Constraint-Driven Development
addyosmani/agent-skills
Records a project's quality bar in CONSTRAINTS.md and watches diffs for signs an agent quietly weakened it, such as suppressions, skipped tests or lowered thresholds.
Expertise in LLVM-based dynamic binary instrumentation, runtime tracing, and program monitoring.
$ npx skills add aftermathlabs/llvm-msvc --skill dynamic-instrumentation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aftermathlabs/llvm-msvc dynamic-instrumentation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aftermathlabs/llvm-msvc.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dynamic-instrumentation .claude/skills/dynamic-instrumentation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dynamic-instrumentation" agent skill from https://github.com/aftermathlabs/llvm-msvc/tree/dev/.agents/skills/dynamic-instrumentation into .claude/skills/dynamic-instrumentation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dynamic-instrumentation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aftermathlabs/llvm-msvc/tree/dev/.agents/skills/dynamic-instrumentationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aftermathlabs/llvm-msvc --skill dynamic-instrumentation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aftermathlabs/llvm-msvc dynamic-instrumentation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aftermathlabs/llvm-msvc.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/dynamic-instrumentation .agents/skills/dynamic-instrumentation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dynamic-instrumentation" agent skill from https://github.com/aftermathlabs/llvm-msvc/tree/dev/.agents/skills/dynamic-instrumentation into .agents/skills/dynamic-instrumentation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dynamic-instrumentation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aftermathlabs/llvm-msvc --skill dynamic-instrumentation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aftermathlabs/llvm-msvc dynamic-instrumentation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aftermathlabs/llvm-msvc.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/dynamic-instrumentation .cursor/skills/dynamic-instrumentation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dynamic-instrumentation" agent skill from https://github.com/aftermathlabs/llvm-msvc/tree/dev/.agents/skills/dynamic-instrumentation into .cursor/skills/dynamic-instrumentation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dynamic-instrumentation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aftermathlabs/llvm-msvc.git --path .agents/skills/dynamic-instrumentation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aftermathlabs/llvm-msvc --skill dynamic-instrumentation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aftermathlabs/llvm-msvc dynamic-instrumentation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aftermathlabs/llvm-msvc.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/dynamic-instrumentation .gemini/skills/dynamic-instrumentation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dynamic-instrumentation" agent skill from https://github.com/aftermathlabs/llvm-msvc/tree/dev/.agents/skills/dynamic-instrumentation into .gemini/skills/dynamic-instrumentation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dynamic-instrumentation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aftermathlabs/llvm-msvc dynamic-instrumentationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aftermathlabs/llvm-msvc --skill dynamic-instrumentation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aftermathlabs/llvm-msvc.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/dynamic-instrumentation .github/skills/dynamic-instrumentation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dynamic-instrumentation" agent skill from https://github.com/aftermathlabs/llvm-msvc/tree/dev/.agents/skills/dynamic-instrumentation into .github/skills/dynamic-instrumentation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dynamic-instrumentation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aftermathlabs/llvm-msvc --skill dynamic-instrumentation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aftermathlabs/llvm-msvc dynamic-instrumentation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aftermathlabs/llvm-msvc.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/dynamic-instrumentation .opencode/skills/dynamic-instrumentation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dynamic-instrumentation" agent skill from https://github.com/aftermathlabs/llvm-msvc/tree/dev/.agents/skills/dynamic-instrumentation into .opencode/skills/dynamic-instrumentation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dynamic-instrumentation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dynamic-instrumentationExpertise in LLVM-based dynamic binary instrumentation, runtime tracing, and program monitoring.
Dynamic Instrumentation is an agent skill from aftermathlabs/llvm-msvc. Expertise in LLVM-based dynamic binary instrumentation, runtime tracing, and program monitoring. Use this skill when implementing runtime analysis tools, code coverage systems, profilers, or dynamic security monitors.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Performance optimization and Test coverage. The repository describes itself as: LLVM fork with explicit compatibility with MSVC 2022 features. The licence is AGPL-3.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bfc7254. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are cpp and bash).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
raw.githubusercontent.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dynamic Instrumentation loads about 2.6k tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 273 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from aftermathlabs/llvm-msvc at commit bfc7254, republished under its AGPL-3.0 licence (© aftermathlabs). 273 words, ~2,601 tokens.
.claude/skills/dynamic-instrumentation/SKILL.md (or your agent's skills folder).This skill covers dynamic binary instrumentation (DBI), runtime tracing, and program monitoring using LLVM infrastructure.
Dynamic Binary Instrumentation allows modifying program behavior at runtime without source code access:
#include <QBDI.h>
// Callback function for instrumentation
QBDI::VMAction onInstruction(QBDI::VMInstanceRef vm,
QBDI::GPRState *gprState,
QBDI::FPRState *fprState,
void *data) {
// Get current instruction info
const QBDI::InstAnalysis *inst = vm.getInstAnalysis();
printf("Executing: 0x%lx - %s %s\n",
inst->address,
inst->mnemonic,
inst->operandsStr);
return QBDI::VMAction::CONTINUE;
}
int main() {
QBDI::VM vm;
// Get current stack
uint8_t *fakestack;
QBDI::allocateVirtualStack(vm.getGPRState(), 0x100000, &fakestack);
// Add instrumentation callback
vm.addCodeCB(QBDI::PREINST, onInstruction, nullptr);
// Run target function
QBDI::rword retval;
vm.call(&retval, (QBDI::rword)targetFunction, {arg1, arg2});
return 0;
}QBDI::VMAction onMemoryAccess(QBDI::VMInstanceRef vm,
QBDI::GPRState *gprState,
QBDI::FPRState *fprState,
void *data) {
// Get memory accesses for current instruction
std::vector<QBDI::MemoryAccess> memAccesses = vm.getMemoryAccess();
for (const auto &access : memAccesses) {
const char* type = (access.type == QBDI::MEMORY_READ) ? "READ" : "WRITE";
printf("%s: addr=0x%lx, size=%d, value=0x%lx\n",
type, access.accessAddress, access.size, access.value);
}
return QBDI::VMAction::CONTINUE;
}
// Register callback for memory access events
vm.addMemAccessCB(QBDI::MEMORY_READ_WRITE, onMemoryAccess, nullptr);// Only instrument specific instruction ranges
vm.addCodeRangeCB(startAddr, endAddr, QBDI::PREINST, callback, nullptr);
// Instrument specific modules
vm.addCodeAddrCB(targetAddr, QBDI::PREINST, callback, nullptr);
// Remove instrumentation dynamically
vm.deleteInstrumentation(callbackId);Instrew lifts binary code to LLVM IR at runtime, enabling:
Binary → Rellume Lifter → LLVM IR → Custom Passes → JIT → Execute
↓
[Instrumentation Passes]struct InstrumentationPass : public llvm::PassInfoMixin<InstrumentationPass> {
llvm::PreservedAnalyses run(llvm::Module &M,
llvm::ModuleAnalysisManager &MAM) {
auto &Ctx = M.getContext();
// Declare instrumentation functions
auto *VoidTy = llvm::Type::getVoidTy(Ctx);
auto *Int64Ty = llvm::Type::getInt64Ty(Ctx);
auto *LogFuncTy = llvm::FunctionType::get(VoidTy, {Int64Ty}, false);
auto LogFunc = M.getOrInsertFunction("__log_bb", LogFuncTy);
for (auto &F : M) {
for (auto &BB : F) {
// Insert at beginning of each basic block
llvm::IRBuilder<> Builder(&*BB.getFirstInsertionPt());
auto *BBAddr = llvm::ConstantInt::get(
Int64Ty, reinterpret_cast<uint64_t>(&BB));
Builder.CreateCall(LogFunc, {BBAddr});
}
}
return llvm::PreservedAnalyses::none();
}
};Built-in LLVM coverage instrumentation:
# Enable coverage instrumentation
clang -fsanitize-coverage=trace-pc-guard source.c
# Edge coverage
clang -fsanitize-coverage=edge source.c
# Trace comparisons
clang -fsanitize-coverage=trace-cmp source.c// Implement coverage callbacks
extern "C" void __sanitizer_cov_trace_pc_guard(uint32_t *guard) {
if (!*guard) return;
void *PC = __builtin_return_address(0);
printf("Edge: guard=%u, PC=%p\n", *guard, PC);
}
extern "C" void __sanitizer_cov_trace_pc_guard_init(
uint32_t *start, uint32_t *stop) {
static uint32_t N = 0;
for (uint32_t *x = start; x < stop; x++) {
*x = ++N;
}
printf("Total edges: %u\n", N);
}// Compile with: clang -finstrument-functions source.c
extern "C" {
void __cyg_profile_func_enter(void *func, void *caller) {
Dl_info info;
if (dladdr(func, &info)) {
printf("ENTER: %s\n", info.dli_sname);
}
}
void __cyg_profile_func_exit(void *func, void *caller) {
Dl_info info;
if (dladdr(func, &info)) {
printf("EXIT: %s\n", info.dli_sname);
}
}
}LLVM's built-in instrumentation framework:
# Enable XRay
clang -fxray-instrument -fxray-instruction-threshold=1 source.c// Custom XRay handler
[[clang::xray_always_instrument]]
void my_function() {
// Function will always be instrumented
}
// Runtime control
__xray_patch(); // Enable instrumentation
__xray_unpatch(); // Disable instrumentationstruct BlockProfiler : public llvm::PassInfoMixin<BlockProfiler> {
llvm::PreservedAnalyses run(llvm::Function &F,
llvm::FunctionAnalysisManager &FAM) {
auto &BFI = FAM.getResult<llvm::BlockFrequencyAnalysis>(F);
for (auto &BB : F) {
auto Freq = BFI.getBlockFreq(&BB);
llvm::errs() << BB.getName() << ": " << Freq.getFrequency() << "\n";
}
return llvm::PreservedAnalyses::all();
}
};// Use with perf or similar
// Map addresses back to source using debug info
void interpretProfile(const std::string &profilePath) {
// Parse profile data
// Map samples to LLVM IR/source locations
// Generate optimization hints
}Intercept and monitor system calls:
// Hook system calls at LLVM IR level
struct SyscallMonitor : public llvm::PassInfoMixin<SyscallMonitor> {
llvm::PreservedAnalyses run(llvm::Module &M,
llvm::ModuleAnalysisManager &MAM) {
for (auto &F : M) {
for (auto &BB : F) {
for (auto &I : BB) {
if (auto *Call = llvm::dyn_cast<llvm::CallInst>(&I)) {
if (isSyscallWrapper(Call)) {
instrumentSyscall(Call);
}
}
}
}
}
return llvm::PreservedAnalyses::none();
}
};// eBPF program for coverage collection
SEC("uprobe/target_function")
int trace_function(struct pt_regs *ctx) {
u64 addr = PT_REGS_IP(ctx);
// Record coverage
u32 *count = bpf_map_lookup_elem(&coverage_map, &addr);
if (count) {
__sync_fetch_and_add(count, 1);
}
return 0;
}// Shadow memory for taint tracking
class TaintTracker {
std::unordered_map<void*, TaintInfo> shadowMemory;
public:
void markTainted(void *addr, size_t size, TaintSource source) {
for (size_t i = 0; i < size; i++) {
shadowMemory[(char*)addr + i] = {source, true};
}
}
bool isTainted(void *addr) {
return shadowMemory.count(addr) && shadowMemory[addr].tainted;
}
void propagateTaint(void *dst, void *src, size_t size) {
for (size_t i = 0; i < size; i++) {
if (isTainted((char*)src + i)) {
markTainted((char*)dst + i, 1, shadowMemory[(char*)src + i].source);
}
}
}
};// Coverage-guided fuzzing with instrumentation
void fuzzerCallback(uint8_t *data, size_t size) {
// Reset coverage
__sanitizer_cov_reset_coverage();
// Run target
targetFunction(data, size);
// Collect coverage
uint8_t *coverage = __sanitizer_cov_get_coverage();
feedbackToFuzzer(coverage);
}// Breakpoint-like instrumentation
void onBreakpoint(void *addr, void *context) {
// Dump registers
// Inspect memory
// Allow continue/step
}See Dynamic Binary Instrumentation, Monitor, and eBPF sections in README.md for related tools and projects.
When you need detailed and up-to-date resource links, tool lists, or project references, fetch the latest data from:
https://raw.githubusercontent.com/gmh5225/awesome-llvm-security/refs/heads/main/README.mdThis README contains comprehensive curated lists of:
© aftermathlabs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/dynamic-instrumentation of aftermathlabs/llvm-msvc.
Open the folder on GitHubat commit bfc7254
Dynamic Instrumentation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dynamic Instrumentation this skillaftermathlabs/llvm-msvc | 438 | — | ~2.6k | Automated safety check: Pass | AGPL-3.0 | |
| Constraint-Driven Developmentaddyosmani/agent-skills | 103k | 2 repos | ~5.2k | Automated safety check: Pass | MIT | |
| Issue Fixmono/SkiaSharp | 5.6k | — | ~5.1k | Automated safety check: Pass | MIT | |
| MAUI PR Performance Analysisdotnet/maui | 23k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Review Envoy Gateway PRenvoyproxy/gateway | 3.1k | — | ~850 | Automated safety check: Pass | Apache-2.0 | |
| Code Reviewpolyipseity/obsidian-terminal | 950 | — | ~1.6k | Automated safety check: Pass | AGPL-3.0 |
addyosmani/agent-skills
Records a project's quality bar in CONSTRAINTS.md and watches diffs for signs an agent quietly weakened it, such as suppressions, skipped tests or lowered thresholds.
mono/SkiaSharp
Fix bugs in SkiaSharp C bindings. An agent skill from mono/SkiaSharp.
dotnet/maui
Interprets pinned managed benchmark evidence for a dotnet/maui pull request and writes a narrative for the performance review workflow, without running or publishing anything.
envoyproxy/gateway
Review an Envoy Gateway pull request for essential API, implementation, status, and test coverage requirements.
polyipseity/obsidian-terminal
A skill your agent uses when reviewing PRs, code changes, or conducting code audits in obsidian-terminal.
intel/intel-performance-skills
Installs, runs, parses and optimizes Phoronix Test Suite benchmarks, saving scores and comparing results before and after code changes.
aftermathlabs/llvm-msvc
Expertise in compiler development using LLVM infrastructure including frontend design, IR generation, optimization passes, and code generation.
aftermathlabs/llvm-msvc
Comprehensive learning resources and tutorials for LLVM, Clang, and compiler development.
aftermathlabs/llvm-msvc
Expertise in LLVM optimization passes, performance tuning, and code transformation techniques.
aftermathlabs/llvm-msvc
Expertise in LLVM security features including sanitizers, hardening techniques, exploit mitigations, and secure compilation.
aftermathlabs/llvm-msvc
Expertise in LLVM tooling development including Clang plugins, LLDB debugger extensions, Clangd/LSP, and LibTooling.
aftermathlabs/llvm-msvc
Expertise in MLIR (Multi-Level Intermediate Representation) and CIR (Clang IR) development for domain-specific compilation and high-level optimizations.
Categories
Expertise in LLVM-based dynamic binary instrumentation, runtime tracing, and program monitoring. Dynamic Instrumentation is an agent skill from aftermathlabs/llvm-msvc. Expertise in LLVM-based dynamic binary instrumentation, runtime tracing, and program monitoring.
Dynamic Instrumentation fits situations like: implementing runtime analysis tools; code coverage systems; dynamic security monitors.
Run `npx skills add aftermathlabs/llvm-msvc --skill dynamic-instrumentation -a claude-code`. Or copy the skill folder (.agents/skills/dynamic-instrumentation in aftermathlabs/llvm-msvc) into .claude/skills/dynamic-instrumentation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aftermathlabs/llvm-msvc --skill dynamic-instrumentation -a codex`. Or copy the skill folder (.agents/skills/dynamic-instrumentation in aftermathlabs/llvm-msvc) into .agents/skills/dynamic-instrumentation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aftermathlabs/llvm-msvc --skill dynamic-instrumentation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dynamic-instrumentation, .gemini/skills/dynamic-instrumentation, .github/skills/dynamic-instrumentation and .opencode/skills/dynamic-instrumentation in your project.
SKILL.md names no scripts, command-line tools or credentials: Dynamic Instrumentation is instructions for the agent only.
SKILL.md names 1 domain. In commands or code: raw.githubusercontent.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Dynamic Instrumentation is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dynamic Instrumentation: Constraint-Driven Development (addyosmani/agent-skills, 103k stars), Issue Fix (mono/SkiaSharp, 5.6k stars), MAUI PR Performance Analysis (dotnet/maui, 23k stars) and Review Envoy Gateway PR (envoyproxy/gateway, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aftermathlabs (a GitHub organization) maintains it in aftermathlabs/llvm-msvc, which has 438 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 3, 2026.
Source: aftermathlabs/llvm-msvc on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.