
Security News
pnpm 12’s Rust Rewrite Cuts Install Times by Up to 90%
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.
opencode-rust-coder
Advanced tools
Rust correctness tools, rust-analyzer navigation, safe edit plans, and version-pinned docs for OpenCode V2.
Türkçe | English
An OpenCode V2 plugin that helps coding agents produce correct, idiomatic Rust. It structures Cargo diagnostics, adds rust-analyzer navigation, produces write-free rename/refactor plans, verifies crates, and reads version-pinned Rust API documentation.
| Start here | Contents |
|---|---|
| Tool and Configuration Reference | Every rust.* input, output bound, visibility rule, write behavior, automatic feature, option default/range, and troubleshooting path |
| Benchmark Reference | Controlled A/B preflight, fixtures, scoring, cache/workspace isolation, metrics, artifacts, measured results, cost limits, and deterministic validation |
| Architecture | Plugin hooks, Rust engagement, two-clock gate, LSP lifecycle, identity, scheduling, and build acceleration |
| Rust Guidance Research | Evidence behind ownership, dependency, async, and acceleration decisions |
| Validation Implementation Plan | Validation invariants, rollout stages, and acceptance design |
Use this README for installation and the supported surface. Use the references above for exact contracts and evidence boundaries.
The latest stable release is 0.3.0.
| Surface | Verified release |
|---|---|
| npm | opencode-rust-coder@0.3.0 |
| GitHub | v0.3.0 |
Release 0.3.0 adds evidence-efficient validation orchestration: schedule-only
passive automation, centralized evidence and workspace preflight, complete-or-
inconclusive input identity, compact rustc diagnostics with verified write-free
suggestions, source-first documentation lookup, bounded privacy retention, and
free bilingual cold/warm ablation evidence. Affected-scope execution remains in
shadow mode and runtime impact-capsule injection remains disabled until stronger
evidence exists.
cargo check, test, Clippy, and format feedback.FAST_PASS feedback and authoritative
FULL_PASS only after format, Clippy, all targets, and applicable doctests.MachineApplicable, write-free
suggestion packages; compact check output is the default.timings=true reports; no linker, cache
wrapper, compiler backend, or Cargo configuration is auto-enabled.FULL_PASS, which requires explicit rust.check target=all on this host.@opencode-ai/plugin@0.0.0-beta-18050 target.rust-analyzer for semantic rust.* tools. Resolution order is the explicit
rustAnalyzerPath, PATH, then ~/.cargo/bin/rust-analyzer.1.3.14 for repository development and release checks.Install the exact current release globally:
opencode2 plugin add opencode-rust-coder@0.3.0
opencode2 plugin list
plugin add updates the global OpenCode V2 configuration. Exact versions stay
pinned. Configuration-directory changes reload automatically; if an existing
server does not reflect the changed package, use opencode2 service restart as
a troubleshooting step.
To pass options, replace the string entry in
~/.config/opencode/opencode.jsonc with the object form:
{
"$schema": "https://opencode.ai/config.json",
"plugins": [
{
"package": "opencode-rust-coder@0.3.0",
"options": {
"autoGate": true,
"autoCrateCheck": true,
"autoAudit": true,
"autoLsp": false,
"toolInvites": true,
"maxTokens": 900,
"gateResponseMs": 30000,
"gateHostConcurrency": 1,
"gateCacheMode": "auto",
"gateScopeMode": "shadow",
"tools": {
"check": true,
"audit": true,
"crate": true,
"hints": true,
"lsp": true,
"rename": true,
"refactor": true,
"docs": true
}
}
}
]
}
The shown values are the defaults. autoLsp is intentionally opt-in. Use
toolchainPath or rustAnalyzerPath only when normal executable discovery is
not sufficient. See the
full configuration table
for every option, accepted range, nested tool gate, and interaction.
The plugin does not create or replace an agent. In a Rust workspace it injects
one compact core workflow, exposes rust.check by default, and opens audit,
dependency/docs, or semantic tools only when the task text calls for them. The
full opencode-rust-coder runtime skill remains registered for explicit use but
is not advertised automatically, avoiding a mandatory skill-read turn on small
fixes.
Useful explicit requests include:
Run rust.check with target "all" before finishing.
Run rust.check once with timings=true when build latency needs diagnosis.
Use rust.crate_lookup before adding the dependency.
Trace callers with rust.hierarchy before changing this function.
Prepare a write-free rust.rename plan for this symbol.
| Tool | Purpose |
|---|---|
rust.check | Run Cargo check, test, doctest, Clippy, format, or the full gate; compact output is default and optional timings=true adds bounded stable Cargo timing diagnostics |
rust.audit | Find common agent-generated Rust pitfalls |
rust.crate_lookup | Verify crate names and published versions |
rust.symbol | Show hover type and documentation |
rust.symbols | List document symbols |
rust.references | Find semantic references |
rust.definition | Open the semantic definition |
rust.implementations | Find trait/type implementations |
rust.hierarchy | Inspect incoming/outgoing calls |
rust.rename | Produce a verified, write-free rename package |
rust.refactor | List code actions without executing commands or edits |
rust.docs | Read version-pinned source/rustdoc/docs.rs content; expensive local generation is explicit |
The complete tool reference documents required and optional inputs, exact Cargo commands, gate status and authority, result limits, task-based visibility, network behavior, and path safety for every row.
autoGate, autoCrateCheck, and autoAudit are enabled only in detected
Rust workspaces and are session-limited.autoGate schedules only a fast check after validation-relevant edits and
never blocks model dispatch on Cargo, rust-analyzer, network, or terminal work.rust.check; task cues open the specialized tools.FAST_PASS, FULL_PASS, FAIL, or a non-authoritative
state such as PENDING, STALE, or RESOURCE_BLOCKED. A 30-second response
budget never turns unfinished work into a pass.FULL_PASS always uses the complete workspace scope and a separate applicable
doctest command. Affected-package scope remains in shadow mode by default.autoLsp is disabled by default and has a deadline and per-session quota
when enabled.FULL_PASS commands stay unchanged.bun install --frozen-lockfile
bun scripts/check-release-docs.ts
bun run typecheck
bun test
bun run build
bun run benchmark:fixtures
bun run benchmark:validation:smoke
bun run benchmark:ablation:smoke
The release gate is bun run typecheck && bun test && bun run build. dist/ is
generated and must not be edited manually. The previous full benchmark is
invalid because of a scorer/workspace failure and is not release evidence. The
latest two-fixture controlled A/B is valid but exceeds the documented cost
budget and is not a general rollout claim; a new paid run requires explicit
approval. See the benchmark evidence limits.
The free ablation smoke exercises sequential feature arms, Turkish mirrors,
cold/warm cohorts, source-state safety, and concurrency, but is explicitly
measurement-only rather than a rollout claim.
Maintainers should follow the version and tag consistency checklist in the release process.
MIT © 2026 Uğur Murat Altıntaş
FAQs
Rust correctness tools, rust-analyzer navigation, safe edit plans, and version-pinned docs for OpenCode V2.
We found that opencode-rust-coder demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.

Security News
Socket CTO Ahmad Nassri joins AppSec leaders at Black Hat to discuss active malware, package manager risks, and software supply chain defense.

Research
/Security News
Thirteen malicious Packagist themes expose visitors on unpatched iPhones to a WebKit-to-kernel exploit chain that steals device data and wallet seeds.