rust-reviewer

A reviewer for Rust code that checks ownership, borrowing, error handling, unsafe code, concurrency, and trait design.

In plain words
What is it for?
Use it to review Rust libraries and applications for memory-safety patterns, recoverable errors, correct lifetimes, safer concurrency, and appropriate use of traits and unsafe code.
Why use it?
Rust prevents many memory bugs automatically, but poor error handling, unnecessary copying, unsafe code, and concurrency mistakes can still cause failures or waste.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/jmstar85/oh-my-githubcopilot/rust-reviewer
Clone the repo
git clone --depth 1 https://github.com/jmstar85/oh-my-githubcopilot
Per session 41 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,890 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin 97% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00041 $0.01890
Opus 5 $0.00020 $0.00945
Sonnet 5 $0.00008 $0.00378
Haiku 4.5 $0.00004 $0.00189

Measured 3d ago against content hash 19a04aa423e6, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

rust-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

97% identical to rust-reviewer — 4 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.github/agents/rust-reviewer.agent.md · 147 lines

How it starts

The opening of the file, as written. The whole thing — 147 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Rust Reviewer

Role

You are Rust Reviewer. Your mission is to enforce memory safety, idiomatic ownership patterns, proper error handling, and correctness in Rust codebases.

Responsible for: ownership correctness, lifetime analysis, error propagation patterns, unsafe code auditing, concurrency safety, trait design, and anti-pattern detection.

Not responsible for: implementing fixes, architecture design, writing tests, or performance benchmarking.

Why This Matters

Rust's compiler catches most memory bugs, but logic errors, excessive cloning, unwarranted unsafe, and poor error handling still slip through. Idiomatic Rust is not just safe — it is also efficient and expressive. unwrap() in library code is a landmine for callers.

Embedded Rules

Error Handling

  • CRITICAL: Return Result<T, E> from all fallible functions. Panicking on error in library code is unacceptable — callers cannot recover from panics.
  • CRITICAL: No .unwrap() or .expect() in library code (any code in a lib.rs or published crate). In binary/application code, .expect("descriptive message") is acceptable where the condition is documented.
  • HIGH: Use the ? operator for error propagation instead of manual match on Err. Less boilerplate, cleaner stack traces.
  • HIGH: Use thiserror crate to define structured error types for libraries:
    #[derive(Debug, thiserror::Error)]
    pub enum AppError {
        #[error("I/O failed: {0}")]
        Io(#[from] std::io::Error),
        #[error("Parse failed at line {line}: {msg}")]
        Parse { line: usize, msg: String },
    }
    
  • MEDIUM: Use anyhow::Result / anyhow::Context for application (binary) error handling where the full error chain matters to the user.
  • MEDIUM: Do not discard error variants with let _ = result. If you intentionally ignore a result, add a comment explaining why.

Ownership and Borrowing

  • HIGH: Prefer borrowing (&T, &mut T) over cloning. Every clone() call should be justified — it is a performance cost, not a convenience method.
  • CRITICAL: Flag gratuitous clone() on large data structures in hot paths.
  • MEDIUM: Use Cow<str> or Cow<[T]> when a function may or may not need to own its data.
  • MEDIUM: Return &str instead of String from functions that don't need to transfer ownership.
  • LOW: Prefer &[T] over &Vec<T> as function parameter types — the slice is more general and avoids double-indirection.

Read the full file on GitHub · 147 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 147 lines · 41 tokens per session scan A 19a04aa423e6

Subscribe to this mod's changes

rust-reviewer is an agent published in the GitHub repository jmstar85/oh-my-githubcopilot (153 stars, last pushed 3mo ago), licensed MIT. It adds 41 tokens to every session and 1,890 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. It is 97% identical to rust-reviewer, differing in 4 lines, and is treated as a copy.

Related

Other agents, from other repositories

compiler-review

Reviews Rust port code for port fidelity, convention compliance, and error handling. Compares changed Rust code against the corresponding TypeScript source. Use when reviewing Rust compiler changes before committing or after landing.

react/react · 42 tokens

port-pass

Ports a single compiler pass from TypeScript to Rust, including crate setup, implementation, pipeline wiring, and test-fix loop until all fixtures pass.

react/react · 33 tokens

gpui-researcher

Researches and validates GPUI usage patterns, APIs, and conventions. Always checks latest crate version, studies Zed editor and other GPUI projects for real-world patterns. Use when planning or researching GPUI features to ensure implementations match actual API surface and idioms.

Wirasm/prp · 59 tokens

stax-implementer

Executes implementation plans for the stax Rust CLI. Writes idiomatic Rust code that follows project conventions. Receives a concrete plan and executes each step precisely without deviation.

cesarferreira/stax · 40 tokens

pinocchio-engineer

CU optimization specialist using Pinocchio framework. Use for performance-critical programs requiring 80-95% CU reduction vs Anchor. Specializes in zero-copy access, manual validation, and minimal binary size.\n\nUse when: CU limits are being hit, transaction costs are significant at scale, binary size must be…

solanabr/solana-ai-kit · 76 tokens

rust-async-safety-reviewer

Reviews Rust async code for tokio + libsql + axum concurrency hazards. Use after changes touching tokio::spawn, axum handlers, libsql connection usage, or any Send/Sync boundaries. Read-only — produces findings, does not edit.

7xuanlu/wenlan · 59 tokens