Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Setup Rust Pre Commit

ASecurity

Set up fast pre-commit hooks for a Rust repo — format and lint the staged changes only, with CI left as the real gate.

2 stars
0 votes
0 copies
0 views
Added 9/19/2026
developmentpythonrustgoshellbashgit

Works with

cli

Security Analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned 9/19/2026

$npx -y skills add rewrite-rs/skills --skill setup-rust-pre-commit --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Setup Rust Pre Commit?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Setup Rust Pre Commit
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/rewrite-rs-setup-rust-pre-commit/badge)](https://www.skillsdirectory.com/skills/rewrite-rs-setup-rust-pre-commit)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: setup-rust-pre-commit
description: Set up fast pre-commit hooks for a Rust repo — format and lint the staged changes only, with CI left as the real gate.
disable-model-invocation: true
---

# Setup Rust Pre-commit

A pre-commit hook is a convenience, never a gate. CI is the gate: it runs on every
push whether or not a local hook ever fired. A hook that tries to be the gate gets
slow, and a slow hook gets bypassed with `--no-verify` within a week — at which
point the repo has neither a hook nor the honesty of admitting it. Like
`/setup-rust-ci`, this skill runs only when the user invokes it — a hook executes
on someone's behalf at every commit, and the model never decides that on its own.

## The one rule, stated first

A hook that takes longer than about two seconds will be bypassed. Everything else
in this skill follows from that: format and lint, never test; staged files, never
the workspace; report and stop, never fix silently.

## Ask which mechanism before writing anything

Three, and the choice is the user's:

| Mechanism | Fits when | Costs |
|---|---|---|
| `core.hooksPath` script | Rust-only repo, no other hook needs | Each contributor runs one `git config` line; nothing enforces that they did |
| `lefthook` | Mixed repo, wants parallel hooks, no Python | One binary dependency |
| `pre-commit` | The repo already uses it for other languages | Python toolchain, and the Rust hooks shell out to cargo anyway |

Detect what is already there — an existing `.pre-commit-config.yaml`,
`lefthook.yml`, or `core.hooksPath` setting — and match it rather than introducing
a second mechanism. The complete files for all three, ready to paste, are in
`HOOKS.md`.

## What goes in the hook, and what never does

In: `cargo fmt` on the staged Rust files, and `cargo clippy` at the configured
level. Out: `cargo test` (too slow, and a broken test is what CI exists to
report), `cargo build --release`, and anything network-bound such as
`cargo audit` — those belong on a schedule, and `/rust-supply-chain` covers them.

The level is not a flag the hook adds. Read the recorded posture from
`docs/agents/rust.md`, exactly as `/setup-rust-ci` does — including the clippy
command it records, at the level configured in `Cargo.toml` — and if the file
is absent, say so and offer to run `/setup-rust-skills` first; do not guess a
level and bake the guess into a hook. The hook then runs clippy with no level
flag added, because clippy applies the repo `[lints]` configuration on its own.
A hook stricter than CI fails commits CI would pass, which is the single most
effective way to get a hook uninstalled. The `-D warnings` flag belongs only in
the fallback form — a repo with no lint configuration at all — and nowhere else.

## Staged-only is the difference between two seconds and thirty

The file list comes from what the user actually staged:

    git diff --cached --name-only --diff-filter=ACM -- '*.rs'

The warning worth stating plainly: `cargo clippy` cannot be scoped to files. It
works per crate, so a workspace hook should lint only the crates containing staged
files — and a repo where even that is still slow should drop clippy from the hook
and keep `fmt`. The hook that survives is the one the repo keeps trusting.

## Formatting: report or rewrite, and say which

Two defensible designs. `cargo fmt --check` fails and makes the user format;
`cargo fmt` rewrites the files and re-stages them. Rewriting silently changes what
the user is about to commit, so if the repo picks it, the hook must print every
file it touched. Never rewrite without printing. Say in the contributing notes
which design the repo uses, so a newcomer is not ambushed by a hook that edits a
staged file. The rewrite variant, written out, is in `HOOKS.md`.

## Document the bypass in the same breath as the hook

`git commit --no-verify` exists, and contributors will need it — a
work-in-progress commit on a branch, an emergency fix. A hook presented as
unbypassable is a hook people route around resentfully. Write the bypass into the
repo contributing notes next to the setup line: what the hook runs, how to install
it, and that `--no-verify` is available and legitimate. The block to paste is in
`HOOKS.md`.

## Verification

Prove the hook both fires and passes — a hook nobody has seen reject anything is
not known to work:

```bash
# 1. install it, then deliberately break formatting
printf 'fn  main( ) {}\n' > /tmp/hook-probe.rs && cp /tmp/hook-probe.rs src/hook_probe.rs
git add src/hook_probe.rs
git commit -m "probe: hook must reject this"   # expected: rejected, naming the file
git restore --staged src/hook_probe.rs && rm src/hook_probe.rs
# the reset in step 2 is only valid because step 1 was rejected — if that commit landed, fix the install before step 2
# 2. confirm a clean commit still passes, and time it
time git commit --allow-empty -m "probe: hook must allow this"
git reset HEAD~1
```

Report the measured time. Over two seconds, cut the hook down rather than shipping
it.

Attribution

rewrite-rsrewrite-rs
View sourceSee grades on GitHubMore from rewrite-rs →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Clean Code

Pragmatic coding standards - concise, direct, no over-engineering, no unnecessary comments

304955 votes

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

285172 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2222 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Tanstack Start

Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per ...

10341 votes
View all in development →