Token导航 LogoToken导航TokenDH.com
研究检索需要联网clawhub未标认证来源可访问clear审计通过

rust-code-reviewRust 代码审查

Agent Skill

rust-code-review 用于记录任务执行中的错误、用户纠正、经验和能力缺口,适合在 OpenClaw 中希望让 Agent 持续沉淀问题、修正和最佳实践时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

7,246

周安装

296

GitHub Stars

公开资料未说明

下载量

2,321
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:rust-code-review(Rust 代码审查)
来源仓库:https://github.com/anderskev/rust-code-review
安装命令:
openclaw skills install rust-code-review
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install rust-code-review

简介

专注于 Rust 代码的所有权、借用和生命周期审查,提升代码安全性。

  • 适合在查看 .rs 文件时检查惯用模式和潜在内存错误。
  • 可分析并发设计、不安全块使用和依赖关系风险点。
  • 使用前需确认项目结构,避免对非 Rust 项目误用造成干扰。
  • 建议配合 rust-analyzer 等工具使用,增强审查结果的准确性。

SKILL.md

name
rust-code-review
description
Reviews Rust code for ownership, borrowing, lifetime, error handling, trait design, unsafe usage, and common mistakes. Use when reviewing .rs files, checking borrow checker issues, error handling patterns, or trait implementations. Covers Rust 2024 edition patterns and modern idioms.

Rust Code Review

Review Workflow

Follow this sequence to avoid false positives and catch edition-specific issues:

  1. Check Cargo.toml — Note the Rust edition (2018, 2021, 2024) and MSRV if set. Edition 2024 introduces breaking changes to unsafe semantics, RPIT lifetime capture, temporary scoping, and ! type fallback. This determines which patterns apply. Check workspace structure if present.
  2. Check dependencies — Note key crates (thiserror vs anyhow, tokio features, serde features). These inform which patterns are expected.
  3. Scan changed files — Read full functions, not just diffs. Many Rust bugs hide in ownership flow across a function.
  4. Check each category — Work through the checklist below, loading references as needed.
  5. Verify before reporting — Complete Gates (below), including the verification-protocol gate, before submitting findings.

Gates

These steps are sequenced: do not skip ahead with “mental verification.” Each step has an objective Pass you can satisfy from files on disk and your own read path.

  1. Crate context — Before relying on edition-specific checklist rows (Edition 2024, MSRV-sensitive APIs) or dependency assumptions. Pass: You opened the relevant Cargo.toml (package or workspace manifest) and can state edition and rust-version (if set) in one line.
  2. Expanded read — Before reporting a Major or Critical finding. Pass: You read the full function, unsafe block, or impl / trait item that contains the cited line (not only a diff hunk).
  3. Severity match — Before each finding line in the report. Pass: The Severity label matches Severity Calibration for that issue class, or you use Informational and give a one-line rationale.
  4. Verification protocol — Before finalizing the report. Pass: beagle-rust:review-verification-protocol is loaded and every step in it that applies to this review is completed (do not substitute a vague “I checked”).

Output Format

Report findings as:

[FILE:LINE] ISSUE_TITLE
Severity: Critical | Major | Minor | Informational
Description of the issue and why it matters.

Quick Reference

Issue TypeReference
Ownership transfers, borrowing, lifetimes, clone traps, iteratorsreferences/ownership-borrowing.md
Lifetime variance, covariance/invariance, memory regionsreferences/lifetime-variance.md
Result/Option handling, thiserror, anyhow, error context, Error traitreferences/error-handling.md
Async pitfalls, Send/Sync bounds, runtime blockingreferences/async-concurrency.md
Send/Sync semantics, atomics, memory ordering, lock patternsreferences/concurrency-primitives.md
Type layout, alignment, repr, PhantomData, generics vs dyn Traitreferences/types-layout.md
Unsafe code, API design, derive patterns, clippy patternsreferences/common-mistakes.md
Safety contracts, raw pointers, MaybeUninit, soundness, Mirireferences/unsafe-deep.md
For development guidance on performance, pointer types, type state, clippy config, iterators, generics, and documentation, use the beagle-rust:rust-best-practices skill.

Review Checklist

Ownership and Borrowing

  • [ ] No unnecessary .clone() to silence the borrow checker (hiding design issues)
  • [ ] No .clone() inside loops — prefer .cloned() or .copied() on iterators
  • [ ] No cloning to avoid lifetime annotations (take ownership explicitly or restructure)
  • [ ] References have appropriate lifetimes (not overly broad 'static when shorter lifetime works)
  • [ ] Edition 2024: RPIT (-> impl Trait) captures all in-scope lifetimes by default; use + use<'a> for precise capture control
  • [ ] &str preferred over String, &[T] over Vec<T> in function parameters
  • [ ] impl AsRef<T> or Into<T> used for flexible API parameters
  • [ ] No dangling references or use-after-move
  • [ ] Interior mutability (Cell, RefCell, Mutex) used only when shared mutation is genuinely needed
  • [ ] Small types (≤24 bytes) derive Copy and are passed by value
  • [ ] Cow<'_, T> used when ownership is ambiguous
  • [ ] Iterator chains preferred over index-based loops for collection transforms
  • [ ] No premature .collect() — pass iterators directly when the consumer accepts them
  • [ ] .sum() preferred over .fold() for summation (compiler optimizes better)
  • [ ] _or_else variants used when fallbacks involve allocation
  • [ ] Edition 2024: if let temporaries drop at end of the if let — code relying on temporaries living through the else branch needs restructuring
  • [ ] Edition 2024: Box<[T]> implements IntoIterator — prefer direct iteration over into_vec() first

Error Handling

  • [ ] Result<T, E> used for recoverable errors, not panic!/unwrap/expect
  • [ ] Error types provide context (thiserror with #[error("...")] or manual Display)
  • [ ] ? operator used with proper From implementations or .map_err()
  • [ ] unwrap() / expect() only in tests, examples, or provably-safe contexts
  • [ ] Error variants are specific enough to be actionable by callers
  • [ ] anyhow used in applications, thiserror in libraries (or clear rationale for alternatives)
  • [ ] _or_else variants used when fallbacks involve allocation (ok_or_else, unwrap_or_else)
  • [ ] let-else used for early returns on failure (let Ok(x) = expr else { return ... })
  • [ ] inspect_err used for error logging, map_err for error transformation

Traits and Types

  • [ ] Traits are minimal and cohesive (single responsibility)
  • [ ] derive macros appropriate for the type (Clone, Debug, PartialEq used correctly)
  • [ ] Newtypes used to prevent primitive obsession (e.g., struct UserId(Uuid) not bare Uuid)
  • [ ] From/Into implementations are lossless and infallible; TryFrom for fallible conversions
  • [ ] Sealed traits used when external implementations shouldn't be allowed
  • [ ] Default implementations provided where they make sense
  • [ ] Send + Sync bounds verified for types shared across threads
  • [ ] #[diagnostic::on_unimplemented] used on public traits to provide clear error messages when users forget to implement them

Unsafe Code

  • [ ] unsafe blocks have safety comments explaining invariants
  • [ ] unsafe is minimal — only the truly unsafe operation is inside the block
  • [ ] Safety invariants are documented and upheld by surrounding safe code
  • [ ] No undefined behavior (null pointer deref, data races, invalid memory access)
  • [ ] unsafe trait implementations justify why the contract is upheld
  • [ ] Edition 2024: unsafe fn bodies use explicit unsafe {} blocks around unsafe ops (unsafe_op_in_unsafe_fn is deny)
  • [ ] Edition 2024: extern "C" {} blocks written as unsafe extern "C" {}
  • [ ] Edition 2024: #[no_mangle] and #[export_name] written as #[unsafe(no_mangle)] and #[unsafe(export_name)]

Naming and Style

  • [ ] Types are PascalCase, functions/methods snake_case, constants SCREAMING_SNAKE_CASE
  • [ ] Modules use snake_case
  • [ ] is_, has_, can_ prefixes for boolean-returning methods
  • [ ] Builder pattern methods take and return self (not &mut self) for chaining
  • [ ] Public items have doc comments (///)
  • [ ] #[must_use] on functions where ignoring the return value is likely a bug
  • [ ] Imports ordered: std → external crates → workspace → crate/super
  • [ ] #[expect(clippy::...)] preferred over #[allow(...)] for lint suppression

Performance

Detailed guidance: beagle-rust:rust-best-practices skill (references/performance.md)
  • [ ] No unnecessary allocations in hot paths (prefer &str over String, &[T] over Vec<T>)
  • [ ] collect() type is specified or inferable
  • [ ] Iterators preferred over indexed loops for collection transforms
  • [ ] Vec::with_capacity() used when size is known
  • [ ] No redundant .to_string() / .to_owned() chains
  • [ ] No intermediate .collect() when passing iterators directly works
  • [ ] .sum() preferred over .fold() for summation
  • [ ] Static dispatch (impl Trait) used over dynamic (dyn Trait) unless flexibility required

Clippy Configuration

Detailed guidance: beagle-rust:rust-best-practices skill (references/clippy-config.md)
  • [ ] Workspace-level lints configured in Cargo.toml ([workspace.lints.clippy] or [lints.clippy])
  • [ ] #[expect(clippy::lint)] used over #[allow(...)] — warns when suppression becomes stale
  • [ ] Justification comment present when suppressing any lint
  • [ ] Key lints enforced: redundant_clone, large_enum_variant, needless_collect, perf group
  • [ ] cargo clippy --all-targets --all-features -- -D warnings passes
  • [ ] Doc lints enabled for library crates (missing_docs, broken_intra_doc_links)

Type State Pattern

Detailed guidance: beagle-rust:rust-best-practices skill (references/type-state-pattern.md)
  • [ ] PhantomData<State> used for zero-cost compile-time state machines (not runtime enums/booleans)
  • [ ] State transitions consume self and return new state type (prevents reuse of old state)
  • [ ] Only applicable methods available per state (invalid operations are compile errors)
  • [ ] Pattern used where it adds safety value (builders with required fields, connection states, workflows)
  • [ ] Not overused for trivial state (simple enums are fine when runtime flexibility needed)

Severity Calibration

Critical (Block Merge)

  • unsafe code with unsound invariants or undefined behavior
  • Use-after-free or dangling reference patterns
  • unwrap() on user input or external data in production code
  • Data races (concurrent mutation without synchronization)
  • Memory leaks via circular Arc<Mutex<...>> without weak references

Major (Should Fix)

  • Errors returned without context (bare return err equivalent)
  • .clone() masking ownership design issues in hot paths
  • Missing Send/Sync bounds on types used across threads
  • panic! for recoverable errors in library code
  • Overly broad 'static lifetimes hiding API design issues

Minor (Consider Fixing)

  • Missing doc comments on public items
  • String parameter where &str or impl AsRef<str> would work
  • Derive macros missing for types that should have them
  • Unused feature flags in Cargo.toml
  • Suboptimal iterator chains (multiple allocations where one suffices)

Informational (Note Only)

  • Suggestions to introduce newtypes for domain modeling
  • Refactoring ideas for trait design
  • Performance optimizations without measured impact
  • Suggestions to add #[must_use] or #[non_exhaustive]

When to Load References

  • Reviewing ownership, borrows, lifetimes, clone traps → ownership-borrowing.md
  • Reviewing lifetime variance, covariance/invariance, multiple lifetime params → lifetime-variance.md
  • Reviewing Result/Option handling, error types, Error trait impls → error-handling.md
  • Reviewing async code, tokio usage, task management → async-concurrency.md
  • Reviewing Send/Sync, atomics, memory ordering, mutexes, lock patterns → concurrency-primitives.md
  • Reviewing type layout, alignment, repr, PhantomData, generics vs dyn → types-layout.md
  • Reviewing unsafe code, API design, derive macros, clippy patterns → common-mistakes.md
  • Reviewing safety contracts, raw pointers, MaybeUninit, soundness → unsafe-deep.md
  • Reviewing performance, pointer types, type state, generics, iterators, documentation → beagle-rust:rust-best-practices skill

Valid Patterns (Do NOT Flag)

These are acceptable Rust patterns — reporting them wastes developer time:

  • .clone() in tests — Clarity over performance in test code
  • unwrap() in tests and examples — Acceptable where panicking on failure is intentional
  • Box<dyn Error> in simple binaries — Not every application needs custom error types
  • String fields in structs — Owned data in structs is correct; &str fields require lifetime parameters
  • #[allow(dead_code)] during development — Common during iteration
  • todo!() / unimplemented!() in new code — Valid placeholder during active development
  • .expect("reason") with clear message — Self-documenting and acceptable for invariants
  • **use super::* in test modules** — Standard pattern for #[cfg(test)] modules
  • Type aliases for complex typestype Result<T> = std::result::Result<T, MyError> is idiomatic
  • impl Trait in return position — Zero-cost abstraction, standard pattern
  • Turbofish syntaxcollect::<Vec<_>>() is idiomatic when type inference needs help
  • _ prefix for intentionally unused variables — Compiler convention
  • #[expect(clippy::...)] with justification — Self-cleaning lint suppression
  • Arc::clone(&arc) — Explicit Arc cloning is idiomatic and recommended
  • std::sync::Mutex for short critical sections in async — Tokio docs recommend this
  • for loops over iterators — When early exit or side effects are needed
  • async fn in trait definitions — Stable since 1.75; async-trait crate only needed for dyn Trait or pre-1.75 MSRV
  • LazyCell / LazyLock from std — Stable since 1.80; replaces once_cell and lazy_static for new code
  • + use<'a, T> precise capture syntax — Edition 2024 syntax for controlling RPIT lifetime capture

Context-Sensitive Rules

Only flag these issues when the specific conditions apply:

IssueFlag ONLY IF
Missing error contextError crosses module boundary without context
Unnecessary .clone()In hot path or repeated call, not test/setup code
Missing doc commentsItem is pub and not in a #[cfg(test)] module
unwrap() usageIn production code path, not test/example/provably-safe
Missing Send + SyncType is actually shared across thread/task boundaries
Overly broad lifetimeA shorter lifetime would work AND the API is public
Missing #[must_use]Function returns a value that callers commonly ignore
Stale #[allow] suppressionShould be #[expect] for self-cleaning lint management
Missing Copy deriveType is ≤24 bytes with all-Copy fields and used frequently
Edition 2024: ! type fallbackMatch on Result<T, !> or diverging expressions where () fallback was assumed — ! now falls back to ! not ()
Edition 2024: r#gen identifierCode uses gen as an identifier — must be r#gen in edition 2024 (reserved keyword)

Before Submitting Findings

Satisfy Gates § verification protocol (step 4). Load and follow beagle-rust:review-verification-protocol before reporting any issue.

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

71.09%
按下载量换算1,650

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills