rust

A set of guidelines for Rust, a programming language focused on memory safety and speed. It covers ownership, error handling, asynchronous work, data formats, web frameworks, and project structure.

In plain words
What is it for?
Use it when building Rust applications or web services with Tokio, serde, Axum or Actix-web, structured errors, and integration tests.
Why use it?
It provides consistent patterns for handling failures, organizing code, and choosing common Rust libraries.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/renvia-code/best-cursor-rules/rust
Clone the repo
git clone --depth 1 https://github.com/Renvia-code/best-cursor-rules
Per session 0 Nothing until a file matches its globs; then the whole rule loads.
When invoked 2,270 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.02270
Opus 5 $0.00000 $0.01135
Sonnet 5 $0.00000 $0.00454
Haiku 4.5 $0.00000 $0.00227

Measured 2d ago against content hash 01053bdd9b98, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

rust scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

rules/languages/rust.mdc · 426 lines

How it starts

The opening of the file, as written. The whole thing — 426 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Rust Best Practices

Overview

Aspect Recommendation
Edition Rust 2021
Error Handling Result with ? operator
Async Runtime Tokio
Serialization serde
Web Framework Axum or Actix-web

Project Structure

src/
├── main.rs              # Binary entry point
├── lib.rs               # Library root
├── config.rs            # Configuration
├── error.rs             # Error types
├── models/
│   ├── mod.rs
│   └── user.rs
├── handlers/            # Route handlers
│   ├── mod.rs
│   └── users.rs
├── services/            # Business logic
│   ├── mod.rs
│   └── user_service.rs
└── db/
    ├── mod.rs
    └── repository.rs
tests/
├── integration_test.rs
Cargo.toml

Error Handling

Custom Error Type

// src/error.rs
use axum::{
    http::StatusCode,
    response::{IntoResponse, Response},
    Json,
};
use serde_json::json;

#[derive(Debug)]
pub enum AppError {
    NotFound(String),
    BadRequest(String),
    Internal(String),
    Unauthorized,
}

impl IntoResponse for AppError {
    fn into_response(self) -> Response {
        let (status, message) = match self {
            Self::NotFound(msg) => (StatusCode::NOT_FOUND, msg),
            Self::BadRequest(msg) => (StatusCode::BAD_REQUEST, msg),
            Self::Internal(msg) => (StatusCode::INTERNAL_SERVER_ERROR, msg),
            Self::Unauthorized => (StatusCode::UNAUTHORIZED, "Unauthorized".into()),
        };

        (status, Json(json!({ "error": message }))).into_response()
    }
}

// Convert from other error types
impl From<sqlx::Error> for AppError {
    fn from(err: sqlx::Error) -> Self {
        match err {
            sqlx::Error::RowNotFound => Self::NotFound("Resource not found".into()),
            _ => Self::Internal(err.to_string()),
        }
    }
}

pub type Result<T> = std::result::Result<T, AppError>;

Using Result

// ✅ Good - Use ? operator
fn parse_config(path: &str) -> Result<Config, ConfigError> {
    let content = std::fs::read_to_string(path)?;
    let config: Config = serde_json::from_str(&content)?;
    Ok(config)
}

// ✅ Good - Early return pattern
fn process_user(id: u32) -> Result<User, AppError> {
    let user = find_user(id).ok_or(AppError::NotFound("User not found".into()))?;
    
    if !user.is_active {
        return Err(AppError::BadRequest("User is inactive".into()));
    }
    
    Ok(user)
}

// ❌ Bad - Unwrap in production code
fn bad_example() {
    let value = risky_operation().unwrap(); // Don't do this
}

Read the full file on GitHub · 426 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 426 lines · 0 tokens per session scan A 01053bdd9b98

Subscribe to this mod's changes

rust is a cursor rule published in the GitHub repository Renvia-code/best-cursor-rules (12 stars, last pushed 9mo ago), licensed CC0-1.0. It costs nothing until one of its globs matches a file; then it loads 2,270 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.