← 返回 Skills 市场
82
总下载
0
收藏
1
当前安装
1
版本数
在 OpenClaw 中安装
/install nm-pensive-rust-review
功能描述
Rust code audit: unsafe blocks, ownership patterns, and Cargo dependency security scanning
安全使用建议
This skill appears to be a coherent Rust code-audit instruction pack, but check two things before installing: (1) confirm why it requires the config paths night-market.pensive:shared and night-market.imbue:proof-of-work — ask the publisher what data those configs contain and whether they grant access to unrelated settings, and (2) ensure your environment has the expected local tools (cargo, cargo-audit, cargo-outdated, cargo-deny) because the SKILL.md expects running those commands even though no binaries are declared. Also be cautious about installing the separate 'Claude Code' plugin the README mentions—treat that as a separate component to vet because it may add hooks or networked features.
功能分析
Type: OpenClaw Skill
Name: nm-pensive-rust-review
Version: 1.0.0
The skill bundle is a comprehensive Rust code audit tool designed to assist an AI agent in reviewing ownership patterns, concurrency, unsafe blocks, and security vulnerabilities. It provides detailed modules for identifying anti-patterns like SQL injection (modules/sql-injection.md), improper error handling (modules/error-handling.md), and inefficient collection usage (modules/collection-types.md). The inclusion of shell commands for cargo auditing (modules/cargo-dependencies.md) is consistent with its stated purpose of dependency security scanning.
能力标签
能力评估
Purpose & Capability
The name, description, and modules align with a Rust audit (ownership, unsafe, dependency scanning). However the SKILL.md expects running cargo commands (cargo audit/tree/outdated) and a CLI-style invocation (/rust-review) yet the registry metadata lists no required binaries — a small mismatch. Also the declared required config paths (night-market.pensive:shared, night-market.imbue:proof-of-work) are not explained by the audit purpose and look unrelated.
Instruction Scope
Runtime instructions focus on code review steps (ownership, unsafe, concurrency, cargo audits) and recommend running local cargo tools and recording an evidence log. They do not instruct reading unrelated system files or contacting external endpoints; the scope stays within reviewing source and running local tooling.
Install Mechanism
This is instruction-only with no install spec and no code files to write to disk, which is the lowest-risk install mechanism. The SKILL.md mentions (optionally) an external 'Claude Code' plugin for additional features, which would be a separate install and should be inspected separately.
Credentials
No environment variables or credentials are requested (good), but the two required config paths (night-market.pensive:shared and night-market.imbue:proof-of-work) are unexpected for a Rust code auditor and are not justified in the documentation. The 'proof-of-work' config name in particular is opaque and may indicate access to unrelated agent configuration — ask what those configs contain and why they're required.
Persistence & Privilege
The skill does not request always:true and is user-invocable (normal). It does not declare modifications to other skills or system-wide settings. Autonomous invocation is allowed by default but is not combined here with broad credentials or always:true.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install nm-pensive-rust-review - 安装完成后,直接呼叫该 Skill 的名称或使用
/nm-pensive-rust-review触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
- Initial release of rust-review skill for Rust code audits.
- Provides expert-level review focusing on unsafe blocks, ownership patterns, and dependency security.
- Includes detailed workflow and checklist for safety, correctness, performance, and idiomatic Rust patterns.
- Supports modular, progressive review (ownership, error handling, concurrency, unsafe, dependencies).
- Output format specified for clear audit reporting and recommendations.
- Special requirements: relies on "night-market.pensive:shared" and "night-market.imbue:proof-of-work" configuration.
元数据
常见问题
Nm Pensive Rust Review 是什么?
Rust code audit: unsafe blocks, ownership patterns, and Cargo dependency security scanning. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 82 次。
如何安装 Nm Pensive Rust Review?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install nm-pensive-rust-review」即可一键安装,无需额外配置。
Nm Pensive Rust Review 是免费的吗?
是的,Nm Pensive Rust Review 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
Nm Pensive Rust Review 支持哪些平台?
Nm Pensive Rust Review 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Nm Pensive Rust Review?
由 athola(@athola)开发并维护,当前版本 v1.0.0。
推荐 Skills