different-ai/openwork92 installs
cargo-lock-manager
Manages Cargo.lock file updates and resolves --locked flag issues in CI/CD. Triggers when user mentions: - "cargo test --locked failed" - "cannot update the lock file" - "Cargo.lock is out of date" - "PR failed with --locked error" - "fix Cargo.lock"
How do I install this agent skill?
npx skills add https://github.com/different-ai/openwork --skill cargo-lock-managerIs this agent skill safe to install?
- Gen Agent Trust Hubwarn
The skill helps manage Rust Cargo.lock files but contains shell scripts that are vulnerable to command injection. The scripts accept user-provided file paths as arguments and use them directly in shell commands without sanitization.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
- Runlayerwarn
4/4 files flagged
What does this agent skill do?
Quick Usage (Already Configured)
Check Cargo.lock status
cd packages/desktop/src-tauri
cargo check --locked 2>&1 | head -20
Update Cargo.lock locally
cd packages/desktop/src-tauri
cargo update --workspace
Test with --locked after update
cd packages/desktop/src-tauri
cargo test --locked
Common Gotchas
- The
--lockedflag prevents automatic updates to Cargo.lock, which is good for reproducible builds but fails when dependencies change. - PRs often fail because the lock file wasn't committed after dependency updates.
- Running
cargo updatewithout--workspacemay not update all workspace members.
When CI Fails with --locked
Option 1: Update lock file and commit (Recommended)
cd packages/desktop/src-tauri
cargo update --workspace
git add Cargo.lock
git commit -m "chore: update Cargo.lock"
git push
Option 2: Use --offline flag (for air-gapped environments)
cargo test --manifest-path packages/desktop/src-tauri/Cargo.toml --offline
First-Time Setup (If Not Configured)
No setup required. This skill assumes:
- Rust/Cargo is installed
- You're in the openwork repository
- The Tauri app is in
packages/desktop/src-tauri/
Prevention Tips
- Always run
cargo checkorcargo buildafter modifyingCargo.tomlfiles - Include
Cargo.lockchanges in the same commit as dependency updates - Consider adding a pre-commit hook to verify lock file is up to date
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/different-ai/openwork/cargo-lock-manager">View cargo-lock-manager on skillZs</a>