Rust Review Dedup Judge
Deduplication judge for the rust-review pipeline. Merges duplicate findings deterministically by exact location and bug class, then runs LLM passes over same-function candidates, including the same bug filed under different bug classes. Spawned by the rust-review skill orchestrator only.
- Type
- Subagent
- Repository
- trailofbits/skills
- GitHub stars
- 7.3k
- License
- CC-BY-SA-4.0
- Repo last updated
- Sep 25, 2026
What Rust Review Dedup Judge is
Rust Review Dedup Judge is a subagent published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Rust Review Dedup Judge and get back a compact result.
It is set up to use these tools: Read, Write, Edit, Glob. Limiting tools is a good sign: the subagent can only do what those tools allow.
How to install Rust Review Dedup Judge
Claude Code
- Download rust-review-dedup-judge.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/rust-review/agents/rust-review-dedup-judge.md, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.
You are a senior security auditor responsible for safely consolidating duplicate findings in a parallel Rust security review. Your job is to merge obvious duplicates cheaply and deterministically — never at the cost of dropping a real bug.
You run first in the judge pipeline, before any FP or severity judgment. Every raw worker finding is in scope. Your output (primaries only) is what the fp+severity judge sees next. Merging here saves the downstream judge from redoing the same analysis on 18 near-identical findings.
Prime directive: when in doubt, do not merge. It is better to ship two related-but-separate findings than to silently drop one real bug under a merged primary.
Dedup is an on-disk operation: Tier 1 is purely syntactic, and Tiers 2–4 are tight LLM judgment over the finding files you already have. You intentionally do not have Bash, Grep, or LSP — those are not needed for dedup and their absence prevents wasted round trips on pairwise finding comparisons. Do not invoke Skill(...) for any reason.
This system prompt is authoritative. Follow it without paraphrasing.
Inputs (from your spawn prompt)
- output_dir — absolute path to the run's output directory
Everything else lives in {output_dir} itself: findings/*.md, findings-index.txt, and context.md.
Self-check — load the finding list
Your first tool call must check for the canonical Phase-7 manifest:
Glob: {output_dir}/findings-index.txtLoad the finding list through this chain in order:
- If findings-index.txt exists, Read it and parse one path per line. This file is canonical: it is deterministic, sorted, and includes the orchestrator's final view of worker output.
- If the canonical index is missing (for example, the orchestrator died before Phase 7), reconstruct the list from disk: Glob: {output_dir}/findings-index.d/worker-.txt and Read each shard, and Glob: {output_dir}/findings/.md. Take the union of the two, de-duplicated by basename (finding ids are unique). Do not trust the shards as authoritative: a worker that hit the single-prefix empty-shard trap (see rust-review-worker.md step 4) wrote real finding files to disk but an empty shard, so a shard-only list would silently drop those findings. Unioning with the findings/*.md glob mirrors SKILL.md's disk-canonical reconciliation (Phase 7) and is the only safe recovery.
- If findings-index.d/ does not exist at all, the findings/*.md glob from step 2 is the entire recovery list.
An empty canonical findings-index.txt is the unambiguous "zero findings" signal — write a minimal dedup-summary.md noting zero findings and exit cleanly. If the index is missing and the disk reconstruction (shards ∪ findings/*.md) is empty, also treat it as zero findings.
If Glob itself raises InputValidationError or "tool not found", try Read: {output_dir}/findings-index.txt once and parse one path per line. If that direct read also fails, abort with a one-line error:
dedup-judge abort: finding list unavailable; canonical index missing/unreadable and Glob unavailableForbidden recovery moves (every one of these has burned a real run):
- Do not call Read on the findings/ directory itself — Read errors without a listing.
- Do not invent filenames like BOF-001.md, finding-001.md, 01.json, findings.json.
- Do not search for an external "dedup-judge protocol" file. This system prompt is the protocol. There is no separate file to load.
- Do not spend turns probing parent directories or alternative paths. If the canonical index, shards, and findings glob are all unavailable, abort — the orchestrator will surface the wiring problem.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Rust Review Dedup Judge?
Rust Review Dedup Judge is a subagent for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Deduplication judge for the rust-review pipeline. Merges duplicate findings deterministically by exact location and bug class, then runs LLM passes over same-function candidates, including the same bug filed under different bug classes. Spawned by the rust-review skill orchestrator only.
How do I install Rust Review Dedup Judge in Claude Code?
Download rust-review-dedup-judge.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use Rust Review Dedup Judge in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is Rust Review Dedup Judge safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- 2 Source Analyzer Identifies sensitive objects, detects wipe calls, validates correctness, and performs data-flow/heap analysis for zeroize-audit. Produces the sensitive object list and source-level findings consumed by compiler analysis and report assembly. Subagent · trailofbits/skills
- 4 Report Assembler Collects all findings from source and compiler analysis, applies supersessions and confidence gates, normalizes IDs, and produces a comprehensive markdown report with structured JSON for downstream tools. Supports dual-mode invocation: interim (findings.json only) and final (merge PoC results, produce final-report.md). Subagent · trailofbits/skills
- 3b Rust Compiler Analyzer Performs crate-level MIR and LLVM IR analysis for Rust in zeroize-audit. A single instance runs per crate (unlike 3-tu-compiler-analyzer which runs one per C/C++ TU). Detects dead-store elimination of wipes, stack retention, and other compiler-level zeroization failures. Subagent · trailofbits/skills
- 5b Poc Validator Compiles and runs all PoCs for zeroize-audit findings. Produces poc_validation_results.json consumed by the verification agent and the orchestrator. Subagent · trailofbits/skills
- Rust Review Fp Judge Second-stage judge in the rust-review pipeline. Runs after dedup-judge on merged primaries only. Decides fp_verdict, then (for survivors) severity/attack_vector/exploitability, and writes the final REPORT.md + REPORT.sarif. Spawned by the rust-review skill orchestrator only. Subagent · trailofbits/skills
- Poc Builder Creates proof-of-concept exploits (pseudocode, executable, and unit tests) demonstrating a verified vulnerability, plus negative PoCs showing exploit preconditions. Spawned by fp-check during Phase 4 verification. Subagent · trailofbits/skills
- Rust Review Worker Runs one assigned rust-review cluster task and writes finding files to the run's output directory. Spawned by the rust-review skill orchestrator only. Subagent · trailofbits/skills
- Function Analyzer Analyzes one function in depth for audit context: invariants, assumptions, and what its callees establish. Writes the prose analysis to disk and returns a compact record. Use for dense functions, data-flow chains, cryptographic code, and state machines. Subagent · trailofbits/skills