cargo-machete

v2026.09.24

cargo-machete: detect unused Rust dependencies. Use when auditing Cargo.toml, optimizing build times, or cleaning up dependency bloat.

GitHub
Install command
npx skhub add laurigates/cargo-machete
Markdown
SKILL.md

cargo-machete - Unused Dependency Detection

Detect and remove unused dependencies in Rust projects using cargo-machete.

When to Use This Skill

Use this skill when...Use X instead when...
Auditing for unused dependenciesChecking for outdated deps -- use cargo outdated
Cleaning up Cargo.tomlAuditing security vulnerabilities -- use cargo audit
Optimizing build times by removing bloatChecking license compliance -- use cargo deny
Verifying deps in CINeed nightly-accurate analysis -- use cargo +nightly udeps

Context

  • Cargo.toml: !find . -maxdepth 1 -name \'Cargo.toml\'
  • Workspace: !find . -maxdepth 1 -name 'Cargo.toml' -exec grep -q '\[workspace\]' {} +
  • cargo-machete installed: !cargo machete --version
  • Machete config: !find . -maxdepth 1 -name \'.cargo-machete.toml\'
  • Workspace members: !find . -maxdepth 1 -name 'Cargo.toml' -exec grep -A 20 '^\[workspace\]' {} +

Execution

Execute this unused dependency analysis:

Step 1: Verify installation

Check if cargo-machete is installed (see Context above). If not installed, install it:

cargo install cargo-machete

Step 2: Run dependency analysis

Run cargo-machete with metadata for detailed output:

# Single crate
cargo machete --with-metadata

# Workspace (if Context shows workspace)
cargo machete --workspace --with-metadata

Step 3: Evaluate results

Review the output and classify each finding:

FindingAction
Genuinely unused dependencyRemove with --fix or manually
Proc-macro dependency (e.g., serde derive)Add machete:ignore comment
Build.rs-only dependencyMove to [build-dependencies]
Re-exported dependencyAdd machete:ignore comment with explanation

Step 4: Apply fixes

For confirmed unused dependencies, auto-remove them:

cargo machete --fix

For false positives, add ignore annotations in Cargo.toml:

serde = "1.0"  # machete:ignore - used via derive macro

Or create .cargo-machete.toml for project-wide ignores:

[ignore]
dependencies = ["serde", "log"]

Step 5: Verify build

After removing dependencies, confirm everything still compiles:

cargo check --all-targets
cargo test --no-run

False Positive Handling

ScenarioSolution
Proc-macro deps (e.g., serde derive)machete:ignore comment
Build.rs-only depsMove to [build-dependencies]
Re-exported depsmachete:ignore comment with explanation
Example/bench-only depsVerify in [dev-dependencies]

Comparison with cargo-udeps

Featurecargo-machetecargo-udeps
AccuracyGoodExcellent
SpeedVery fastSlower
Rust versionStableRequires nightly
False positivesSomeFewer

Use cargo-machete for fast CI checks. Use cargo-udeps for thorough audits:

cargo +nightly udeps --workspace --all-features

Agentic Optimizations

ContextCommand
Quick checkcargo machete
Detailed checkcargo machete --with-metadata
Workspace checkcargo machete --workspace --with-metadata
Auto-fixcargo machete --fix
Verify after fixcargo check --all-targets
Accurate check (nightly)cargo +nightly udeps --workspace

Quick Reference

FlagDescription
--with-metadataShow detailed output with versions and locations
--fixAuto-remove unused dependencies from Cargo.toml
--workspaceCheck all workspace members
-p <crate>Check specific workspace member
--exclude <crate>Exclude specific workspace member

Troubleshooting

ProblemSolution
Proc macro flagged as unusedAdd machete:ignore comment in Cargo.toml
Build.rs dep flaggedMove to [build-dependencies]
Re-exported dep flaggedAdd machete:ignore with explanation
Need more accuracyUse cargo +nightly udeps

For CI integration patterns, configuration file examples, pre-commit setup, and Makefile integration, see REFERENCE.md.

Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

MIT

Source path

rust-plugin/skills/cargo-machete

Default branch

main

Latest commit

1668324

Tree SHA

b2d4cc3