Agent skill

Rust Crate CI

by ZaxbyHub in ZaxbyHub/opencode-swarm

Load before editing any Rust crate in this repo (currently runners/swarm-sandbox-runner).

MITAuto-check passed

Install Rust Crate CI

skills CLI
$ npx skills add ZaxbyHub/opencode-swarm --skill rust-crate-ci -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ZaxbyHub/opencode-swarm rust-crate-ci --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/rust-crate-ci .claude/skills/rust-crate-ci && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rust-crate-ci
GitHub stars
494
Token cost
~1.7k tokens
SKILL.md length
699 words
Files
1
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Load before editing any Rust crate in this repo (currently runners/swarm-sandbox-runner).

  • SKILL.md covers Mandatory local gate (run in…, How rustfmt makes decisions, Common clippy errors in this… and Windows path normalization…, plus 2 more sections
  • Calls cargo

What it does

Rust Crate CI is an agent skill from ZaxbyHub/opencode-swarm. Load before editing any Rust crate in this repo (currently runners/swarm-sandbox-runner). Covers the mandatory local validation gate, common rustfmt/clippy pitfalls, and Windows-specific Rust correctness patterns that CI enforces but are hard to catch locally without a Windows toolchain.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Rust. The repository describes itself as: Architect-centric agentic swarm plugin for OpenCode. Hub-and-spoke orchestration with SME consultation, code generation, and QA review. The licence is MIT.

Example prompts

  • “/rust-crate-ci”

What it can do on your machine

Read from SKILL.md and the folder at commit b63a4bd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rust Crate CI loads about 1.7k tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 699 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ZaxbyHub/opencode-swarm at commit b63a4bd, republished under its MIT licence (© ZaxbyHub). 699 words, ~1,723 tokens.

Download SKILL.mdSave it as .claude/skills/rust-crate-ci/SKILL.md (or your agent's skills folder).
name
rust-crate-ci
description
Load before editing any Rust crate in this repo (currently runners/swarm-sandbox-runner). Covers the mandatory local validation gate, common rustfmt/clippy pitfalls, and Windows-specific Rust correctness patterns that CI enforces but are hard to catch locally without a Windows toolchain.
audience
swarm-plugin
effort
low

Rust Crate CI Guide

This repo contains a Rust crate at runners/swarm-sandbox-runner/. The CI job that validates it is rust-sandbox-runner (runs on windows-latest). This guide prevents the most common failure modes before they reach CI.

Mandatory local gate (run in order before pushing)

powershell
cd runners/swarm-sandbox-runner

# 1. Format check — CI fails here first; clippy will not run if this fails
cargo fmt --check

# 2. Clippy — -D warnings makes all warnings hard errors; --all-targets matches CI,
#    which also lints tests, examples, and benches (ci.yml rust-sandbox-runner job)
cargo clippy --all-targets -- -D warnings

# 3. Tests — --all-targets matches CI; Windows-specific tests are gated with #[cfg(windows)]
cargo test --all-targets

# 4. Release build — confirms the binary compiles with optimizations
cargo build --release

Run them in this exact order. If cargo fmt --check fails, fix formatting first — clippy errors may be masked until fmt passes.

If cargo is not in PATH locally (e.g. you are on a machine without Rust installed), push to a draft PR and let CI run the checks. Read the CI log carefully; do not guess at what failed.

How rustfmt makes decisions

rustfmt (current stable — rust-toolchain.toml floats on channel = "stable") applies line-length thresholds per syntax item, not per file or per block. Two patterns that look equivalent locally can format differently:

Long format! macros: If the total length of format!("...", arg) exceeds the line limit, rustfmt splits it. If it fits on one line, rustfmt collapses it.

rust
// rustfmt will COLLAPSE this to one line if it fits:
return Err(RunnerError::PolicyViolation {
    reason: format!(
        "cwd resolves outside allowed roots (symlink egress): {canonical_str}"
    ),
});

// rustfmt will SPLIT this if it exceeds the limit:
events::emit(&events::denial_event("deny_symlink_egress", Some(canonical_str)));
// becomes:
events::emit(&events::denial_event(
    "deny_symlink_egress",
    Some(canonical_str),
));

Rule of thumb: After editing, always run cargo fmt (not --check) locally to apply rustfmt's opinion, then read the diff before committing. Do not hand-format and assume rustfmt agrees.

Common clippy errors in this codebase

windows-rs 0.58 API changes: Several Win32 APIs changed signatures between windows crate versions. The Cargo.toml pins the version; do not bump it without checking the full API diff.

HANDLE is not Send + Sync: Raw HANDLE values cannot be sent across threads. Wrap them in a newtype with unsafe impl Send and unsafe impl Sync, or use OwnedHandle from std::os::windows::io. The kill-callback pattern in temp_watcher.rs uses raw isize (handle as integer) to sidestep this.

Unused imports: #[cfg(windows)] blocks frequently hide imports that are used only on Windows. On non-Windows builds, the import becomes dead code. Use #[cfg(windows)] on the use statement itself or accept the #[allow(unused_imports)] annotation for platform-conditional code.

struct default initialization: For Win32 structs like STARTUPINFOW, use a struct initializer with ..Default::default() rather than unsafe { std::mem::zeroed() } — clippy flags the latter when Default is available.

Windows path normalization (critical correctness patterns)

These bugs are invisible on Linux/macOS CI and will only appear on windows-latest.

std::fs::canonicalize always prepends \\?\

On Windows, canonicalize typically returns a verbatim extended-length path with the \\?\ prefix, but this is not guaranteed across all Windows configurations and path forms. Always use .strip_prefix with a fallback:

C:\foo\bar  →  \\?\C:\foo\bar  (typical)

If you compare a canonicalized path against a policy root stored without this prefix, the comparison silently fails. Strip the prefix before comparing, always with .unwrap_or:

rust
let lower = canonical.to_string_lossy().to_lowercase();
let canonical_str = lower.strip_prefix("\\\\?\\").unwrap_or(&lower);

Apply the same strip to both sides of any comparison.

Show full SKILL.md (279 more words)Show less
GitHub Actions CI uses 8.3 short names in %TEMP%

std::env::temp_dir() on GitHub Actions Windows runners returns a path like:

C:\Users\RUNNER~1\AppData\Local\Temp

But std::fs::canonicalize expands it to:

C:\Users\runneradmin\AppData\Local\Temp

If your code stores the temp_dir() path as a policy root and then canonicalizes the cwd, the comparison will fail because RUNNER~1 ≠ runneradmin.

Fix: Canonicalize both the policy root AND the cwd before comparing. Fall back to the raw value if the root does not exist on disk yet:

rust
let root_resolved = std::fs::canonicalize(root)
    .map(|p| p.to_string_lossy().to_lowercase())
    .unwrap_or_else(|_| root.to_lowercase());
let root_cmp = root_resolved
    .strip_prefix("\\\\?\\")
    .unwrap_or(&root_resolved)
    .to_owned();
WaitForSingleObject return value semantics

WAIT_TIMEOUT is 0x00000102u32, not a Rust Err. Check the return value explicitly before treating the child as having exited normally.

IPC contract stability

The exit codes in error.rs are frozen — do not renumber them. TypeScript callers in runner-client.ts depend on these values:

CodeMeaning
0Child exited zero (or non-zero child exit code passed through directly)
64Policy violation
65Temp quota exceeded
66Wall-clock timeout
67Launcher misconfiguration or policy parse error (invalid JSON from caller)
68OS API failure, I/O error, or JSON error
69Probe failed

The NDJSON event types on stderr (start, denial, quota_exceeded, exit) are also frozen. Adding new event types is safe; renaming or removing existing ones is a breaking IPC change.

Exit events are required on every termination path. Emit exit_event before returning from both the wall-clock timeout path and the temp-cap kill path, not only on the normal exit path. TypeScript consumers block waiting for an exit event.

CI workflow reference

The job is defined in .github/workflows/ci.yml as rust-sandbox-runner. It runs on windows-latest with the toolchain pinned in runners/swarm-sandbox-runner/rust-toolchain.toml. All third-party uses: actions are pinned to 40-character SHAs per the repo policy.

Steps in order: fmt check → clippy → tests → release build → probe smoke test.

© ZaxbyHub, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/rust-crate-ci of ZaxbyHub/opencode-swarm.

Open the folder on GitHubat commit b63a4bd

Compare with similar skills

Rust Crate CI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rust Crate CI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rust Crate CI this skillZaxbyHub/opencode-swarm494—~1.7kAutomated safety check: PassMIT
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0
Firecrawl Page Scrape Integrationfirecrawl/firecrawl190k1 repos~944Automated safety check: PassISC
Migrate Core Code to Submodulestinyhumansai/openhuman42k—~2.6kAutomated safety check: PassGPL-3.0
Rust TDD Workflowrtk-ai/rtk83k—~753Automated safety check: NotesApache-2.0
OpenLogi macOS Permissions TriageAprilNEA/OpenLogi23k—~2.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • Adds Firecrawl's /scrape endpoint to application code to pull markdown, HTML, links, screenshots or structured data from a single known URL.

    190k GitHub starsUsed in 1 repo~944 tokens
    Data & AnalyticsAuto-check passed
  • Migrate Core Code to Submodules

    tinyhumansai/openhuman

    Plans and carries out moving non-host-specific code and its tests from the OpenHuman core into vendored tiny submodule libraries, then releases the submodule and re-pins the host.

    42k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Enforces red-green-refactor for Rust work, with idiomatic test patterns, a naming convention and a pre-commit gate of cargo fmt, clippy and test.

    83k GitHub stars~753 tokensUpdated yesterday
    Testing & QAAuto-check: notes
  • Decides whether an OpenLogi device problem on macOS is a privacy-permission (TCC) problem, using agent log lines, and says which identity needs which grant.

    23k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Guide for writing idiomatic Rust code based on Apollo GraphQL's best practices handbook.

    5.6k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed

More from ZaxbyHub/opencode-swarm

All 91 skills in this repo
  • Codebase Review Swarm

    ZaxbyHub/opencode-swarm

    Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.

    496 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Issue Tracer

    ZaxbyHub/opencode-swarm

    Drives a bug report from validation and root-cause tracing through a critic-reviewed plan, an approved minimal fix and a PR-ready closure, never merging without recorded human approval.

    496 GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Commit and PR Publishing for Codex

    ZaxbyHub/opencode-swarm

    Codex adapter for opencode-swarm that governs commits, pushes, draft PRs, PR body updates and CI closeout, deferring to the repo's canonical commit-pr protocol.

    496 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Durable Session State

    ZaxbyHub/opencode-swarm

    Keeps plans, decisions, evidence and reviewer verdicts in small files so long multi-phase tasks survive context compaction and session resumes.

    496 GitHub stars~896 tokensUpdated today
    Auto-check passed
  • Swarm PR Feedback Closer

    ZaxbyHub/opencode-swarm

    Ingests existing pull request feedback such as review comments and CI failures, verifies each claim, fixes confirmed issues and reports closure status for every item.

    496 GitHub stars~14k tokensUpdated today
    Auto-check passed
  • Swarm PR Subscribe

    ZaxbyHub/opencode-swarm

    Monitor a pull request after creation and act autonomously on pushed PR activity.

    496 GitHub stars~2.2k tokensUpdated today
    Auto-check passed

Works with

Questions about Rust Crate CI

What does Rust Crate CI do?

Load before editing any Rust crate in this repo (currently runners/swarm-sandbox-runner). Rust Crate CI is an agent skill from ZaxbyHub/opencode-swarm. Load before editing any Rust crate in this repo (currently runners/swarm-sandbox-runner).

How do I install Rust Crate CI in Claude Code?

Run `npx skills add ZaxbyHub/opencode-swarm --skill rust-crate-ci -a claude-code`. Or copy the skill folder (.claude/skills/rust-crate-ci in ZaxbyHub/opencode-swarm) into .claude/skills/rust-crate-ci in your project. Claude Code loads it when a task matches its description.

How do I install Rust Crate CI in Codex?

Run `npx skills add ZaxbyHub/opencode-swarm --skill rust-crate-ci -a codex`. Or copy the skill folder (.claude/skills/rust-crate-ci in ZaxbyHub/opencode-swarm) into .agents/skills/rust-crate-ci in your project. Codex loads it when a task matches its description.

Can I use Rust Crate CI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ZaxbyHub/opencode-swarm --skill rust-crate-ci -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rust-crate-ci, .gemini/skills/rust-crate-ci, .github/skills/rust-crate-ci and .opencode/skills/rust-crate-ci in your project.

What does Rust Crate CI need to run?

Going by SKILL.md and its folder, Rust Crate CI needs the command-line tools its instructions call (cargo).

Does Rust Crate CI access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Rust Crate CI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rust Crate CI use?

Rust Crate CI is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rust Crate CI use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rust Crate CI?

Skills that share tags, products or a category with Rust Crate CI: Update V8 Version (openinterpreter/openinterpreter, 69k stars), Firecrawl Page Scrape Integration (firecrawl/firecrawl, 190k stars), Migrate Core Code to Submodules (tinyhumansai/openhuman, 42k stars) and Rust TDD Workflow (rtk-ai/rtk, 83k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rust Crate CI?

ZaxbyHub (a GitHub organization) maintains it in ZaxbyHub/opencode-swarm, which has 494 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 10, 2026.

Source: ZaxbyHub/opencode-swarm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.