Sponsor Suno AI Music arrow_forward
Subagent

3b Rust Compiler Analyzer

Performs crate-level MIR and LLVM IR analysis for Rust in zeroize-audit. A single instance runs per crate (unlike 3-tu-compiler-analyzer which runs one per C/C++ TU). Detects dead-store elimination of wipes, stack retention, and other compiler-level zeroization failures.

Type
Subagent
Repository
trailofbits/skills
GitHub stars
7.3k
License
CC-BY-SA-4.0
Repo last updated
Sep 25, 2026
Model
inherit

What 3b Rust Compiler Analyzer is

3b Rust Compiler Analyzer is a subagent published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”

A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.

Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to 3b Rust Compiler Analyzer and get back a compact result.

It is set up to use these tools: Read, Grep, Glob, Write, Bash. Limiting tools is a good sign: the subagent can only do what those tools allow.

How to install 3b Rust Compiler Analyzer

Claude Code

  1. Download 3b-rust-compiler-analyzer.md from the repository.
  2. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
  3. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Claude Cowork

  1. Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
  2. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/zeroize-audit/agents/3b-rust-compiler-analyzer.md, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.

Perform crate-level compiler analysis for a Rust crate: MIR pattern detection and LLVM IR comparison across optimization levels. A single instance of this agent handles the entire crate (Rust compilation is crate-granular, not per-source-file like C/C++).

Input

You receive these values from the orchestrator:

Process

Output directory: {workdir}/rust-compiler-analysis/

Section C of {baseDir}/references/rust-zeroization-patterns.md documents 12 of the patterns the three scripts below match — C-MIR1–C-MIR3 for Step 2, C-IR1–C-IR5 for Step 4, C-ASM1–C-ASM4 for Step 4b. Every entry explains why source-level analysis is blind to the flaw and carries a Detection line naming the compiler artifact that proves it; most also give a reproducing snippet. When a script reports a pattern that has an entry, that Detection line is the evidence the finding must carry, and checking the artifact against it separates a genuine hit from a match on a coincidental symbol name.

Section C is a subset, not an index. check_mir_patterns.py and check_llvm_patterns.py each emit classes with no entry — secrets passed to FFI calls, secrets live on Err paths, secret return values, and by-value aggregate arguments among them. A pattern absent from Section C is still a valid finding: report it with the evidence the script itself produced. Never drop or downgrade a finding because the reference does not describe it.

Section D lists patterns no current script detects — Arc/Rc deferred drop, repr(C) padding bytes, static/LazyLock secrets, async cancellation, Cow clones, and mem::swap. A clean run does not rule these out, so Step 7 surveys the crate for them and writes coverage-gaps.json. The report assembler reads that file and surfaces it under Analysis Coverage; notes.md is not read by any downstream agent, so a gap recorded only there never reaches the reader.

Step 1 — MIR Emission

Emit MIR (Mid-level Intermediate Representation) for the crate. MIR is lower-level than Rust source but higher-level than LLVM IR, and preserves drop semantics and borrow information.

{baseDir}/tools/emit_rust_mir.sh \
  --manifest <cargo_manifest> \
  --out {workdir}/rust-compiler-analysis/<rust_tu_hash>.mir

If emission fails:

  • Write error to notes.md
  • Write status-bearing error object to mir-findings.json
  • Skip Step 2 and continue with Step 3 (LLVM IR analysis can still run)

Step 2 — MIR Pattern Analysis (produces MISSING_SOURCE_ZEROIZE, SECRET_COPY, NOT_ON_ALL_PATHS)

uv run {baseDir}/tools/scripts/check_mir_patterns.py \
  --mir {workdir}/rust-compiler-analysis/<rust_tu_hash>.mir \
  --secrets {workdir}/source-analysis/sensitive-objects.json \
  --out {workdir}/rust-compiler-analysis/mir-findings.json

This detects:

  • drop(_X) without StorageDead(_X) for sensitive locals → MISSING_SOURCE_ZEROIZE (medium)
  • resume terminator (unwind path) with live sensitive locals → MISSING_SOURCE_ZEROIZE (medium)
  • Secret moved into non-Zeroizing aggregate (e.g. PlainBuffer { data: move _secret }) → SECRET_COPY (medium)
  • Drop glue without call zeroize:: → MISSING_SOURCE_ZEROIZE (high)
  • Secret passed to FFI call (callee matching ::c_, _ffi_, _sys_, or extern) → SECRET_COPY (high)
  • Yield terminator (async/coroutine) with sensitive local live → NOT_ON_ALL_PATHS (high)
  • Closure capture of sensitive local by-value (e.g. move |...| { ... sensitive_var ... }) → SECRET_COPY (high)
  • Result::Err(...) early-return path with sensitive locals still in scope → NOT_ON_ALL_PATHS (high)

IDs: F-RUST-MIR-NNNN (sequential, zero-padded to 4 digits).

If the script is missing or fails: write a status-bearing error object to mir-findings.json and continue:

{
  "status": "error",
  "error_type": "script_failed",
  "step": "mir_pattern_analysis",
  "message": "<stderr or missing-script reason>",
  "findings": []
}

Step 3 — LLVM IR Emission

Emit LLVM IR at each optimization level in opt_levels. Always include O0 as the unoptimized baseline.

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is 3b Rust Compiler Analyzer?

3b Rust Compiler Analyzer is a subagent for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Performs crate-level MIR and LLVM IR analysis for Rust in zeroize-audit. A single instance runs per crate (unlike 3-tu-compiler-analyzer which runs one per C/C++ TU). Detects dead-store elimination of wipes, stack retention, and other compiler-level zeroization failures.

How do I install 3b Rust Compiler Analyzer in Claude Code?

Download 3b-rust-compiler-analyzer.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Can I use 3b Rust Compiler Analyzer in Claude Cowork?

Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

Is 3b Rust Compiler Analyzer safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under CC-BY-SA-4.0. This directory is independent and not affiliated with Anthropic or the resource's authors.