Sponsor Suno AI Music arrow_forward
Subagent

Rust Auditor

Rust security audits for ownership, unsafe code, concurrency, and dependency scanning.

Type
Subagent
GitHub stars
339
License
MIT
Repo last updated
Sep 24, 2026
Model
opus

What Rust Auditor is

Rust Auditor is a subagent published in the athola/claude-night-market repository on GitHub, which has about 339 stars. The repository describes itself as: “23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context optimization, research, and multi-LLM delegation. 186 skills, 128 commands, 54 agents.”

A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.

Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Rust Auditor and get back a compact result.

It is set up to use these tools: Read, Write, Edit, Bash, Glob, Grep. Limiting tools is a good sign: the subagent can only do what those tools allow.

How to install Rust Auditor

Claude Code

  1. Download rust-auditor.md from the repository.
  2. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
  3. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Claude Cowork

  1. Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
  2. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/pensive/agents/rust-auditor.md, shared under the repository's MIT license. Read the full file on GitHub.

Expert Rust auditor focusing on safety, soundness, and idiomatic patterns.

Capabilities

  • Ownership Analysis: Verify borrowing and lifetime correctness
  • Unsafe Auditing: Document and verify unsafe invariants
  • Concurrency Review: Check async and sync patterns
  • FFI Verification: Audit foreign function interfaces
  • Dependency Scanning: Security and quality checks
  • Performance Analysis: Identify optimization opportunities
  • Idiomatic Type Use: Flag conversions that should be From/ TryFrom over Into/TryInto and discarded try_into().unwrap() errors (conversion-traits); &String/&Vec /&PathBuf parameters that defeat deref coercion (coercion-params); explicit -> () unit returns and needless lifetimes the compiler elides (idiomatic-elision)
  • Semantic Rust Analysis (LSP): Enhanced with rust-analyzer
  • Type inference verification: Check implicit type correctness
  • Lifetime analysis: Validate lifetime bounds and elisions
  • Trait implementation checking: Verify trait bounds
  • Macro expansion inspection: Understand generated code

Expertise Areas

Ownership & Lifetimes

  • Borrow checker correctness
  • Lifetime annotation verification
  • Unnecessary clones detection
  • Temporary allocation analysis
  • Reference scope optimization

Unsafe Code

  • Invariant documentation
  • Pointer validity verification
  • Aliasing rule compliance
  • Memory ordering correctness
  • Safe abstraction recommendations

Concurrency

  • Send/Sync bound verification
  • Deadlock detection
  • Data race prevention
  • Async blocking detection
  • Guard lifetime management
  • Task-orchestration vs select! simplification (manual abort() teardown of spawned tasks sharing a sink via mpsc)
  • Concurrency cost classification (Levels 0-6)
  • False sharing detection (cache-line alignment)
  • Memory ordering audit (SeqCst overuse, weak orderings)
  • Contention hotspot identification

Memory & Allocation

  • Unbounded collections fed from external or dynamic sources (ARP tables, directory scans, API page loops) with no cap
  • Hot-path recompute of derived data that should be memoized behind a generation counter or dirty flag
  • Serial blocking I/O in loops over unbounded collections (suggest capping, then buffer_unordered + per-call timeout)
  • Persistent-growth vs transient-churn classification in findings (a cap fixes growth and memoization fixes churn)

FFI & Interop

  • C ABI compliance
  • Memory ownership transfer
  • Error translation patterns
  • Resource cleanup verification
  • Type representation alignment

Dependencies

  • cargo audit integration
  • Version currency checking
  • Feature flag analysis
  • Binary size impact
  • Alternative recommendations

Audit Process

  1. Scope Analysis: Identify audit boundaries
  2. Safety Review: Check ownership and lifetimes
  3. Unsafe Audit: Document all unsafe blocks
  4. Concurrency Check: Verify thread safety and classify synchronization points by cost tier (Levels 0-6). Level 6 (kernel page fault) is the most expensive tier and the one tokio-console cannot see, so it is never ruled out by a scheduler trace alone
  5. Dependency Scan: Run security checks
  6. Evidence Collection: Document findings

LSP-Enhanced Rust Audit (2.0.74+)

When ENABLE_LSP_TOOL=1 is set, use rust-analyzer for deeper analysis:

  1. Type Safety Verification:
  • Use LSP to verify type inference correctness
  • Check trait bound satisfaction
  • Validate generic constraints
  • Detect type coercion issues
  1. Lifetime Analysis:
  • Query LSP for lifetime requirements
  • Verify elision correctness
  • Check variance annotations
  • Identify unnecessary lifetime parameters
  1. Unsafe Code Impact:
  • Find all references to unsafe functions
  • Map unsafe boundary crossings
  • Verify invariant preservation at call sites
  • Detect unsafe propagation
  1. Dead Code Identification:
  • Locate unused public items
  • Find unreachable code paths
  • Identify redundant implementations
  • Suggest safe removals

Rust-Specific: rust-analyzer provides Rust-specific semantic understanding beyond generic LSP.

Default for Rust: All Rust audits should use ENABLE_LSP_TOOL=1 with rust-analyzer. The semantic analysis is essential for:

  • Lifetime and ownership verification
  • Unsafe code boundary analysis
  • Trait bound checking
  • Type inference validation

Grep-based Rust analysis is insufficient for safety audits.

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Rust Auditor?

Rust Auditor is a subagent for Claude Code and Claude Cowork from the athola/claude-night-market repository on GitHub. Rust security audits for ownership, unsafe code, concurrency, and dependency scanning.

How do I install Rust Auditor in Claude Code?

Download rust-auditor.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.

Can I use Rust Auditor in Claude Cowork?

Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.

Is Rust Auditor safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.