rust-review
Audits Rust code for unsafe blocks, ownership issues, and Cargo dependency risks Skill: rust-review Owner: athola Summary: Audits Rust code for unsafe blocks, ownership issues, and Cargo dependency risks Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:19:16.072Z | user Release v1.9.19 v1.9.17 | 2026-07-30T05:39:27.389Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:56:10.799Z | user Release v1.9.16 v1.9.14 | 2026-06-30T18:04:28.776Z | user Release v1.9.14 v1.9.13 | 2026-06-27T16:22:2
Rank
62
Safety
84
Downloads
1.5k
Updated
Oct 10, 2026
Version
1.9.19
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.5K downloadsadoption · observed Oct 10, 2026
- Latest release
- 1.9.19release · observed Aug 26, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-pensive-rust-review- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-rust-review/snapshot"
Documentation
CLAWHUB
149,582 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: rust-review
description: Audits Rust code for unsafe blocks, ownership issues, and Cargo dependency risks
version: 1.9.8
triggers:
- rust
- ownership
- concurrency
- unsafe
- traits
- cargo
- reviewing Rust code or before merging Rust changes
metadata: {"openclaw": {"homepage": "https://github.com/athola/claude-night-market/tree/master/plugins/pensive", "emoji": "\ud83d\udd0d", "requires": {"config": ["night-market.pensive:shared", "night-market.imbue:proof-of-work"]}}}
source: claude-night-market
source_plugin: pensive
---
> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.
## Table of Contents
- [Quick Start](#quick-start)
- [When to Use](#when-to-use)
- [Required TodoWrite Items](#required-todowrite-items)
- [Progressive Loading](#progressive-loading)
- [Core Workflow](#core-workflow)
- [Rust Quality Checklist](#rust-quality-checklist)
- [Safety](#safety)
- [Correctness](#correctness)
- [Performance](#performance)
- [Idioms](#idioms)
- [Output Format](#output-format)
- [Summary](#summary)
- [Ownership Analysis](#ownership-analysis)
- [Error Handling](#error-handling)
- [Concurrency](#concurrency)
- [Unsafe Audit](#unsafe-audit)
- [[U1] file:line](#[u1]-file:line)
- [Dependencies](#dependencies)
- [Recommendation](#recommendation)
- [Exit Criteria](#exit-criteria)
# Rust Review Workflow
Expert-level Rust code audits with focus on safety, correctness, and idiomatic patterns.
## Quick Start
```bash
/rust-review
```
**Verification:** Run the command with `--help` flag to verify availability.
## When To Use
- Reviewing Rust code changes
- Auditing unsafe blocks
- Analyzing concurrency patterns
- Dependency security review
- Performance optimization review
## When NOT To Use
- General code review without Rust - use unified-review
- Performance profiling - use parseltongue:python-performance pattern
## Required TodoWrite Items
1. `rust-review:ownership-analysis`
2. `rust-review:error-handling`
3. `rust-review:concurrency`
4. `rust-review:unsafe-audit`
5. `rust-review:cargo-deps`
6. `rust-review:evidence-log`
## Progressive Loading
Load modules as needed based on review scope:
**Quick Review** (ownership and errors):
- See `modules/ownership-analysis.md` for borrowing and lifetime analysis
- See `modules/error-handling.md` for Result/Option patterns
**Concurrency Focus**:
- See `modules/concurrency-patterns.md` for async and sync primitives
**Safety Audit**:
- See `modules/unsafe-audit.md` for unsafe block documentation
**Dependency Review**:
- See `modules/cargo-dependencies.md` for vulnerability scanning
**Idiomatic Patterns**:
- See `modules/builtin-preference.md` for conversion traits and builtin preference
## Core Workflow
1. **Ownership Analysis**: Check borrowing, lifetimes, clone patterns
2. **Error Handling**: Verif_meta.json
{
"ownerId": "kn7d107jg9jv602h9ytsegydq184a42s",
"slug": "nm-pensive-rust-review",
"version": "1.9.19",
"publishedAt": 1787750356072
}modules/async-slop.md
---
module: async-slop
category: detection
dependencies: [Read, Grep]
estimated_tokens: 500
---
# Async Slop
**AI defaults to `async` and `tokio::spawn` even where
sync code is faster, simpler, and correct.**
This module covers the high-frequency async patterns that
look idiomatic but are not. The clippy lints catch some;
the rest is structural.
## Pattern 1: `async fn` that contains no `.await`
```rust
// SLOP
async fn compute_total(items: &[Item]) -> u64 {
items.iter().map(|i| i.price).sum()
}
```
If the function body has no `.await`, it has no reason
to be `async`. Async coloring is contagious: this
function is callable only from async contexts, forcing
every caller to also be `async`. Strip `async` from the
signature unless the body actually awaits.
Detection (preferred: clippy):
```bash
cargo clippy --all-targets -- -W clippy::async_yields_async
```
File-level heuristic when clippy is unavailable:
```bash
for f in $(rg -l "async fn " --type rust); do
rg -q "\.await" "$f" || echo "no-await: $f"
done
```
(Heuristic; manual review needed since `.await` may be in
a helper called by the async fn rather than inline.)
## Pattern 2: blocking I/O inside an async runtime
```rust
// SLOP
async fn read_config() -> Result<String> {
Ok(std::fs::read_to_string("config.toml")?)
}
// SLOP
async fn rate_limit_wait() {
std::thread::sleep(Duration::from_secs(1)); // blocks the runtime
}
// SLOP
async fn query_db(conn: &Connection) -> Result<Vec<Row>> {
conn.query("SELECT ...")? // blocking driver
}
```
Blocking calls inside `async` block the entire executor
thread, defeating the runtime's concurrency model.
Fix:
```rust
// Use the async equivalent
async fn read_config() -> Result<String> {
Ok(tokio::fs::read_to_string("config.toml").await?)
}
// Or wrap blocking work in spawn_blocking
async fn rate_limit_wait() {
tokio::time::sleep(Duration::from_secs(1)).await;
}
// For unavoidable blocking work
async fn query_db(conn: Arc<Connection>) -> Result<Vec<Row>> {
let conn = conn.clone();
tokio::task::spawn_blocking(move || conn.query("SELECT ..."))
.await?
}
```
Detection:
```bash
# Find blocking ops inside async functions (heuristic)
rg -B 5 "(std::fs::|std::thread::sleep|std::net::TcpStream)" --type rust |
rg -B 5 "async fn"
```
## Pattern 3: `tokio::spawn` for synchronous-equivalent work
```rust
// SLOP
async fn handle_request(req: Request) -> Response {
let result = tokio::spawn(async move {
compute_response(&req)
}).await.unwrap();
result
}
```
Spawning a task only to immediately await its single
completion is equivalent to a direct call, plus the
overhead of task creation, scheduling, and a join. Just
call the function:
```rust
async fn handle_request(req: Request) -> Response {
compute_response(&req)
}
```
`tokio::spawn` is for *concurrent* work: when the
spawned task should make progress while the caller does
something else, or when the task should outlive the
camodules/builtin-preference.md
---
name: builtin-preference
description: Detection of helper functions that should be standard trait
implementations and reimplemented Rust builtins
category: rust-review
tags: [from, into, tryfrom, fromstr, default, display, iterator, idioms]
---
# Builtin Preference
Detects custom helper functions that duplicate Rust's standard
trait system and built-in combinators.
## What This Detects
Four categories of anti-patterns:
1. **Conversion helpers**: `parse_foo()`, `foo_from_bar()`,
`convert_*()`, `to_*(&self)` that should be `FromStr`,
`From`, `TryFrom`, or `Into` implementations
2. **Standard trait replacements**: `default_config()`,
`format_error()`, `as_bytes(&self)`, `compare()` that
should be `Default`, `Display`, `AsRef`, or `PartialEq`
3. **Error conversion wrappers**: `io_to_my_error()`,
`wrap_error()` that should be `impl From<Error>` or
thiserror `#[from]`
4. **Manual combinators**: `match opt { Some(x) => Some(f(x)),
None => None }` that should be `.map()`, `.unwrap_or()`,
`.flatten()`, etc.
## Why It Matters
Rust's trait system is compositional by design:
- `impl From<A> for B` gives `impl Into<B> for A` for free
- `impl Display` gives `ToString` for free
- `From` enables the `?` operator for error propagation
- Trait impls participate in generic bounds and blanket impls
- Standard combinators are optimized and well-tested
Helper functions that bypass this system create API
inconsistency, miss ergonomic benefits, and signal
unfamiliarity with idiomatic Rust.
## Safe Patterns
```rust
// Good: From trait enables .into() and ? operator
impl From<Config> for Settings {
fn from(c: Config) -> Self {
Settings { timeout: c.timeout }
}
}
// Good: FromStr enables .parse()
impl FromStr for Config {
type Err = ConfigError;
fn from_str(s: &str) -> Result<Self, Self::Err> { ... }
}
// Good: Default via derive
#[derive(Default)]
struct Config { timeout: u64 }
// Good: Display for human-readable output
impl fmt::Display for MyError {
fn fmt(&self, f: &mut fmt::Formatter) -> fmt::Result {
write!(f, "Error: {}", self.msg)
}
}
// Good: Option combinators
let result = opt.map(|x| x.to_string());
let value = opt.unwrap_or(default);
```
## Patterns to Flag
```rust
// Flag: should be impl FromStr
fn parse_config(s: &str) -> Config { ... }
// Flag: should be impl From<Bar> for Foo
fn foo_from_bar(b: Bar) -> Foo { ... }
// Flag: should be impl Default
fn default_config() -> Config { ... }
// Flag: should be impl From<io::Error> for MyError
fn io_to_my_error(e: io::Error) -> MyError { ... }
// Flag: should use .map()
match opt {
Some(x) => Some(x.to_string()),
None => None,
}
```
## Exclusions (Not Flagged)
- Lossy conversions (`to_lossy_ascii`)
- Builder methods (`with_timeout(self, ...)`)
- Multi-parameter conversions (context-dependent)
- Domain-specific operations (`serialize`, `encode`, `decode`)
## Related Clippy Lints
| Lint | Detects |
|------|---------|
modules/cargo-dependencies.md
--- name: cargo-dependencies description: Dependency auditing, security scanning, and version management category: rust-review tags: [cargo, dependencies, security, audit] --- # Cargo Dependencies Audit and management of Cargo dependencies and build configuration. ## Audit Commands Run detailed dependency analysis: ```bash cargo tree -d # Find duplicates cargo audit # Security vulnerabilities cargo outdated # Stale versions cargo deny check # Policy enforcement ``` ## Dependency Evaluation Check: - Feature flags usage - Optional dependencies - Build scripts safety - Binary size impact - Compilation time ## Security Scanning Review for: - Known vulnerabilities - Abandoned crates - Unmaintained dependencies - Security advisories - Supply chain risks ## Version Management Verify: - Semver compliance - Version pinning strategy - Dependency updates frequency - Breaking change handling ## Common Issues Flag: - Abandoned crates - Excessively large dependencies - Security-vulnerable versions - Duplicate dependencies - Unnecessary dependencies ## Alternatives Suggestion Recommend alternatives for: - Unmaintained crates - Heavy dependencies - Vulnerable versions - Better maintained options ## Output Section ```markdown ## Dependencies ### Security Issues - [crate@version] Vulnerability: [CVE/advisory] ### Recommendations - Update [crate] from X to Y - Replace [abandoned-crate] with [alternative] - Remove unused dependency: [crate] ```
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/athola/skills/nm-pensive-rust-review",
"sourceUrl": "https://clawhub.ai/athola/skills/nm-pensive-rust-review",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T09:05:39.139Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-rust-review/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-rust-review/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T09:05:39.139Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.5K downloads",
"href": "https://clawhub.ai/athola/nm-pensive-rust-review",
"sourceUrl": "https://clawhub.ai/athola/nm-pensive-rust-review",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T09:05:39.139Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.9.19",
"href": "https://clawhub.ai/athola/nm-pensive-rust-review",
"sourceUrl": "https://clawhub.ai/athola/nm-pensive-rust-review",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-26T13:19:16.072Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-rust-review/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-rust-review/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.9.19",
"description": "Release v1.9.19",
"href": "https://clawhub.ai/athola/nm-pensive-rust-review",
"sourceUrl": "https://clawhub.ai/athola/nm-pensive-rust-review",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-26T13:19:16.072Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
