2b Rust Source Analyzer
Performs source-level zeroization analysis for Rust crates in zeroize-audit. Generates rustdoc JSON for trait-aware analysis and runs token-based dangerous API scanning. Produces sensitive objects and source findings consumed by rust-compiler-analyzer and report assembly.
- Type
- Subagent
- Repository
- trailofbits/skills
- GitHub stars
- 7.3k
- License
- CC-BY-SA-4.0
- Repo last updated
- Sep 25, 2026
- Model
- inherit
What 2b Rust Source Analyzer is
2b Rust Source Analyzer is a subagent published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to 2b Rust Source Analyzer and get back a compact result.
It is set up to use these tools: Read, Grep, Glob, Write, Bash. Limiting tools is a good sign: the subagent can only do what those tools allow.
How to install 2b Rust Source Analyzer
Claude Code
- Download 2b-rust-source-analyzer.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/zeroize-audit/agents/2b-rust-source-analyzer.md, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.
Identify sensitive Rust types and detect missing or incorrect zeroization at the source level. Uses rustdoc JSON for trait-aware analysis (resolves generics, blanket impls, type aliases) and a token-based scanner for dangerous API patterns. Produces source findings that drive crate-level compiler analysis.
Input
You receive these values from the orchestrator:
Process
Step 1 — Generate Rustdoc JSON
Generate the rustdoc JSON file for the crate. This provides trait implementation data, derive macros, and type information needed for semantic analysis.
cargo +nightly rustdoc \
--manifest-path <cargo_manifest> \
--document-private-items -- \
-Z unstable-options --output-format jsonThe output is written to /target/doc/ .json. Find it with:
find <rust_crate_root>/target/doc -name "*.json" -not -name "search-index*.json" | head -1If cargo +nightly rustdoc fails: write an error note and skip to Step 3 (dangerous API scan can still run without rustdoc JSON).
Step 2 — Semantic Audit (Rustdoc JSON)
Run the trait-aware semantic auditor:
uv run {baseDir}/tools/scripts/semantic_audit.py \
--rustdoc <rustdoc_json_path> \
--cargo-toml <cargo_manifest> \
--out {workdir}/source-analysis/rust-semantic-findings.jsonThis detects:
- #[derive(Copy)] on sensitive types → SECRET_COPY (critical)
- No Zeroize/ZeroizeOnDrop/Drop → MISSING_SOURCE_ZEROIZE (high)
- Zeroize without auto-trigger → MISSING_SOURCE_ZEROIZE (high)
- Partial Drop impl → PARTIAL_WIPE (high)
- ZeroizeOnDrop with heap fields → PARTIAL_WIPE (medium)
- Clone on zeroizing type → SECRET_COPY (medium)
- From/Into returning non-zeroizing type → SECRET_COPY (medium)
- Source file containing ptr::write_bytes and no compiler_fence(...) call → OPTIMIZED_AWAY_ZEROIZE (medium, needs_review)
- #[cfg(feature=...)] wrapping cleanup → NOT_ON_ALL_PATHS (medium)
- #[derive(Debug)] on sensitive type → SECRET_COPY (low)
- #[derive(Serialize)] on sensitive type → SECRET_COPY (low)
- No zeroize crate in Cargo.toml → MISSING_SOURCE_ZEROIZE (low)
Section A of {baseDir}/references/rust-zeroization-patterns.md documents most of these as A1–A12, each with a minimal reproducing snippet and the recommended fix. Read the entry for a pattern before writing its finding detail, and use its snippet to judge how closely the flagged type matches.
Never drop or downgrade a finding because it reads as a poor match for the entry. A weak match is a needs_review finding whose evidence says how the code differs from the entry, not an omission: Step 5 combines both arrays in full, and a finding left out here is unrecoverable from any artifact the run produces.
The mapping is not one-to-one. The missing-zeroize-dependency check has no Section A entry, and A6 (a ManuallyDrop struct field) covers a pattern the list above does not name. Where a check has no entry, write the detail and the fix from that check's own output — borrowing a neighbouring entry's snippet produces a finding that describes the wrong flaw.
If the script is missing or fails: write a status-bearing error object to the output file and continue:
{
"status": "error",
"error_type": "script_failed",
"step": "semantic_audit",
"message": "<stderr or missing-script reason>",
"findings": []
}Step 3 — Dangerous API Scan
Run the token/grep-based scanner across all .rs source files:
uv run {baseDir}/tools/scripts/find_dangerous_apis.py \
--src <rust_crate_root>/src \
--out {workdir}/source-analysis/rust-dangerous-api-findings.jsonThis detects:
- mem::forget → MISSING_SOURCE_ZEROIZE (critical)
- ManuallyDrop::new → MISSING_SOURCE_ZEROIZE (critical)
- Box::leak → MISSING_SOURCE_ZEROIZE (critical)
- mem::uninitialized → MISSING_SOURCE_ZEROIZE (critical)
- Box::into_raw → MISSING_SOURCE_ZEROIZE (high)
- ptr::write_bytes → OPTIMIZED_AWAY_ZEROIZE (high)
- mem::transmute → SECRET_COPY (high)
- slice::from_raw_parts → SECRET_COPY (medium)
- mem::take → MISSING_SOURCE_ZEROIZE (medium)
- async fn with secret-named local + .await → NOT_ON_ALL_PATHS (high)
Section B of {baseDir}/references/rust-zeroization-patterns.md covers these as B1–B10. Each entry explains why the API defeats zeroization, which matters here because this scanner is token-based: it cannot tell mem::take used to steal a secret from mem::take used on an unrelated buffer.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is 2b Rust Source Analyzer?
2b Rust Source Analyzer is a subagent for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Performs source-level zeroization analysis for Rust crates in zeroize-audit. Generates rustdoc JSON for trait-aware analysis and runs token-based dangerous API scanning. Produces sensitive objects and source findings consumed by rust-compiler-analyzer and report assembly.
How do I install 2b Rust Source Analyzer in Claude Code?
Download 2b-rust-source-analyzer.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use 2b Rust Source Analyzer in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is 2b Rust Source Analyzer safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- 4 Report Assembler Collects all findings from source and compiler analysis, applies supersessions and confidence gates, normalizes IDs, and produces a comprehensive markdown report with structured JSON for downstream tools. Supports dual-mode invocation: interim (findings.json only) and final (merge PoC results, produce final-report.md). Subagent · trailofbits/skills
- 3b Rust Compiler Analyzer Performs crate-level MIR and LLVM IR analysis for Rust in zeroize-audit. A single instance runs per crate (unlike 3-tu-compiler-analyzer which runs one per C/C++ TU). Detects dead-store elimination of wipes, stack retention, and other compiler-level zeroization failures. Subagent · trailofbits/skills
- 5b Poc Validator Compiles and runs all PoCs for zeroize-audit findings. Produces poc_validation_results.json consumed by the verification agent and the orchestrator. Subagent · trailofbits/skills
- 5c Poc Verifier Verifies that each zeroize-audit PoC actually proves the vulnerability it claims to demonstrate. Reads PoC source code, finding details, and original source to check alignment between the PoC and the finding. Produces poc_verification.json consumed by the orchestrator. Subagent · trailofbits/skills
- 3 Tu Compiler Analyzer Performs per-TU compiler-level analysis (IR diff, assembly, semantic IR, CFG) for zeroize-audit. One instance runs per translation unit, enabling parallel execution across TUs. Subagent · trailofbits/skills
- 2 Source Analyzer Identifies sensitive objects, detects wipe calls, validates correctness, and performs data-flow/heap analysis for zeroize-audit. Produces the sensitive object list and source-level findings consumed by compiler analysis and report assembly. Subagent · trailofbits/skills
- 1 Mcp Resolver Resolves symbol definitions, types, and cross-file references using Serena MCP for zeroize-audit. Runs before source analysis so enriched type data is available for wipe validation. Subagent · trailofbits/skills
- 0 Preflight Performs preflight validation, config merging, TU enumeration, and work directory setup for zeroize-audit. Produces merged-config.yaml, preflight.json, and orchestrator-state.json. Subagent · trailofbits/skills