But isn't this a problem with all code? Looking at a Rust function signature how can you be sure that it does what it says it does? Or python?
For Python, it's very little (nothing?). For Rust, you get more than most; lifetimes tell you whether it holds onto a pointer you give it.