bxc Rust FFI Bridge

A Rust-to-Bun bridge for the bxc project, using a compiled native library and a C-compatible interface. Bun is a JavaScript runtime, while FFI lets code in one language call functions written in another.

In plain words
What is it for?
Use it when changing rust-bridge code, Rust crates, Bun integrations, SQLite workspace settings, exported functions, or release builds.
Why use it?
It documents the constraints needed to build and call the Rust code reliably, including shared SQLite dependencies, asynchronous work, errors, and platform-specific libraries.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/aphrody-code/bxc/bxc-rust-ffi
Any agent
npx skills add aphrody-code/bxc --skill bxc-rust-ffi
Clone the repo
git clone --depth 1 https://github.com/aphrody-code/bxc

Made for: Claude Code, Codex.

Per session 108 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 872 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00108 $0.00872
Opus 5 $0.00054 $0.00436
Sonnet 5 $0.00022 $0.00174
Haiku 4.5 $0.00011 $0.00087

Measured 2d ago against content hash 32ed57145be5, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

bxc Rust FFI Bridge scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/bxc/skills/bxc-rust-ffi/SKILL.md · 55 lines

How it starts

The opening of the file, as written. The whole thing — 55 lines — stays where its author put it; the contents beside it link to each section on GitHub.

bxc Rust FFI (cdylib for Bun)

The hot path of bxc lives in Rust, exposed to Bun via cdylib + N-API style FFI (or raw extern "C" with bun:ffi or manual).

Crate Layout (in rust-bridge/)

  • bxc-rust-bridge (the cdylib crate exporting bxc_* symbols)
  • crates/x-client (native X GraphQL/REST + rusqlite store + ranking helpers)
  • crates/x-algorithm (pure Rust port of xai-org/x-algorithm For You ranking, used via FFI or re-exported)

Critical Rules

  • Single rusqlite: libsqlite3-sys "links" = "sqlite3". Only one version of rusqlite (0.37) can be linked in the cdylib. All crates in the workspace must use { workspace = true } for rusqlite.
  • Workspace Cargo.toml: Define [workspace.dependencies] rusqlite = { version = "0.37", features = ["bundled"] } etc. Use in member crates.
  • no_mangle + extern "C": For symbols called from Bun (or via the bridge lib).
  • Async in FFI: Use tokio::runtime::Builder::new_current_thread().enable_all().build().unwrap().block_on(...) inside the extern "C" fn. Never leak runtimes.
  • Error handling: Return *mut c_char (JSON or null). Caller frees with CString.
  • Build: cargo build -p bxc-rust-bridge --release (or via bun run build:linux). Output in rust-bridge/target/release/libbxc_rust_bridge.{so,dylib,dll}

Cross-Platform Notes

  • Linux: .so (default target)
  • macOS: .dylib (x86_64-apple-darwin + aarch64-apple-darwin for universal if needed)
  • Windows: .dll (x86_64-pc-windows-msvc). Also produce .exe for standalone tools.
  • In Bun code: use dlopen with platform-specific name or process.platform + process.arch to pick the right file. Provide BXC_RUST_BRIDGE_LIB override.

Common FFI Pattern (from bxc)

#[no_mangle]
pub extern "C" fn bxc_x_algorithm_rank(
    candidates_json: *const c_char,
    context_json: *const c_char,
    top_k: i32,
) -> *mut c_char {
    // parse with serde, call pure algo, return CString::new(json).unwrap().into_raw()
}

Bun side lazily dlopen the lib on first use; falls back to pure JS for some paths (title, stripTags, markdown) if cdylib missing.

Read the full file on GitHub · 55 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 55 lines · 108 tokens per session scan A 32ed57145be5

Subscribe to this mod's changes

bxc Rust FFI Bridge is a skill published in the GitHub repository aphrody-code/bxc (2 stars, last pushed 2d ago), licensed Apache-2.0. It adds 108 tokens to every session and 872 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

using-claude-cli

How to drive claude (Claude Code) as a non-interactive CLI tool — headless runs, MCP servers, permissions, output formats, and piping. Use when scripting Claude, spawning a sub-agent from another process, or wiring Claude into CI/automation.

developerz-ai/ui-debugger-mcp · 61 tokens

obscura

Operate and validate Obscura for JavaScript page loading, stealth browsing, anti-fingerprinting, tracker blocking, screenshots and visual comparison, CDP automation with Puppeteer or Playwright, screencasting, PDF export, MCP browser interaction, and web extraction. Use when running Obscura against deterministic…

h4ckf0r0day/obscura · 100 tokens

pinchtab

Use this skill when a task needs browser automation through PinchTab: open a website, inspect interactive elements, click through flows, fill out forms, scrape page text, reuse a dedicated automation profile with user approval, export screenshots or PDFs, manage multiple browser instances, or fall back to the HTTP API…

pinchtab/pinchtab · 94 tokens

pinchtab-mcp

Use this skill when a task requires browser automation through PinchTab's MCP server connected to a remote browser instance. Covers navigation, element interaction, data extraction, form filling, multi-step flows, and session management via MCP tools.

pinchtab/pinchtab · 52 tokens

pinchtab-stealth-score

Run the PinchTab stealth-score sweep against 15 bot-detection / fingerprint sites (sannysoft, rebrowser, deviceandbrowserinfo, iphey, whoer, browserscan, pixelscan, fingerprint-scan, incolumitas, fvision, amiunique, browserleaks, creepjs, coveryourtracks, fingerprint-demo). Starts a Docker PinchTab container per…

pinchtab/pinchtab · 168 tokens

pinchtab-dev

Develop and contribute to the PinchTab project. Use when working on PinchTab source code, adding features, fixing bugs, running tests, or preparing PRs. Triggers on "work on pinchtab", "pinchtab development", "contribute to pinchtab", "fix pinchtab bug", "add pinchtab feature".

pinchtab/pinchtab · 77 tokens