From rust-tools
Audit Rust dependencies for vulnerabilities, license compliance, supply chain integrity, and freshness using cargo-audit, cargo-deny, cargo-vet,
How this skill is triggered — by the user, by Claude, or both
Slash command
/rust-tools:rust-dependency-auditThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
Comprehensive dependency audit workflow using four complementary tools: freshness checking, vulnerability scanning, license/advisory compliance, and supply chain verification.
Comprehensive dependency audit workflow using four complementary tools: freshness checking, vulnerability scanning, license/advisory compliance, and supply chain verification.
Self-Evolving Skill: This skill improves through use. If instructions are wrong, parameters drifted, or a workaround was needed — fix this file immediately, don't defer. Only update for real, reproducible issues.
Always check crates.io for latest versions before recommending upgrades. Static docs go stale; the crates.io API is ground truth.
Before upgrading a crate: Check what version is current and what it depends on
WebFetch: https://crates.io/api/v1/crates/{crate_name}
Prompt: "What is the latest version? List recent versions and their dependencies."
Before ignoring a vulnerability: Verify whether a patched version exists
WebSearch: "{advisory_id} {crate_name} fix patch"
Check compatibility chains: When crate A depends on crate B, verify both latest versions are compatible
WebFetch: https://crates.io/api/v1/crates/{crate_name}/{version}/dependencies
Prompt: "What version of {dependency} does this require?"
Fallback: Firecrawl scrape (if WebFetch fails — JS-heavy pages, rate limits, incomplete data):
curl -s -X POST http://littleblack:3002/v1/scrape \
-H "Content-Type: application/json" \
-d '{"url": "https://crates.io/crates/{crate_name}", "formats": ["markdown"], "waitFor": 0}' \
| jq -r '.data.markdown'
Requires Tailscale connectivity. See /devops-tools:firecrawl-research-patterns for full API reference.
cargo update (verify no new vulnerabilities)Run in this order — each tool catches different issues:
# 1. Freshness — what's outdated?
cargo outdated
# 2. Vulnerabilities — any known CVEs?
cargo audit
# 3. Licenses + Advisories — compliance check
cargo deny check
# 4. Supply Chain — who audited these crates?
cargo vet
# One-liner: run all four (stop on first failure)
cargo outdated && cargo audit && cargo deny check && cargo vet
Three tools for different needs:
| Tool | Install | Purpose | Best For |
|---|---|---|---|
cargo-outdated | cargo install cargo-outdated | Full outdated report with compatible/latest versions | Comprehensive audit |
cargo-upgrades | cargo install cargo-upgrades | Lightweight — only shows incompatible (breaking) updates | Quick check |
cargo upgrade (cargo-edit) | cargo install cargo-edit | Actually updates Cargo.toml versions | Performing updates |
# Show all outdated deps (compatible + incompatible)
cargo outdated --root-deps-only
# Show only breaking updates needed
cargo upgrades
# Actually update Cargo.toml (dry run first)
cargo upgrade --dry-run
cargo upgrade --incompatible
# Nightly: native cargo support (experimental)
cargo +nightly update --breaking
Recommendation: Use cargo-upgrades for quick checks, cargo-outdated for full audits, cargo upgrade (cargo-edit) when ready to actually update.
# Scan for known vulnerabilities
cargo audit
# Auto-fix where possible (updates Cargo.lock)
cargo audit fix
# Binary scanning (audit compiled binaries)
cargo audit bin ./target/release/my-binary
# Custom config (ignore specific advisories)
# Create audit.toml:
# audit.toml
[advisories]
ignore = [
"RUSTSEC-YYYY-NNNN", # Reason for ignoring
]
cargo-deny's advisory check complements cargo-audit with additional sources:
# Check advisories only
cargo deny check advisories
# All checks (advisories + licenses + bans + sources)
cargo deny check
See the License section below for full cargo-deny configuration.
# deny.toml
[licenses]
allow = [
"MIT",
"Apache-2.0",
"BSD-2-Clause",
"BSD-3-Clause",
"ISC",
"Unicode-3.0",
]
confidence-threshold = 0.8
[[licenses.clarify]]
name = "ring"
expression = "MIT AND ISC AND OpenSSL"
license-files = [{ path = "LICENSE", hash = 0xbd0eed23 }]
# Check licenses
cargo deny check licenses
# Generate deny.toml template
cargo deny init
See cargo-deny reference.
cargo-vet tracks which crates have been audited and by whom:
# Check supply chain status
cargo vet
# Audit a specific crate (certify you've reviewed it)
cargo vet certify <crate> <version>
# Import audits from trusted organizations
cargo vet trust --all mozilla
cargo vet trust --all google
# See what needs auditing
cargo vet suggest
Key files:
supply-chain/audits.toml — Your auditssupply-chain/imports.lock — Imported auditssupply-chain/config.toml — Trusted sourcesSee cargo-vet reference.
cargo-geiger quantifies unsafe code usage across your entire dependency tree:
# Quick check: which deps forbid unsafe? (fast, no compilation)
cargo geiger --forbid-only
# Full audit: count unsafe blocks per crate
cargo geiger
# Output as ratio (for CI/scripting)
cargo geiger --forbid-only --output-format ratio
# Markdown report
cargo geiger --output-format markdown > unsafe-report.md
Key flags:
--forbid-only: Fast mode — only checks #![forbid(unsafe_code)] (no compilation)--output-format: ratio, markdown, ascii, json--all-features: Check with all features enabledname: Dependency Audit
on:
pull_request:
schedule:
- cron: "0 6 * * 1" # Weekly Monday 6am
jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install Rust
uses: dtolnay/rust-toolchain@stable
- name: cargo-audit
run: |
cargo install cargo-audit
cargo audit
- name: cargo-deny
uses: EmbarkStudios/cargo-deny-action@v2
- name: cargo-vet
run: |
cargo install cargo-vet
cargo vet
- name: cargo-geiger
run: |
cargo install cargo-geiger
cargo geiger --forbid-only
- name: cargo-outdated
run: |
cargo install cargo-outdated
cargo outdated --root-deps-only --exit-code 1
| Problem | Solution |
|---|---|
cargo audit stale database | Run cargo audit fetch to update RUSTSEC DB |
cargo deny false positive license | Add [[licenses.clarify]] entry in deny.toml |
cargo vet too many unaudited | Import trusted org audits: cargo vet trust --all mozilla |
cargo outdated shows yanked | Run cargo update first to refresh Cargo.lock |
| Private registry crates | Configure [sources] in deny.toml for private registries |
| Workspace vs single crate | Most tools support --workspace flag |
After this skill completes, check before closing:
Only update if the issue is real and reproducible — not speculative.
Guides completion of development work by verifying tests, detecting environment, and presenting structured options for merge, PR, or cleanup.
Enforces test-driven development: write failing test first, then minimal code to pass. Use when implementing features or bugfixes.
Guides creation and editing of skills using test-driven development with pressure scenarios and subagents to verify agent compliance.
npx claudepluginhub terrylica/cc-skills --plugin rust-tools