serde-code-review — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited serde-code-review (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
derive, rc), format crates (serde_json, toml, bincode, etc.), and Rust edition (2024 has breaking changes affecting serde code)Serialize and Deserialize are derived appropriatelygen keyword, RPIT lifetime capture changes, never_type_fallbackRun in order. Do not write a finding until the step that applies has passed.
Cargo.toml (crate or workspace root) and can state Rust edition, serde / serde_derive features if non-default (derive, rc), and which format crates apply (serde_json, toml, bincode, etc.) for the code under review. Then apply edition-specific checklist items (e.g. gen, RPIT/never_type_fallback) only when that file supports them.[FILE:LINE] from the current tree for the struct/enum, Serialize/Deserialize impl, or attribute block in question (not from memory, docs-only, or another branch).flatten, custom impl, sqlx + serde alignment), you ran the matching checks from the review-verification-protocol skill (e.g. full type definition + serde attrs before “wrong representation”; confirmed edition in Cargo.toml before edition-2024-only findings). Then add the finding.Report findings as:
[FILE:LINE] ISSUE_TITLE
Severity: Critical | Major | Minor | Informational
Description of the issue and why it matters.| Issue Type | Reference |
|---|---|
| Derive patterns, attribute macros, field configuration | references/derive-patterns.md |
| Custom Serialize/Deserialize, format-specific issues | references/custom-serialization.md |
#[derive(Serialize, Deserialize)] on types that cross serialization boundaries#[derive(Debug)] alongside serde derives (debugging serialization issues)#[cfg_attr(feature = "serde", derive(Serialize, Deserialize))]#[expect(unused)] over #[allow(unused)] for serde-only fields (self-cleaning lint suppression, stable since 1.81)#[serde(rename_all = "...")] used consistently across the API#[serde(skip_serializing_if = "Option::is_none")] for optional fields (clean JSON output)#[serde(default)] for fields that should have fallback values during deserialization#[serde(rename = "...")] when Rust field names differ from wire format#[serde(flatten)] used judiciously (can cause key collisions)#[serde(deny_unknown_fields)] on types that need forward compatibilitygen — reserved keyword in edition 2024 (use r#gen or rename)#[derive(sqlx::Type)] enums use consistent representation with serderename_all) and sqlx (rename_all)gen (reserved keyword — use r#gen with #[serde(rename = "gen")] or choose a different name)Serialize/Deserialize impls returning impl Trait account for RPIT lifetime capture changes (all in-scope lifetimes captured by default; use + use<'a> for precise control)never_type_fallback — ! falls back to ! instead of (), which affects match exhaustiveness on Result<T, !> patternsPartialEq derived for types with round-trip testsf64 → i64 in JSON numbers)Decimal used for money/precision-sensitive values, not f64#[serde(rename)] causing API-breaking field name changes#[serde(flatten)] causing silent key collisionsf64 precision loss for monetary values)rename_all across related types (confusing API)skip_serializing_if causing null/empty noise in outputdeny_unknown_fields on types consumed by evolving APIs (breaks forward compatibility)gen without r#gen escape (edition 2024 compile failure)#[serde(default)] on required fields#[allow(unused)] instead of #[expect(unused)] for serde-only fields (prefer self-cleaning lint suppression)#[non_exhaustive] alongside serde for forward compatibilitygen fields in wire formatsComplete Gates (before reporting findings) above; gate 3 incorporates the review-verification-protocol skill for serde-related issue types.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.