From pensive
Audits Rust code for unsafe blocks, ownership issues, and Cargo dependency risks. Use when reviewing Rust code or before merging Rust changes.
How this skill is triggered — by the user, by Claude, or both
Slash command
/pensive:rust-reviewThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
- [Quick Start](#quick-start)
modules/async-slop.mdmodules/builtin-preference.mdmodules/cargo-dependencies.mdmodules/cfg-test-misuse.mdmodules/coercion-params.mdmodules/collection-types.mdmodules/concurrency-patterns.mdmodules/conversion-traits.mdmodules/duplicate-validators.mdmodules/error-handling.mdmodules/error-messages.mdmodules/float-equality.mdmodules/idiomatic-elision.mdmodules/iterator-and-allocation-slop.mdmodules/match-wildcard.mdmodules/mem-forget-audit.mdmodules/model-specific-tells.mdmodules/mutable-static-audit.mdmodules/native-type-modeling.mdmodules/numeric-cast-safety.mdExpert-level Rust code audits with focus on safety, correctness, and idiomatic patterns.
/rust-review
Verification: Run the command with --help flag to verify availability.
rust-review:ownership-analysisrust-review:error-handlingrust-review:concurrencyrust-review:unsafe-auditrust-review:cargo-depsrust-review:native-modelingrust-review:idiomatic-elisionrust-review:coercion-paramsrust-review:conversion-traitsrust-review:numeric-cast-safetyrust-review:mutable-static-auditrust-review:match-wildcardrust-review:transmute-auditrust-review:float-equalityrust-review:mem-forget-auditrust-review:repr-packed-auditrust-review:evidence-logrust-review:findings-verifiedLoad modules as needed based on review scope:
Quick Review (ownership and errors):
modules/ownership-analysis.md for borrowing and lifetime analysismodules/error-handling.md for Result/Option patternsConcurrency Focus:
modules/concurrency-patterns.md for async and sync primitivesSafety Audit:
modules/unsafe-audit.md for unsafe block documentationmodules/mutable-static-audit.md for static mut globals and
their thread-safe replacementsmodules/numeric-cast-safety.md for truncating and
precision-losing as castsmodules/match-wildcard.md for catch-all arms that defeat enum
exhaustivenessmodules/transmute-audit.md for mem::transmute/transmute_copy
calls that reinterpret bytes with no layout checkmodules/repr-packed-audit.md for #[repr(packed)] layouts whose
field borrows become unaligned referencesCorrectness Audit:
modules/float-equality.md for ==/!= against float literalsmodules/mem-forget-audit.md for mem::forget leaks and no-op
drop(&x) reference dropsDependency Review:
modules/cargo-dependencies.md for vulnerability scanningIdiomatic Patterns:
modules/builtin-preference.md for conversion traits and builtin preferencemodules/native-type-modeling.md for enums-over-primitives,
newtype, type-state, and derived orderingmodules/idiomatic-elision.md for lifetime elision,
expression-oriented returns, and explicit -> () unit returnsmodules/coercion-params.md for &String/&Vec<T>/&PathBuf
parameters that defeat deref coercion (prefer &str/&[T]/&Path)modules/conversion-traits.md for impl Into that should be
impl From, and discarded try_into().unwrap() conversion errorsstatic mut globals; shared state uses OnceLock/LazyLock,
atomics, or a Mutex/RwLockmem::transmute/transmute_copy; bytes converted with
from_le_bytes/from_bits/bytemuck or pointers with .cast()#[repr(packed)] fields copied out before borrowing (no unaligned
references)mem::forget leaks (use ManuallyDrop/scope) and no no-op
drop(&x) reference dropsmlock/munlock calls: RLIMIT verified, page-aligned,
ENOMEM handledas casts (length truncation, as u8/i8, as f32)
replaced with TryFrom/From_ => unreachable!()/panic!/{}
catch-alls==/!= against a
float literal'_ in pathsreturn dropped in favor of the tail expression-> () unit returns dropped (default is elided)&str/&[T]/&Path, not &String/&Vec<T>/
&PathBuf (deref coercion accepts both, so the slice is more general)From/TryFrom, not Into/TryInto; a
fallible conversion's error is propagated, not unwrap()ped## Summary
Rust audit findings
## Ownership Analysis
[borrowing and lifetime issues]
## Error Handling
[error patterns and issues]
## Concurrency
[async and sync patterns]
## Unsafe Audit
### [U1] file:line
- Invariants: [documented]
- Anchor: `verbatim source text at file:line`
- Risk: [assessment]
- Recommendation: [action]
## Native Type Modeling
[stringly-typed comparisons, boolean blindness, newtype/type-state notes]
## Idiomatic Elision
[needless lifetimes, trailing returns, explicit `-> ()` unit returns]
## Coercion Params
[`&String`/`&Vec<T>`/`&PathBuf` params that should be borrowed slices]
## Conversion Traits
[`impl Into` over `impl From`; discarded `try_into().unwrap()` errors]
## Numeric Cast Safety
[length-truncating, byte-narrowing, and f32 precision-losing `as` casts]
## Mutable Static Audit
[`static mut` globals and their thread-safe replacements]
## Match Wildcard
[catch-all `_ =>` arms that defeat enum exhaustiveness]
## Transmute Audit
[`mem::transmute`/`transmute_copy` calls and their typed replacements]
## Float Equality
[exact `==`/`!=` comparisons against float literals]
## Mem Forget Audit
[`mem::forget` leaks and no-op `drop(&x)` reference drops]
## Repr Packed Audit
[`#[repr(packed)]` layouts whose field borrows become unaligned]
## Dependencies
[cargo audit results]
## Recommendation
Approve / Approve with actions / Block
Verification: Run the command with --help flag to verify availability.
rust-review:findings-verified)Every finding must cite a real location and a verbatim anchor. Write
findings to .review/findings.json and confirm each citation resolves:
python plugins/imbue/scripts/citation_verifier.py \
--findings .review/findings.json --repo-root .
Drop or label UNVERIFIED any finding the verifier fails (exit 1); only
verified findings enter the report. See Skill(imbue:review-core) Step 5
and Skill(imbue:structured-output) for the schema.
Location + verbatim Anchor confirmed by citation_verifier.py (exit 0), or unverified findings were dropped or labeled UNVERIFIEDnpx claudepluginhub athola/claude-night-market --plugin pensiveReviews Rust code for ownership, borrowing, lifetimes, error handling, trait design, unsafe usage, and common mistakes. Covers Rust 2024 edition patterns and modern idioms.
Rust as a language — ownership and lifetimes, error hierarchies with thiserror/anyhow, async with Tokio, trait design, testing, performance, clippy, and rustdoc. Use when writing or reviewing Rust code, deciding between borrowing and cloning, designing an error type, structuring async tasks and channels, or configuring lints and benchmarks. Do not use for Axum HTTP routing and middleware (rc-axum), SQLx/Postgres data access (rc-sqlx), SvelteKit (rc-sveltekit), or non-Rust languages.
Audits Rust project architecture and code quality across type safety, modularity, testability, readability, DRY, and async concurrency.