agentCLAWHUBUnverified

rust-review

Audits Rust code for unsafe blocks, ownership issues, and Cargo dependency risks Skill: rust-review Owner: athola Summary: Audits Rust code for unsafe blocks, ownership issues, and Cargo dependency risks Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:19:16.072Z | user Release v1.9.19 v1.9.17 | 2026-07-30T05:39:27.389Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:56:10.799Z | user Release v1.9.16 v1.9.14 | 2026-06-30T18:04:28.776Z | user Release v1.9.14 v1.9.13 | 2026-06-27T16:22:2

OpenClaw

Rank

62

Safety

84

Downloads

1.5k

Updated

Oct 10, 2026

Version

1.9.19

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.5K downloadsadoption · observed Oct 10, 2026
Latest release
1.9.19release · observed Aug 26, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-pensive-rust-review
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-rust-review/snapshot"

Documentation

CLAWHUB

149,582 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: rust-review
description: Audits Rust code for unsafe blocks, ownership issues, and Cargo dependency risks
version: 1.9.8
triggers:
  - rust
  - ownership
  - concurrency
  - unsafe
  - traits
  - cargo
  - reviewing Rust code or before merging Rust changes
metadata: {"openclaw": {"homepage": "https://github.com/athola/claude-night-market/tree/master/plugins/pensive", "emoji": "\ud83d\udd0d", "requires": {"config": ["night-market.pensive:shared", "night-market.imbue:proof-of-work"]}}}
source: claude-night-market
source_plugin: pensive
---

> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.


## Table of Contents

- [Quick Start](#quick-start)
- [When to Use](#when-to-use)
- [Required TodoWrite Items](#required-todowrite-items)
- [Progressive Loading](#progressive-loading)
- [Core Workflow](#core-workflow)
- [Rust Quality Checklist](#rust-quality-checklist)
- [Safety](#safety)
- [Correctness](#correctness)
- [Performance](#performance)
- [Idioms](#idioms)
- [Output Format](#output-format)
- [Summary](#summary)
- [Ownership Analysis](#ownership-analysis)
- [Error Handling](#error-handling)
- [Concurrency](#concurrency)
- [Unsafe Audit](#unsafe-audit)
- [[U1] file:line](#[u1]-file:line)
- [Dependencies](#dependencies)
- [Recommendation](#recommendation)
- [Exit Criteria](#exit-criteria)


# Rust Review Workflow

Expert-level Rust code audits with focus on safety, correctness, and idiomatic patterns.

## Quick Start

```bash
/rust-review
```
**Verification:** Run the command with `--help` flag to verify availability.

## When To Use

- Reviewing Rust code changes
- Auditing unsafe blocks
- Analyzing concurrency patterns
- Dependency security review
- Performance optimization review

## When NOT To Use

- General code review without Rust - use unified-review
- Performance profiling - use parseltongue:python-performance pattern

## Required TodoWrite Items

1. `rust-review:ownership-analysis`
2. `rust-review:error-handling`
3. `rust-review:concurrency`
4. `rust-review:unsafe-audit`
5. `rust-review:cargo-deps`
6. `rust-review:evidence-log`

## Progressive Loading

Load modules as needed based on review scope:

**Quick Review** (ownership and errors):
- See `modules/ownership-analysis.md` for borrowing and lifetime analysis
- See `modules/error-handling.md` for Result/Option patterns

**Concurrency Focus**:
- See `modules/concurrency-patterns.md` for async and sync primitives

**Safety Audit**:
- See `modules/unsafe-audit.md` for unsafe block documentation

**Dependency Review**:
- See `modules/cargo-dependencies.md` for vulnerability scanning

**Idiomatic Patterns**:
- See `modules/builtin-preference.md` for conversion traits and builtin preference

## Core Workflow

1. **Ownership Analysis**: Check borrowing, lifetimes, clone patterns
2. **Error Handling**: Verif

_meta.json

{
  "ownerId": "kn7d107jg9jv602h9ytsegydq184a42s",
  "slug": "nm-pensive-rust-review",
  "version": "1.9.19",
  "publishedAt": 1787750356072
}

modules/async-slop.md

---
module: async-slop
category: detection
dependencies: [Read, Grep]
estimated_tokens: 500
---

# Async Slop

**AI defaults to `async` and `tokio::spawn` even where
sync code is faster, simpler, and correct.**

This module covers the high-frequency async patterns that
look idiomatic but are not. The clippy lints catch some;
the rest is structural.

## Pattern 1: `async fn` that contains no `.await`

```rust
// SLOP
async fn compute_total(items: &[Item]) -> u64 {
    items.iter().map(|i| i.price).sum()
}
```

If the function body has no `.await`, it has no reason
to be `async`. Async coloring is contagious: this
function is callable only from async contexts, forcing
every caller to also be `async`. Strip `async` from the
signature unless the body actually awaits.

Detection (preferred: clippy):

```bash
cargo clippy --all-targets -- -W clippy::async_yields_async
```

File-level heuristic when clippy is unavailable:

```bash
for f in $(rg -l "async fn " --type rust); do
  rg -q "\.await" "$f" || echo "no-await: $f"
done
```

(Heuristic; manual review needed since `.await` may be in
a helper called by the async fn rather than inline.)

## Pattern 2: blocking I/O inside an async runtime

```rust
// SLOP
async fn read_config() -> Result<String> {
    Ok(std::fs::read_to_string("config.toml")?)
}

// SLOP
async fn rate_limit_wait() {
    std::thread::sleep(Duration::from_secs(1));  // blocks the runtime
}

// SLOP
async fn query_db(conn: &Connection) -> Result<Vec<Row>> {
    conn.query("SELECT ...")?  // blocking driver
}
```

Blocking calls inside `async` block the entire executor
thread, defeating the runtime's concurrency model.

Fix:

```rust
// Use the async equivalent
async fn read_config() -> Result<String> {
    Ok(tokio::fs::read_to_string("config.toml").await?)
}

// Or wrap blocking work in spawn_blocking
async fn rate_limit_wait() {
    tokio::time::sleep(Duration::from_secs(1)).await;
}

// For unavoidable blocking work
async fn query_db(conn: Arc<Connection>) -> Result<Vec<Row>> {
    let conn = conn.clone();
    tokio::task::spawn_blocking(move || conn.query("SELECT ..."))
        .await?
}
```

Detection:

```bash
# Find blocking ops inside async functions (heuristic)
rg -B 5 "(std::fs::|std::thread::sleep|std::net::TcpStream)" --type rust |
  rg -B 5 "async fn"
```

## Pattern 3: `tokio::spawn` for synchronous-equivalent work

```rust
// SLOP
async fn handle_request(req: Request) -> Response {
    let result = tokio::spawn(async move {
        compute_response(&req)
    }).await.unwrap();
    result
}
```

Spawning a task only to immediately await its single
completion is equivalent to a direct call, plus the
overhead of task creation, scheduling, and a join. Just
call the function:

```rust
async fn handle_request(req: Request) -> Response {
    compute_response(&req)
}
```

`tokio::spawn` is for *concurrent* work: when the
spawned task should make progress while the caller does
something else, or when the task should outlive the
ca

modules/builtin-preference.md

---
name: builtin-preference
description: Detection of helper functions that should be standard trait
  implementations and reimplemented Rust builtins
category: rust-review
tags: [from, into, tryfrom, fromstr, default, display, iterator, idioms]
---

# Builtin Preference

Detects custom helper functions that duplicate Rust's standard
trait system and built-in combinators.

## What This Detects

Four categories of anti-patterns:

1. **Conversion helpers**: `parse_foo()`, `foo_from_bar()`,
   `convert_*()`, `to_*(&self)` that should be `FromStr`,
   `From`, `TryFrom`, or `Into` implementations
2. **Standard trait replacements**: `default_config()`,
   `format_error()`, `as_bytes(&self)`, `compare()` that
   should be `Default`, `Display`, `AsRef`, or `PartialEq`
3. **Error conversion wrappers**: `io_to_my_error()`,
   `wrap_error()` that should be `impl From<Error>` or
   thiserror `#[from]`
4. **Manual combinators**: `match opt { Some(x) => Some(f(x)),
   None => None }` that should be `.map()`, `.unwrap_or()`,
   `.flatten()`, etc.

## Why It Matters

Rust's trait system is compositional by design:

- `impl From<A> for B` gives `impl Into<B> for A` for free
- `impl Display` gives `ToString` for free
- `From` enables the `?` operator for error propagation
- Trait impls participate in generic bounds and blanket impls
- Standard combinators are optimized and well-tested

Helper functions that bypass this system create API
inconsistency, miss ergonomic benefits, and signal
unfamiliarity with idiomatic Rust.

## Safe Patterns

```rust
// Good: From trait enables .into() and ? operator
impl From<Config> for Settings {
    fn from(c: Config) -> Self {
        Settings { timeout: c.timeout }
    }
}

// Good: FromStr enables .parse()
impl FromStr for Config {
    type Err = ConfigError;
    fn from_str(s: &str) -> Result<Self, Self::Err> { ... }
}

// Good: Default via derive
#[derive(Default)]
struct Config { timeout: u64 }

// Good: Display for human-readable output
impl fmt::Display for MyError {
    fn fmt(&self, f: &mut fmt::Formatter) -> fmt::Result {
        write!(f, "Error: {}", self.msg)
    }
}

// Good: Option combinators
let result = opt.map(|x| x.to_string());
let value = opt.unwrap_or(default);
```

## Patterns to Flag

```rust
// Flag: should be impl FromStr
fn parse_config(s: &str) -> Config { ... }

// Flag: should be impl From<Bar> for Foo
fn foo_from_bar(b: Bar) -> Foo { ... }

// Flag: should be impl Default
fn default_config() -> Config { ... }

// Flag: should be impl From<io::Error> for MyError
fn io_to_my_error(e: io::Error) -> MyError { ... }

// Flag: should use .map()
match opt {
    Some(x) => Some(x.to_string()),
    None => None,
}
```

## Exclusions (Not Flagged)

- Lossy conversions (`to_lossy_ascii`)
- Builder methods (`with_timeout(self, ...)`)
- Multi-parameter conversions (context-dependent)
- Domain-specific operations (`serialize`, `encode`, `decode`)

## Related Clippy Lints

| Lint | Detects |
|------|---------|

modules/cargo-dependencies.md

---
name: cargo-dependencies
description: Dependency auditing, security scanning, and version management
category: rust-review
tags: [cargo, dependencies, security, audit]
---

# Cargo Dependencies

Audit and management of Cargo dependencies and build configuration.

## Audit Commands

Run detailed dependency analysis:
```bash
cargo tree -d              # Find duplicates
cargo audit                # Security vulnerabilities
cargo outdated             # Stale versions
cargo deny check           # Policy enforcement
```

## Dependency Evaluation

Check:
- Feature flags usage
- Optional dependencies
- Build scripts safety
- Binary size impact
- Compilation time

## Security Scanning

Review for:
- Known vulnerabilities
- Abandoned crates
- Unmaintained dependencies
- Security advisories
- Supply chain risks

## Version Management

Verify:
- Semver compliance
- Version pinning strategy
- Dependency updates frequency
- Breaking change handling

## Common Issues

Flag:
- Abandoned crates
- Excessively large dependencies
- Security-vulnerable versions
- Duplicate dependencies
- Unnecessary dependencies

## Alternatives Suggestion

Recommend alternatives for:
- Unmaintained crates
- Heavy dependencies
- Vulnerable versions
- Better maintained options

## Output Section

```markdown
## Dependencies
### Security Issues
- [crate@version] Vulnerability: [CVE/advisory]

### Recommendations
- Update [crate] from X to Y
- Replace [abandoned-crate] with [alternative]
- Remove unused dependency: [crate]
```
Github ReposUpdated 16h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/athola/skills/nm-pensive-rust-review",
      "sourceUrl": "https://clawhub.ai/athola/skills/nm-pensive-rust-review",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T09:05:39.139Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-rust-review/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-rust-review/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T09:05:39.139Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.5K downloads",
      "href": "https://clawhub.ai/athola/nm-pensive-rust-review",
      "sourceUrl": "https://clawhub.ai/athola/nm-pensive-rust-review",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T09:05:39.139Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.9.19",
      "href": "https://clawhub.ai/athola/nm-pensive-rust-review",
      "sourceUrl": "https://clawhub.ai/athola/nm-pensive-rust-review",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-08-26T13:19:16.072Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-rust-review/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-rust-review/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.9.19",
      "description": "Release v1.9.19",
      "href": "https://clawhub.ai/athola/nm-pensive-rust-review",
      "sourceUrl": "https://clawhub.ai/athola/nm-pensive-rust-review",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-08-26T13:19:16.072Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to rust-review and adjacent AI workflows.