Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .claude-plugin/marketplace.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,14 +6,14 @@
},
"metadata": {
"description": "Professional Rust development plugin: specialist agents with LSP integration, team orchestration, and peer-to-peer communication",
"version": "1.49.0"
"version": "1.50.0"
},
"plugins": [
{
"name": "rust-agents",
"source": "./rust-code",
"description": "Rust development agents and skills for Claude Code: 15 specialist agents (architect, developer, testing, performance, security, reviewer, CI/CD, debugger, critic, SDD, live-tester, tech-writer, researcher, architecture and security analysts), team-develop and team-debug agent-team orchestration, a read-only continuous-improvement cycle that also runs headless, Rust 1.89-1.99 API reference, handoff protocol, spec-driven development pipeline, and rust-analyzer LSP integration.",
"version": "1.49.0",
"version": "1.50.0",
"author": {
"name": "Andrei G",
"email": "andrei.g@my.com"
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ This repository contains plugins that extend Claude Code's capabilities with spe

### Rust Agents Plugin (`rust-code`)

[![Version](https://img.shields.io/badge/version-1.49.0-blue)](./rust-code)
[![Version](https://img.shields.io/badge/version-1.50.0-blue)](./rust-code)
[![License](https://img.shields.io/badge/license-MIT-green)](./rust-code/LICENSE)

A comprehensive collection of specialized Rust development agents covering the entire Rust development lifecycle.
Expand Down
2 changes: 1 addition & 1 deletion rust-code/.claude-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "rust-agents",
"version": "1.49.0",
"version": "1.50.0",
"description": "Rust development agents and skills for Claude Code: 15 specialist agents (architect, developer, testing, performance, security, reviewer, CI/CD, debugger, critic, SDD, live-tester, tech-writer, researcher, architecture and security analysts), team-develop and team-debug agent-team orchestration, a read-only continuous-improvement cycle that also runs headless, Rust 1.89-1.99 API reference, handoff protocol, spec-driven development pipeline, and rust-analyzer LSP integration.",
"author": {
"name": "Andrei G",
Expand Down
19 changes: 19 additions & 0 deletions rust-code/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,25 @@ All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## [1.50.0] - 2026-10-04

### Added

- `continuous-improvement`: unchanged-HEAD cycle mode, cycle-start sync, `head:` journal frontmatter, archive-aware numbering. (#13)
- `live-testing`: permanent `coverage-status.md` master table and process self-improvement loop. (#13)
- `research-protocol`: delta check on unchanged HEAD and dependency functionality coverage. (#13)
- `arch-inspect`: mandatory DRY, type-safety, modern-API, and MSRV checks every cycle. (#13)
- `research-protocol`: optional monthly CVE class sweep and competitor-gap analysis. (#13)
- `live-testing`: optional benchmark comparison and live drift gate. (#13)
- `security-audit`: optional scope structure (trust boundaries, accepted risks, sensitive assets). (#13)

### Changed

- CI skills and agents: literal `P0`-`P4` label required at issue creation. (#13)
- CI skills: spec and implementation issue filed in one pass; symptoms filed without a root cause. (#13)
- `security-audit`: P0 findings go to private reporting first when supported. (#13)
- `live-testing`: `Tested` coverage rows are re-verified when dependencies move. (#13)

## [1.49.0] - 2026-10-01

### Added
Expand Down
2 changes: 1 addition & 1 deletion rust-code/README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Rust Agents Plugin

[![Version](https://img.shields.io/badge/version-1.49.0-blue)](https://github.com/bug-ops/claude-plugins)
[![Version](https://img.shields.io/badge/version-1.50.0-blue)](https://github.com/bug-ops/claude-plugins)
[![License](https://img.shields.io/badge/license-MIT-green)](LICENSE)
[![Rust Edition](https://img.shields.io/badge/rust-Edition%202024-orange)](https://doc.rust-lang.org/edition-guide/rust-2024/)

Expand Down
2 changes: 1 addition & 1 deletion rust-code/agents/06-rust-code-reviewer.md
Original file line number Diff line number Diff line change
Expand Up @@ -195,7 +195,7 @@ Found during code review of PR #<number> / commit <sha>.
## Priority

<IMPORTANT / SUGGESTION / NITPICK>" \
--label "tech-debt" # or "bug", "enhancement" — whichever fits
--label "<P0-P4>,tech-debt" # priority label required; category may instead be "bug" or "enhancement"
```

Report the created issue URLs in your review summary so the author can reference them.
Expand Down
2 changes: 2 additions & 0 deletions rust-code/agents/14-rust-researcher.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,6 +52,8 @@ Follow the phase sequence from the `research-protocol` skill. Summary:

For P0–P2 bugs, enhancements, and all research findings: spawn the `sdd` agent first (`Agent(subagent_type: "rust-agents:sdd")`) to produce a spec before filing the issue. See the SDD integration protocol in the skill references.

Labeling, the unchanged-HEAD delta check, dependency functionality coverage, and the optional competitor-gap and CVE sweeps are defined in the `research-protocol` skill.

# Research Knowledge Base

Maintain these files in `.local/testing/`:
Expand Down
2 changes: 2 additions & 0 deletions rust-code/agents/15-rust-arch-analyst.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,4 +23,6 @@ You are not designing new architecture — you are auditing what exists. Every f

If the `Skill` tool is not available in your session, the skills listed in your frontmatter are already preloaded — continue with their content and do not treat the missing call as a failure.

The every-cycle checks (DRY, type safety, modern APIs, MSRV), unchanged-HEAD module selection, and issue labeling are defined in `arch-inspect`.

Before finishing: write handoff and return frontmatter per the handoff protocol.
2 changes: 2 additions & 0 deletions rust-code/agents/16-rust-security-analyst.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,4 +21,6 @@ You are not implementing security fixes — you are finding what is exploitable

If the `Skill` tool is not available in your session, the skills listed in your frontmatter are already preloaded — continue with their content and do not treat the missing call as a failure.

Unchanged-HEAD module selection, issue labeling, and the P0 private-reporting branch are defined in `security-audit`.

Before finishing: write handoff and return frontmatter per the handoff protocol, including the Security Review section from the audit protocol.
21 changes: 18 additions & 3 deletions rust-code/skills/arch-inspect/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,17 @@ The agent runs in the background; report its result when the task notification a

**Type safety is the primary defense against entire classes of bugs.** Every invariant expressible in the type system is a bug that cannot exist at runtime. Audit this first and treat violations as the highest priority findings.

## Every-Cycle Requirements

These checks run explicitly on every cycle, including cycles where HEAD is unchanged since the last audit. Never report zero findings by default; state what was checked.

- **DRY** — grep for duplicated logic and types (near-identical match arms, repeated validation, parallel structs for one shape) before concluding there are none.
- **Type safety** — re-check newtype coverage for ids and unit-bearing fields, and look for id-shaped fields added since the last audit; do not mark a standing gap as covered without re-checking.
- **Modern APIs** — use `rust-modern-apis` and cite the specific API and file/line where a newer stable API replaces a manual workaround.
- **MSRV impact** — for each modern-API finding, say whether the declared `rust-version` already covers it. If it needs a higher MSRV, say so in the finding: an MSRV bump is a breaking change and part of the fix's cost. File as `enhancement`, P3 or lower, unless the old pattern is a correctness or safety liability.

**Unchanged HEAD** — do not re-audit the subsystem you audited last. Read prior `journal/ci-*.md` entries (and `journal/archive/`) attributed to your role, pick the modules least recently audited or audited only superficially, and audit those. Record the modules covered in the handoff.

Gather evidence with the toolchain before reading by hand — the tools enumerate what a manual pass misses:

```bash
Expand Down Expand Up @@ -211,6 +222,8 @@ cargo tree --duplicates

**Swallowed errors** — `let _ = fallible()`, `.ok()` discarding a `Result`, or a `match` arm that logs nothing leave failures invisible. Every discarded error needs a log line or a justification comment.

**New work paths without spans** (optional, when the project requires tracing) — a newly added path that does meaningful work (I/O, network call, database query, CPU-heavy transform) and ships without a `tracing` span is invisible to trace analysis; file it as P3, or P2 on a hot path.

**No metrics on saturable resources** — connection pools, queues, and worker counts without gauges make capacity problems undiagnosable. Note absence for services; libraries may expose hooks instead.

---
Expand Down Expand Up @@ -241,12 +254,12 @@ For each finding, assess priority:
- **P2** — structural debt that multiplies as the codebase grows: DRY violations, missing type abstractions, untestable design, crate boundary violations, missing timeouts
- **P3** — maintainability and readability: API naming, comment quality, function length

File a GitHub issue for every P1 and P2 finding. Batch multiple P3 findings of the same kind into one issue:
File a GitHub issue for every P1 and P2 finding. Batch multiple P3 findings of the same kind into one issue. The literal priority label is set at creation (create the label first if missing; never use another priority scheme); finding symptoms count even without a proven root cause:

```bash
gh issue create \
--title "<concise title>" \
--label "architecture,code-quality" \
--label "<P1|P2|P3|P4>,architecture,code-quality" \
--body "$(cat <<'EOF'
## Finding
<description>
Expand Down Expand Up @@ -282,8 +295,10 @@ Write your handoff with an **Architecture Review** section:
## Architecture Review

### Summary
- Findings: <N total> (P1: N, P2: N, P3: N)
- Findings: <N total> (P1: N, P2: N, P3: N, P4: N)
- Issues filed: <links>
- Modules audited: <list; feeds least-recently-audited selection next cycle>
- Every-cycle checks: DRY <result> | type safety <result> | modern APIs <result> | MSRV <result>

### Findings by Category
| Category | Count | Top Issue |
Expand Down
40 changes: 37 additions & 3 deletions rust-code/skills/continuous-improvement/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ name: continuous-improvement
description: "Orchestrate a continuous improvement cycle: spawn rust-live-tester for live testing, rust-researcher for dependency monitoring and research, rust-arch-analyst for code quality and architecture review, and rust-security-analyst for vulnerability scanning. Read-only; aggregates findings into a cycle journal. Runs as an agent team when CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS=1, otherwise (including headless `claude -p`, /loop, /schedule) as background subagents."
when_to_use: "'run a CI cycle', 'continuous improvement', 'live-test the latest changes', 'monitor dependencies', 'audit architecture and security', 'what should we improve next'."
argument-hint: "[testing|research|dependencies|parity|arch|security|full]"
allowed-tools: Bash(printenv *), Bash(ls *), Bash(test *), Bash(echo *), Bash(grep *), Bash(sort *), Bash(tail *)
allowed-tools: Bash(printenv *), Bash(ls *), Bash(test *), Bash(echo *), Bash(grep *), Bash(sort *), Bash(tail *), Bash(dirname *), Bash(git rev-parse *)
---

# Continuous Improvement Orchestrator
Expand Down Expand Up @@ -32,6 +32,8 @@ Run a continuous improvement cycle for the current Rust project by coordinating
1. **NEVER modify source code** in this orchestrator session — delegate all execution to agents
2. **NEVER run live tests, research, or security scans directly** — spawn the appropriate agent
3. All spawned agents are read-only with respect to source code; they only write to `.local/`
4. CI sessions never fix anything: every finding, including a symptom without a known root cause, becomes an issue, and fixes run in a separate team session (`/rust-agents:team-develop`)
5. `.local/testing/` artifacts live under the **main repository root**, even when the cycle runs from a git worktree; handoffs stay in the current directory's `.local/handoff/`

## Project-Specific Rules

Expand All @@ -43,7 +45,7 @@ If the preflight shows `.claude/rules/continuous-improvement.md` as present, pas
- Task tools flag: !`printenv CLAUDE_CODE_ENABLE_TODO_TOOLS || echo unset`
- Cargo.toml: !`test -f Cargo.toml && echo present || echo missing`
- Project CI rules: !`test -f .claude/rules/continuous-improvement.md && echo present || echo absent`
- Last cycle journal: !`ls .local/testing/journal/ 2>/dev/null | grep -E '^ci-[0-9]{3}\.md$' | sort | tail -1 | grep . || echo none`
- Last cycle journal: !`ls "$(dirname "$(git rev-parse --path-format=absolute --git-common-dir)")/.local/testing/journal/" "$(dirname "$(git rev-parse --path-format=absolute --git-common-dir)")/.local/testing/journal/archive/" 2>/dev/null | grep -E '^ci-[0-9]{3}\.md$' | sort | tail -1 | grep . || echo none`

STOP if Cargo.toml is `missing`.

Expand All @@ -67,7 +69,23 @@ ToolSearch("select:TaskCreate,TaskUpdate,TaskList,TaskGet")

If the Task tools are not found: Claude Code 2.1.233+ omits them on current models unless `CLAUDE_CODE_ENABLE_TODO_TOOLS=1` is set (e.g. in the `env` block of `settings.json`). Tell the user, then continue in **message-based fallback**: skip every TaskCreate/TaskUpdate call in this workflow, drop the Task Management section from the spawn template, and track each agent's completion by its handoff message.

Determine the next cycle number from the preflight "Last cycle journal" value: `none` means `001`; otherwise increment by one. Create `.local/testing/journal/` if it does not exist.
Determine the next cycle number from the preflight "Last cycle journal" value (it resolves the main repository root and covers `journal/archive/`): `none` means `001`; otherwise increment by one. Create `.local/testing/journal/` under the main repository root if it does not exist. A legacy `coverage.md` or `journal.md` is migrated by `rust-live-tester` per the [Testing Methodology](references/testing-methodology.md#coverage-status-file).

### Cycle start

Before spawning, sync and decide the cycle mode:

1. `git pull origin main` (or the project's default branch) and read the new commits.
2. Record `git rev-parse HEAD` as `{head}` and read the previous HEAD from the last journal's `head:` frontmatter or the last handoff.
3. Equal HEADs mean **unchanged-HEAD mode**: the cycle is never skipped. Pass the mode and both SHAs to every agent in its prompt.

| Role | Unchanged-HEAD behavior |
|---|---|
| `rust-live-tester` | Tests the stalest `Untested`/`Partial` rows and `Tested` rows whose dependencies moved |
| `rust-arch-analyst`, `rust-security-analyst` | Audit the modules least recently covered, found in prior `journal/ci-*.md` entries by that role |
| `rust-researcher` | Delta check only |

A re-verification with zero findings is a valid cycle outcome.

### Agent outcomes

Expand All @@ -85,6 +103,7 @@ Create `.local/testing/journal/ci-NNN.md`:
---
cycle: NNN
date: YYYY-MM-DD
head: <git sha>
focus: <focus>
team: <team-name>
---
Expand Down Expand Up @@ -151,9 +170,13 @@ You are operating as a teammate in this session's CI cycle team.
2. TaskUpdate(status: "in_progress") when starting
3. TaskUpdate(status: "completed") when done

## Cycle Mode
HEAD: {changed|unchanged} (previous {previous-sha}, current {head}). Follow the Unchanged HEAD rules in your protocol when unchanged; never skip the cycle.

## Journal
Append each finding as a new row in the Findings table of `{journal-path}`:
`| N | <type> | <title> | <P0-P4> | #<issue> | <spec-path or —> |`
Record the issue number and the spec path of a finding together in the same row. Follow the Priority Label rules of your protocol.

## Communication
- Send results to the lead: SendMessage(to: "team-lead", message: "...", summary: "...")
Expand Down Expand Up @@ -226,6 +249,7 @@ Agent({

Run a full architecture and code quality audit of this project.
This is a READ-ONLY analysis pass — do NOT modify source files. Use the audit checklist in your agent definition.
Explicitly cover DRY, type safety, modern APIs (rust-modern-apis) and MSRV impact every cycle, including unchanged-HEAD cycles; do not report zero findings by default.
Project-specific rules: <paste .claude/rules/continuous-improvement.md if it exists, else omit>
Write your handoff with an Architecture Review section listing all findings and filed issue URLs."
})
Expand Down Expand Up @@ -292,9 +316,19 @@ Aggregate results from agent messages and complete the remaining sections of `{j
- Issues filed: <links>
- Top security risk: <one-sentence summary; note if immediate rotation/patch is required>

### Process Retrospective

- <methodology only: what worked, what failed and is dropped, techniques to promote to a playbook — appended to `.local/testing/process-notes.md`>

### Next Cycle Priorities

- <top 3 items based on Findings table>
```

Then close the cycle (the orchestrator touches only `.local/` and issue labels, never source code):

1. Append the retrospective to `.local/testing/process-notes.md` per the [Process Self-Improvement Loop](references/testing-methodology.md#process-self-improvement-loop).
2. If a bug category recurs three or more times across cycle journals, list it under Next Cycle Priorities and file one `testing-infra` issue yourself proposing a structural fix or automated regression test. After the agents finish, the orchestrator is the single permitted filer.
3. Run the label spot-check from [Issue Management](references/issue-management.md#priority-label-mandatory); the orchestrator may add a missing `P0`-`P4` label with `gh issue edit`.

Print `{journal-path}` to the console so the user can locate the cycle record.
Loading
Loading