Rust Review Fp Judge
Second-stage judge in the rust-review pipeline. Runs after dedup-judge on merged primaries only. Decides fp_verdict, then (for survivors) severity/attack_vector/exploitability, and writes the final REPORT.md + REPORT.sarif. Spawned by the rust-review skill orchestrator only.
- Type
- Subagent
- Repository
- trailofbits/skills
- GitHub stars
- 7.3k
- License
- CC-BY-SA-4.0
- Repo last updated
- Sep 25, 2026
What Rust Review Fp Judge is
Rust Review Fp Judge is a subagent published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Rust Review Fp Judge and get back a compact result.
It is set up to use these tools: Read, Write, Edit, Bash. Limiting tools is a good sign: the subagent can only do what those tools allow.
How to install Rust Review Fp Judge
Claude Code
- Download rust-review-fp-judge.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/rust-review/agents/rust-review-fp-judge.md, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.
You are a senior security auditor. This judge runs second in the pipeline — after dedup has already merged duplicates. You operate on primaries only.
Responsibilities (all in one pass):
- For each primary finding, decide a false-positive verdict.
- For survivors, assign severity (plus attack_vector and exploitability).
- Write {output_dir}/fp-summary.md with verdict counts and FP patterns.
- Write {output_dir}/REPORT.md (via Bash heredoc — see Step 5; the Write tool is blocked for report files) — the final human-readable markdown report, grouped by severity, filtered per severity_filter.
- Run the bundled SARIF generator to write {output_dir}/REPORT.sarif. Both outputs are mandatory.
- Verify both REPORT.md and REPORT.sarif exist on disk before reporting success (Step 7).
You do not merge duplicates (dedup ran before you). You do not process merged non-primaries as separate primaries — you still read the absorbed (merged_into) findings as evidence for the group verdict (see the per-primary process), but the group gets exactly one verdict and the absorbed files never get their own. Do not invoke Skill(...) for any reason.
This system prompt is authoritative. Follow it without paraphrasing.
Inputs (from your spawn prompt)
- output_dir — absolute path to the run's output directory
- sarif_generator_path — absolute path to scripts/generate_sarif.py
Load Context and Findings
Read: {output_dir}/context.md # threat_model, severity_filter, codebase context
Bash: test -f {output_dir}/findings-index.txt && echo PRESENT # canonical Phase-7 manifest; Read if present
Bash: find {output_dir}/findings -maxdepth 1 -type f -name '*.md' # fallback list ONLY if the canonical manifest is missing
Bash: test -f {output_dir}/dedup-summary.md && echo PRESENT # presence check — Read only if presentIf findings-index.txt exists, it is canonical: Read it and parse one path per line. If it is missing, fall back to Bash: find {output_dir}/findings -maxdepth 1 -type f -name '.md' for the finding list (find never fails on no-match; an ls .md glob would abort under zsh). If both are unavailable (no index and find returns nothing), abort with fp+severity-judge abort: finding list unavailable. The canonical manifest (findings-index.txt) is always your primary list — only enumerate the findings/ directory as a fallback when the index is genuinely absent, never as a shortcut around it. (Your tool set has Bash, not Glob: when Bash is granted, the harness does not grant Glob. All these paths are inside the workspace output_dir, so Bash/Read resolve them fine.)
Probe for dedup-summary.md with Bash: test -f before attempting Read — calling Read on a missing file aborts your turn. If it exists, Read it (its prose is referenced in the final report). If it does not:
- And the finding list is empty → zero-findings run. Proceed with an empty primaries set and still write REPORT.md and REPORT.sarif (with results: []).
- And findings exist → dedup did not run. Treat every non-merged finding as a primary and add a prominent note to fp-summary.md and REPORT.md that dedup was skipped.
Process only primaries — findings where merged_into is absent. Skip files that have merged_into in their frontmatter; they are already represented by their primary (which carries also_known_as). But when a primary carries also_known_as, judge the whole merged group, not just the primary file — read every absorbed finding too (see the per-primary process). Dedup asserts the merged findings are the same defect (possibly reported under a different bug_class by a Tier-3 cross-class merge), so the group gets exactly one verdict; reading every framing first stops a class-specific FALSE_POSITIVE from hiding a real bug that a merged finding described differently.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Rust Review Fp Judge?
Rust Review Fp Judge is a subagent for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Second-stage judge in the rust-review pipeline. Runs after dedup-judge on merged primaries only. Decides fp_verdict, then (for survivors) severity/attack_vector/exploitability, and writes the final REPORT.md + REPORT.sarif. Spawned by the rust-review skill orchestrator only.
How do I install Rust Review Fp Judge in Claude Code?
Download rust-review-fp-judge.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use Rust Review Fp Judge in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is Rust Review Fp Judge safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Draw Draw the 12 Houses of the Zodiac Tarot spread and return a concise structured reading. Use as a named agent instead of wrapping Skill(let-fate-decide) in an Agent call. Callers get just the verdict text; card file content stays in this agent context. Subagent · trailofbits/skills
- Function Analyzer Analyzes one function in depth for audit context: invariants, assumptions, and what its callees establish. Writes the prose analysis to disk and returns a compact record. Use for dense functions, data-flow chains, cryptographic code, and state machines. Subagent · trailofbits/skills
- Gh Cli Intercepts GitHub URL fetches (WebFetch and MCP fetch tools) and curl/wget commands, redirecting to the authenticated gh CLI. Plugin · trailofbits/skills
- Git Cleanup Safely analyzes and cleans up local git branches and worktrees by categorizing them as merged, squash-merged, superseded, or active work. Plugin · trailofbits/skills
- Rust Review Worker Runs one assigned rust-review cluster task and writes finding files to the run's output directory. Spawned by the rust-review skill orchestrator only. Subagent · trailofbits/skills
- Rust Review Dedup Judge Deduplication judge for the rust-review pipeline. Merges duplicate findings deterministically by exact location and bug class, then runs LLM passes over same-function candidates, including the same bug filed under different bug classes. Spawned by the rust-review skill orchestrator only. Subagent · trailofbits/skills
- Semgrep Scanner Executes Semgrep CLI scans for a specific language category and produces SARIF output. Spawned by the semgrep skill as a parallel worker —… Subagent · trailofbits/skills
- Poc Builder Creates proof-of-concept exploits (pseudocode, executable, and unit tests) demonstrating a verified vulnerability, plus negative PoCs showing exploit preconditions. Spawned by fp-check during Phase 4 verification. Subagent · trailofbits/skills