/functions/methods/fields) inside a [[crates]] entry, crate-wide and unioned across every language; per-language exclude_types / exclude_functions directly on each [crates.<lang>] table; [workspace.opaque_types], workspace-level only, which remaps a type rather than excluding it. At the attribute level, the extractor accepts three spellings — #[alef::skip], #[alef(skip)], and either nested in #[cfg_attr(...)] (the form in common use) — plus #[doc(hidden)]; #[alef::exclude] and #[alef::opaque] do not exist. Only flag items not covered by these.
  2. Every gap is triaged. Never report a missing binding without identifying the root cause (alef codegen bug, action script error, or config oversight).
  3. All findings update CHANGELOG.md — each upstream fix gets an [Unreleased] entry.
  4. Commit SHAs and workflow URLs are recorded so consumer repos can pin the exact fix.

Procedure

0. Gather config

From the source repo (the Rust library being bound, not alef itself):

bash
# Open alef.toml and record:
# - [languages] enabled backends
# - [e2e] enabled language suites
# - [crates.exclude] items (types/functions/methods/fields) inside a [[crates]]
#   entry — crate-wide, unioned across every language
# - Per-language exclude_types / exclude_functions directly on each
#   [crates.<lang>] table (e.g. [crates.python].exclude_types,
#   [crates.ffi].exclude_functions) — unioned with the crate-wide list for
#   that language only
# - [workspace.opaque_types] — workspace-level only, no per-crate override.
#   This is a type-REMAPPING declaration (Rust type name -> external path
#   alef can't extract), not an exclusion list.
grep -E '^\[' alef.toml | head -20

There is no [crates.skipped], no bare exclude_types key, and no per-crate override under [workspace.crates."<name>"] — [[crates]] is a plain array (WorkspaceConfig has no crates field; RawCrateConfig has no skipped field), so there is no name-keyed map to override into. src/docs/language_pages/excludes.rs::language_excludes is the canonical per-language union of the config surfaces above.

Record intentional removals. Anything listed here is not a gap.

The current backend surface is Python/PyO3, TypeScript/Node/NAPI, Ruby/Magnus, PHP, Go/cgo, Java, JNI, C#, Elixir/Rustler, WASM, Dart, Kotlin, Kotlin Android, Swift, Zig, C FFI, R/extendr when enabled, and Gleam when generated. Do not invent an expected package for a language that is not enabled in alef.toml.

1. Scan source for attributes

Grep the source Rust crate for intentional removal markers. The extractor accepts three spellings of the skip attribute, plus #[doc(hidden)] (src/extract/extractor/helpers/attributes.rs::extract_binding_exclusion_reason, lines 304-333): #[alef::skip], the list form #[alef(skip)], and either of those nested in #[cfg_attr(...)] (e.g. #[cfg_attr(alef, alef(skip))] — the form in common use; the extractor's own reason string for it is literally "alef(skip)", not "alef::skip"). A grep for only #[alef::skip] misses the cfg_attr form and will manufacture false gaps. #[alef::exclude] and #[alef::opaque] do not exist in alef — do not grep for or expect them.

bash
# Find all skip-attribute spellings (bare, list-form, cfg_attr-nested) and #[doc(hidden)]
grep -rEln '#\[(cfg_attr\([^)]*,\s*)?(alef::skip|alef\(skip\))\]?|#\[doc\(hidden\)\]' --include='*.rs' .

# For each file found, inspect the context:
grep -B2 -A2 -E '#\[(cfg_attr\([^)]*,\s*)?(alef::skip|alef\(skip\))\]?|#\[doc\(hidden\)\]' <file.rs>

Record the annotated items — these are intentional and do not flag as gaps.

Both attributes set the binding_excluded flag on the item's IR node at extraction time. That flag is honored independently by every downstream consumer — each backend, src/core/jni.rs, src/core/validation/readiness.rs, docs generation, etc. all filter on it separately; there is no single central enforcement point. Critically, language_excludes (step 0) never consults binding_excluded; it only reads the config surfaces. So a #[alef::skip]'d (or #[doc(hidden)]) item is correctly invisible in every generated binding, but tooling that treats language_excludes's answer as the complete set of intentional removals will misclassify that skipped item as a real gap, because it never shows up in language_excludes's output at all (live defect: alef-task #329).

2. Enumerate public items

From the source Rust crate, list all public items. Adjust the path glob to the source repo's layout (src/, crates/*/src/, or a workspace path):

bash
# Functions:
grep -rE "^pub fn " src --include="*.rs" | wc -l

# Types (structs, enums):
grep -rE "^pub struct|^pub enum|^pub trait" src --include="*.rs"

# Methods (on pub types):
grep -rE "impl.*pub fn" src --include="*.rs"

Build a reference set: {module::ItemName} for each public item, excluding those from step 1.

3. Walk each generated binding

For each enabled language under packages/<lang>/, crates/*-<binding>/, or language-native output dirs:

bash
# Python (generated stubs):
ls -la packages/python/*.pyi
grep -E "^def |^class " packages/python/*.pyi

# TypeScript / Node (generated .d.ts or package entrypoint):
grep -R -E "export (function|class|type|const) " packages/typescript crates/*-node --include="*.ts" --include="*.d.ts"

# Ruby:
grep -R -E "^  def |^    def " packages/ruby crates/*-rb --include="*.rb"

# PHP:
grep -R -E "function |class " packages/php --include="*.php"

# Go (FFI):
grep -R -E "^func " packages/go --include="*.go"

# Java / JNI:
grep -R -E "^\s+(public static|public) (native )?" packages/java packages/jni --include="*.java"

# C#:
grep -R -E "^\s+public (static|extern|class|struct)" packages/csharp --include="*.cs"

# Elixir:
grep -R -E "def |defmodule " packages/elixir --include="*.ex"

# WASM:
grep -R -E "export (function|class|type|const) " packages/wasm --include="*.ts" --include="*.d.ts"

# Dart:
grep -R -E "class |^[a-zA-Z_][a-zA-Z0-9_]*\\(" packages/dart --include="*.dart"

# Kotlin / Kotlin Android:
grep -R -E "fun |class " packages/kotlin packages/kotlin-android --include="*.kt"

# Swift:
grep -R -E "public (func|class|struct|enum)" packages/swift --include="*.swift"

# Zig:
grep -R -E "pub (fn|const|const.*= struct|const.*= enum)" packages/zig --include="*.zig"

# C FFI headers:
grep -R -E "^[a-zA-Z_][a-zA-Z0-9_ *]+ [a-zA-Z_][a-zA-Z0-9_]+\\(" packages/c crates/*-ffi --include="*.h"

# R / extendr:
grep -R -E "^[a-zA-Z.][a-zA-Z0-9_.]* <- function|#' @export" packages/r --include="*.R"

# Gleam:
grep -R -E "^pub (fn|type)" packages/gleam --include="*.gleam"

For each language, build a set of exported items.

Show full SKILL.md (391 more words)Show less
4. Diff and report gaps

For each public Rust item, check presence across all binding sets:

bash
# Pseudo-algorithm:
all_langs = [
    "python", "typescript", "ruby", "php", "go", "java", "jni", "csharp", "elixir", "wasm",
    "dart", "kotlin", "kotlin_android", "swift", "zig", "c_ffi", "r", "gleam",
]
enabled_langs = [lang for lang in all_langs if lang is enabled in alef.toml and output exists]

for each item in reference_set:
    langs_present = [lang for lang in enabled_langs if item in binding_sets[lang]]
    if len(langs_present) < len(enabled_langs):
        report(item, langs_present, missing_from=enabled_langs - langs_present)

Output: gap report with columns:

  • Rust item (function/type name)
  • Present in (comma-separated languages)
  • Missing from (comma-separated languages)
  • Intentional? (yes if config or attribute covers it, no otherwise)
5. Triage

For each non-intentional gap:

  • Codegen issue: Does the item appear in the source Rust but fail to generate in all backends? Root cause likely in src/codegen/ or a specific src/backends/<lang>/. Fix in ../alef repo.
  • Alef-owned workflow/action issue: Does an Alef-maintained scaffold or publish workflow have a bug that skips a language? Fix the owning workflow/action repository and retag only the documented action tags for that repository.
  • Consumer config issue: Is the gap listed in the consuming repo's alef.toml under [crates.exclude] or a per-language exclude_types / exclude_functions on [crates.<lang>]? That's intentional — no action needed upstream.
  • Package layout issue: Does generated code exist but not in the expected package path? Fix the backend output path or package manifest wiring, not the Rust source item.
  • Unsupported type issue: Does the Rust item use a type the backend cannot express? Add explicit conversion, an opaque wrapper, or an intentional exclusion in config.
6. Document and commit

For each upstream fix:

  1. Update the source repo's CHANGELOG.md [Unreleased] section with the gap and the fix.
  2. Commit the fix (codegen or action change) with a conventional commit message.
  3. If the fix is in an Alef-owned workflow/action repository, follow that repository's documented retag procedure.
  4. For alef fixes, follow the normal release-procedure skill.
  5. Record the commit SHA and workflow URL in consumer issues so they can pin the fix.

Anti-patterns

  • Reporting a gap without checking alef.toml and all three skip-attribute spellings (including the cfg_attr-nested form) / #[doc(hidden)] first.
  • Assuming a missing binding is a codegen bug without checking the consuming repo's config.
  • Closing an audit issue without confirming every gap is triaged and documented.
  • Fixing a codegen bug without adding a test under tests/ or a fixture under src/e2e/ to prevent regression.

Quick reference

StepCommandOutput
Configgrep -E '^\[' alef.tomlIntentional exclusions ([crates.exclude], per-language exclude_types/exclude_functions, [workspace.opaque_types])
Attributesgrep -rEln '#\[(cfg_attr\([^)]*,\s*)?(alef::skip|alef\(skip\))\]?|#\[doc\(hidden\)\]' --include='*.rs' .Annotated items
Public itemsgrep -rE "^pub fn|^pub struct" srcReference set
Bindingsgrep -R -E "export|def|func|public|fun " packages cratesPer-language sets
GapsDiff reference set vs per-language setsGap report
TriageRoot-cause analysis (config vs codegen vs action)Fix location

© xberg-io, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .ai-rulez/skills/binding-audit of xberg-io/alef.

Open the folder on GitHubat commit fc04366

Compare with similar skills

Binding Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Binding Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Binding Audit this skillxberg-io/alef100—~2.9kAutomated safety check: PassMIT
Find Untested Sourcesdotnet/skills5.6k1 repos~3.3kAutomated safety check: PassMIT
Libreqos Review Subagents WorkflowLibreQoE/LibreQoS719—~1.2kAutomated safety check: PassGPL-2.0
Reviewwebern/cargo-readme385—~2kAutomated safety check: NotesApache-2.0
Supercovsupercorp-ai/supercov1511 repos~415Automated safety check: PassMIT
Reviewapollographql/apollo-mcp-server313—~2.9kAutomated safety check: PassMIT

Similar skills

  • Official

    Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.

    5.6k GitHub starsUsed in 1 repo~3.3k tokens
    Testing & QAAuto-check passed
  • Project workflow for invoking the local review sub-agents Thomas, Helen, Beck, Jonas, The Reaper, and Heckler during LibreQoS coding sessions.

    719 GitHub stars~1.2k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Review

    webern/cargo-readme

    Reviews a GitHub pull request for correctness, architecture, security, backward compatibility, and test coverage.

    385 GitHub stars~2k tokensUpdated today
    Testing & QAAuto-check: notes
  • Supercov

    supercorp-ai/supercov

    Measures test coverage and code quality in a repository with the supercov CLI, and turns what it finds into small, focused tests or fixes.

    151 GitHub starsUsed in 1 repo~415 tokens
    Testing & QAAuto-check passed
  • Review

    apollographql/apollo-mcp-server

    Review a GitHub pull request for a Rust codebase. An agent skill from apollographql/apollo-mcp-server.

    313 GitHub stars~2.9k tokensUpdated 2 days ago
    Testing & QAAuto-check passed
  • Supercov Security

    supercorp-ai/supercov

    Scans a repository's source for security vulnerabilities with the supercov CLI, pointing to the line of each finding and mapping it to CWE classes.

    151 GitHub starsUsed in 1 repo~236 tokens
    Testing & QAAuto-check passed

More from xberg-io/alef

  • Alef

    xberg-io/alef

    Use Alef correctly for Rust-to-polyglot binding generation. An agent skill from xberg-io/alef.

    100 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Jinja Codegen

    xberg-io/alef

    Mechanics of alef's Minijinja template system: which templateenv module to call, how to register a template, inline-template rules, and engine settings.

    100 GitHub stars~735 tokensUpdated today
    Auto-check passed
  • Regen Audit

    xberg-io/alef

    Treat running alef generate/alef all/alef verify in a consumer repo as an audit, not a build step.

    100 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Release Procedure

    xberg-io/alef

    Cut, tag, and publish an alef release end-to-end. An agent skill from xberg-io/alef.

    100 GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Alef's dominant defect shape: two components read the same config or IR and act on it differently.

    100 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Binding Audit

What does Binding Audit do?

Audit bindings for coverage gaps — verify every public Rust item is exposed across all generated language bindings. Binding Audit is an agent skill from xberg-io/alef. Audit bindings for coverage gaps — verify every public Rust item is exposed across all generated language bindings.

When should I use Binding Audit?

Binding Audit fits situations like: tasks that involve Test coverage.

How do I install Binding Audit in Claude Code?

Run `npx skills add xberg-io/alef --skill binding-audit -a claude-code`. Or copy the skill folder (.ai-rulez/skills/binding-audit in xberg-io/alef) into .claude/skills/binding-audit in your project. Claude Code loads it when a task matches its description.

How do I install Binding Audit in Codex?

Run `npx skills add xberg-io/alef --skill binding-audit -a codex`. Or copy the skill folder (.ai-rulez/skills/binding-audit in xberg-io/alef) into .agents/skills/binding-audit in your project. Codex loads it when a task matches its description.

Can I use Binding Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xberg-io/alef --skill binding-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/binding-audit, .gemini/skills/binding-audit, .github/skills/binding-audit and .opencode/skills/binding-audit in your project.

What does Binding Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Binding Audit is instructions for the agent only. Our summary lists: Python 3.

Does Binding Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Binding Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Binding Audit use?

Binding Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Binding Audit use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Binding Audit?

Skills that share tags, products or a category with Binding Audit: Find Untested Sources (dotnet/skills, 5.6k stars), Libreqos Review Subagents Workflow (LibreQoE/LibreQoS, 719 stars), Review (webern/cargo-readme, 385 stars) and Supercov (supercorp-ai/supercov, 151 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Binding Audit?

xberg-io (a GitHub organization) maintains it in xberg-io/alef, which has 100 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 9, 2026.

Source: xberg-io/alef on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.