axum-code-review
Reviews axum web framework code for routing patterns, extractor usage, middleware, state management, and error handling. Use when reviewing Rust code that uses axum, tower, or hyper for HTTP services. Covers axum 0.7+ patterns including State, Path, Query, Json extractors.
Best use case
axum-code-review is best used when you need a repeatable AI agent workflow instead of a one-off prompt.
Reviews axum web framework code for routing patterns, extractor usage, middleware, state management, and error handling. Use when reviewing Rust code that uses axum, tower, or hyper for HTTP services. Covers axum 0.7+ patterns including State, Path, Query, Json extractors.
Teams using axum-code-review should expect a more consistent output, faster repeated execution, less prompt rewriting.
When to use this skill
- You want a reusable workflow that can be run more than once with consistent structure.
When not to use this skill
- You only need a quick one-off answer and do not need a reusable workflow.
- You cannot install or maintain the underlying files, dependencies, or repository context.
Installation
Claude Code / Cursor / Codex
Manual Installation
- Download SKILL.md from GitHub
- Place it in
.claude/skills/axum-code-review/SKILL.mdinside your project - Restart your AI agent — it will auto-discover the skill
How axum-code-review Compares
| Feature / Agent | axum-code-review | Standard Approach |
|---|---|---|
| Platform Support | Not specified | Limited / Varies |
| Context Awareness | High | Baseline |
| Installation Complexity | Unknown | N/A |
Frequently Asked Questions
What does this skill do?
Reviews axum web framework code for routing patterns, extractor usage, middleware, state management, and error handling. Use when reviewing Rust code that uses axum, tower, or hyper for HTTP services. Covers axum 0.7+ patterns including State, Path, Query, Json extractors.
Where can I find the source code?
You can find the source code on GitHub using the link provided at the top of the page.
Related Guides
AI Agents for Coding
Browse AI agent skills for coding, debugging, testing, refactoring, code review, and developer workflows across Claude, Cursor, and Codex.
Best AI Skills for Claude
Explore the best AI skills for Claude and Claude Code across coding, research, workflow automation, documentation, and agent operations.
Cursor vs Codex for AI Workflows
Compare Cursor and Codex for AI coding workflows, repository assistance, debugging, refactoring, and reusable developer skills.
SKILL.md Source
# Axum Code Review ## Review Workflow 1. **Check Cargo.toml** — Note axum version (0.6 vs 0.7+ have different patterns), tower, tower-http features 2. **Check routing** — Route organization, method routing, nested routers 3. **Check extractors** — Order matters (body extractors must be last), correct types 4. **Check state** — Shared state via `State<T>`, not global mutable state 5. **Check error handling** — `IntoResponse` implementations, error types ## Output Format Report findings as: ```text [FILE:LINE] ISSUE_TITLE Severity: Critical | Major | Minor | Informational Description of the issue and why it matters. ``` ## Quick Reference | Issue Type | Reference | |------------|-----------| | Route definitions, nesting, method routing | [references/routing.md](references/routing.md) | | State, Path, Query, Json, body extractors | [references/extractors.md](references/extractors.md) | | Tower middleware, layers, error handling | [references/middleware.md](references/middleware.md) | ## Review Checklist ### Routing - [ ] Routes organized by domain (nested routers for `/api/users`, `/api/orders`) - [ ] Fallback handlers defined for 404s - [ ] Method routing explicit (`.get()`, `.post()`, not `.route()` with manual method matching) - [ ] No route conflicts (overlapping paths with different extractors) ### Extractors - [ ] Body-consuming extractors (`Json`, `Form`, `Bytes`) are the LAST parameter - [ ] `State<T>` requires `T: Clone` — typically `Arc<AppState>` or direct `Clone` derive - [ ] `Path<T>` parameter types match the route definition - [ ] `Query<T>` fields are `Option` for optional query params with `#[serde(default)]` - [ ] Custom extractors implement `FromRequestParts` (not body) or `FromRequest` (body) ### State Management - [ ] Application state shared via `State<T>`, not global mutable statics - [ ] Database pool in state (not created per-request) - [ ] State contains only shared resources (pool, config, channels), not request-specific data - [ ] `Clone` derived or manually implemented on state type ### Error Handling - [ ] Handler errors implement `IntoResponse` for proper HTTP error codes - [ ] Internal errors don't leak to clients (no raw error messages in 500 responses) - [ ] Error responses use consistent format (JSON error body with code/message) - [ ] `Result<impl IntoResponse, AppError>` pattern used for handlers ### Middleware - [ ] Tower layers applied in correct order (outer runs first on request, last on response) - [ ] `tower-http` used for common concerns (CORS, compression, tracing, timeout) - [ ] Request-scoped data passed via extensions, not global state - [ ] Middleware errors don't panic — they return error responses ## Severity Calibration ### Critical - Body extractor not last in handler parameters (silently consumes body, later extractors fail) - SQL injection via path/query parameters passed directly to queries - Internal error details leaked to clients (stack traces, database errors) - Missing authentication middleware on protected routes ### Major - Global mutable state instead of `State<T>` (race conditions) - Missing error type conversion (raw `sqlx::Error` returned to client) - Missing request timeout (handlers can hang indefinitely) - Route conflicts causing unexpected 405s ### Minor - Manual route method matching instead of `.get()`, `.post()` - Missing fallback handler (default 404 is plain text, not JSON) - Middleware applied per-route when it should be global (or vice versa) - Missing `tower-http::trace` for request logging ### Informational - Suggestions to use `tower-http` layers for common concerns - Router organization improvements - Suggestions to add OpenAPI documentation via `utoipa` or `aide` ## Valid Patterns (Do NOT Flag) - **`#[axum::debug_handler]` on handlers** — Debugging aid that improves compile error messages - **`Extension<T>` for middleware-injected data** — Valid pattern for request-scoped values - **Returning `impl IntoResponse` from handlers** — More flexible than concrete types - **`Router::new()` per module, merged in main** — Standard organization pattern - **`ServiceBuilder` for layer composition** — Tower pattern, not over-engineering - **`axum::serve` with `TcpListener`** — Standard axum 0.7+ server setup ## Before Submitting Findings Load and follow `beagle-rust:review-verification-protocol` before reporting any issue.
Related Skills
Post-Mortem & Incident Review Framework
Run structured post-mortems that actually prevent repeat failures. Blameless analysis, root cause identification, and action tracking.
Pitch Deck Reviewer
Reviews pitch decks and provides investor-ready feedback with scoring
Performance Review Engine
> Your AI-powered performance management system. Write reviews that develop people, not just evaluate them. From self-assessments to 360° feedback to calibration — complete frameworks for every review cycle.
Deal Desk — Structured Deal Review & Approval
Run every non-standard deal through a repeatable review process. Catch margin leaks, enforce discount guardrails, and close faster with pre-approved terms.
Contract Review Assistant
Analyze business contracts for risks, unfavorable terms, and missing clauses. Get a plain-English summary of what you're signing.
afrexai-code-reviewer
Enterprise-grade code review agent. Reviews PRs, diffs, or code files for security vulnerabilities, performance issues, error handling gaps, architecture smells, and test coverage. Works with any language, any repo, no dependencies required.
performance-review-cn
绩效面谈报告、OKR对齐度检测、校准辅助
clawdtm-review
Review and rate OpenClaw skills on ClawdTM. See what humans and AI agents recommend.
cyber-owasp-review
Map application security findings to OWASP Top 10 categories and generate remediation checklists. Use for normalized AppSec review outputs and category-level prioritization.
Contract Reviewer - AI Legal Document Risk Scanner
Upload any contract or legal document and get a structured risk analysis with flagged clauses, plain-language explanations, and negotiation suggestions.
serde-code-review
Reviews serde serialization code for derive patterns, enum representations, custom implementations, and common serialization bugs. Use when reviewing Rust code that uses serde, serde_json, toml, or any serde-based serialization format. Covers attribute macros, field renaming, and format-specific pitfalls.
rust-testing-code-review
Reviews Rust test code for unit test patterns, integration test structure, async testing, mocking approaches, and property-based testing. Use when reviewing _test.rs files,