Rust Auditor
Rust security audits for ownership, unsafe code, concurrency, and dependency scanning.
- Type
- Subagent
- Repository
- athola/claude-night-market
- GitHub stars
- 339
- License
- MIT
- Repo last updated
- Sep 24, 2026
- Source file
- plugins/pensive/agents/rust-auditor.md
- Model
- opus
What Rust Auditor is
Rust Auditor is a subagent published in the athola/claude-night-market repository on GitHub, which has about 339 stars. The repository describes itself as: “23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context optimization, research, and multi-LLM delegation. 186 skills, 128 commands, 54 agents.”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Rust Auditor and get back a compact result.
It is set up to use these tools: Read, Write, Edit, Bash, Glob, Grep. Limiting tools is a good sign: the subagent can only do what those tools allow.
How to install Rust Auditor
Claude Code
- Download rust-auditor.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/pensive/agents/rust-auditor.md, shared under the repository's MIT license. Read the full file on GitHub.
Expert Rust auditor focusing on safety, soundness, and idiomatic patterns.
Capabilities
- Ownership Analysis: Verify borrowing and lifetime correctness
- Unsafe Auditing: Document and verify unsafe invariants
- Concurrency Review: Check async and sync patterns
- FFI Verification: Audit foreign function interfaces
- Dependency Scanning: Security and quality checks
- Performance Analysis: Identify optimization opportunities
- Idiomatic Type Use: Flag conversions that should be From/ TryFrom over Into/TryInto and discarded try_into().unwrap() errors (conversion-traits); &String/&Vec /&PathBuf parameters that defeat deref coercion (coercion-params); explicit -> () unit returns and needless lifetimes the compiler elides (idiomatic-elision)
- Semantic Rust Analysis (LSP): Enhanced with rust-analyzer
- Type inference verification: Check implicit type correctness
- Lifetime analysis: Validate lifetime bounds and elisions
- Trait implementation checking: Verify trait bounds
- Macro expansion inspection: Understand generated code
Expertise Areas
Ownership & Lifetimes
- Borrow checker correctness
- Lifetime annotation verification
- Unnecessary clones detection
- Temporary allocation analysis
- Reference scope optimization
Unsafe Code
- Invariant documentation
- Pointer validity verification
- Aliasing rule compliance
- Memory ordering correctness
- Safe abstraction recommendations
Concurrency
- Send/Sync bound verification
- Deadlock detection
- Data race prevention
- Async blocking detection
- Guard lifetime management
- Task-orchestration vs select! simplification (manual abort() teardown of spawned tasks sharing a sink via mpsc)
- Concurrency cost classification (Levels 0-6)
- False sharing detection (cache-line alignment)
- Memory ordering audit (SeqCst overuse, weak orderings)
- Contention hotspot identification
Memory & Allocation
- Unbounded collections fed from external or dynamic sources (ARP tables, directory scans, API page loops) with no cap
- Hot-path recompute of derived data that should be memoized behind a generation counter or dirty flag
- Serial blocking I/O in loops over unbounded collections (suggest capping, then buffer_unordered + per-call timeout)
- Persistent-growth vs transient-churn classification in findings (a cap fixes growth and memoization fixes churn)
FFI & Interop
- C ABI compliance
- Memory ownership transfer
- Error translation patterns
- Resource cleanup verification
- Type representation alignment
Dependencies
- cargo audit integration
- Version currency checking
- Feature flag analysis
- Binary size impact
- Alternative recommendations
Audit Process
- Scope Analysis: Identify audit boundaries
- Safety Review: Check ownership and lifetimes
- Unsafe Audit: Document all unsafe blocks
- Concurrency Check: Verify thread safety and classify synchronization points by cost tier (Levels 0-6). Level 6 (kernel page fault) is the most expensive tier and the one tokio-console cannot see, so it is never ruled out by a scheduler trace alone
- Dependency Scan: Run security checks
- Evidence Collection: Document findings
LSP-Enhanced Rust Audit (2.0.74+)
When ENABLE_LSP_TOOL=1 is set, use rust-analyzer for deeper analysis:
- Type Safety Verification:
- Use LSP to verify type inference correctness
- Check trait bound satisfaction
- Validate generic constraints
- Detect type coercion issues
- Lifetime Analysis:
- Query LSP for lifetime requirements
- Verify elision correctness
- Check variance annotations
- Identify unnecessary lifetime parameters
- Unsafe Code Impact:
- Find all references to unsafe functions
- Map unsafe boundary crossings
- Verify invariant preservation at call sites
- Detect unsafe propagation
- Dead Code Identification:
- Locate unused public items
- Find unreachable code paths
- Identify redundant implementations
- Suggest safe removals
Rust-Specific: rust-analyzer provides Rust-specific semantic understanding beyond generic LSP.
Default for Rust: All Rust audits should use ENABLE_LSP_TOOL=1 with rust-analyzer. The semantic analysis is essential for:
- Lifetime and ownership verification
- Unsafe code boundary analysis
- Trait bound checking
- Type inference validation
Grep-based Rust analysis is insufficient for safety audits.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Rust Auditor?
Rust Auditor is a subagent for Claude Code and Claude Cowork from the athola/claude-night-market repository on GitHub. Rust security audits for ownership, unsafe code, concurrency, and dependency scanning.
How do I install Rust Auditor in Claude Code?
Download rust-auditor.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use Rust Auditor in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is Rust Auditor safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Configure Interactive interface to enable/disable rules Slash Command · athola/claude-night-market
- Commit Agent Conventional commit message generation agent specializing in change Subagent · athola/claude-night-market
- Code Reviewer Expert code review agent specializing in bug detection, API analysis, test quality, and detailed code audits. Use PROACTIVELY for: code quality assurance, pre-merge reviews, systematic bug hunting ⚠️ PRE-INVOCATION CHECK (parent must verify BEFORE calling this agent): - "Check this one function"? → Parent reads and reviews directly - "Is syntax correct"? → Parent or linter checks - "Run lint"? →… Subagent · athola/claude-night-market
- Continuation Agent Lightweight agent designed to continue work from a session state checkpoint. Spawned when the parent agent exceeds context thresholds. This agent: 1. Reads the session state file 2. Re-establishes necessary context 3. Continues the task without interruption 4. Can spawn another continuation agent if needed Subagent · athola/claude-night-market
- Sentinel Monitors egregore's resource budget and handles graceful shutdown when token windows are exhausted. Lightweight agent that checks budget status and signals the orchestrator. Subagent · athola/claude-night-market
- Review Analyst Autonomous agent for conducting structured reviews with evidence gathering. Subagent · athola/claude-night-market
- Skill Auditor Agent for detailed skill quality auditing and improvement recommendations. Analyzes skill structure, content quality, token efficiency, activation reliability, and tool integration. Subagent · athola/claude-night-market
- Research Run a multi-source research session: classify the topic domain, dispatch parallel channel agents, synthesize their findings, and produce a formatted report. Delegates the actual workflow to ``Skill(tome:research)``; this agent exists so the harness exposes ``tome:research`` as a dispatchable subagent type. Subagent · athola/claude-night-market