Agent skill

Llvm Security

by aftermathlabs in aftermathlabs/llvm-msvc

Expertise in LLVM security features including sanitizers, hardening techniques, exploit mitigations, and secure compilation.

AGPL-3.0Auto-check passedSecurity

Install Llvm Security

skills CLI
$ npx skills add aftermathlabs/llvm-msvc --skill llvm-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aftermathlabs/llvm-msvc llvm-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aftermathlabs/llvm-msvc.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/llvm-security .claude/skills/llvm-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
llvm-security
GitHub stars
438
Token cost
~1.8k tokens
SKILL.md length
249 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Expertise in LLVM security features including sanitizers, hardening techniques, exploit mitigations, and secure compilation.

  • Implementing security-focused compiler features
  • SKILL.md covers Sanitizers, Hardening Techniques, Symbolic Execution and Security-Focused Analysis, plus 4 more sections
  • Reaches raw.githubusercontent.com
  • Analyzing vulnerabilities

What it does

Llvm Security is an agent skill from aftermathlabs/llvm-msvc. Expertise in LLVM security features including sanitizers, hardening techniques, exploit mitigations, and secure compilation. Use this skill when implementing security-focused compiler features, analyzing vulnerabilities, or hardening applications.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Fuzzing. The repository describes itself as: LLVM fork with explicit compatibility with MSVC 2022 features. The licence is AGPL-3.0.

When your agent uses it

  • Implementing security-focused compiler features
  • Analyzing vulnerabilities
  • Hardening applications

Example prompts

  • “/llvm-security”

What it can do on your machine

Read from SKILL.md and the folder at commit bfc7254. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash, cpp and llvm).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • raw.githubusercontent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Llvm Security loads about 1.8k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 249 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aftermathlabs/llvm-msvc at commit bfc7254, republished under its AGPL-3.0 licence (© aftermathlabs). 249 words, ~1,832 tokens.

Download SKILL.mdSave it as .claude/skills/llvm-security/SKILL.md (or your agent's skills folder).
name
llvm-security
description
Expertise in LLVM security features including sanitizers, hardening techniques, exploit mitigations, and secure compilation. Use this skill when implementing security-focused compiler features, analyzing vulnerabilities, or hardening applications.

LLVM Security Skill

This skill covers LLVM-based security features, sanitizers, hardening mechanisms, and secure software development practices.

Sanitizers

AddressSanitizer (ASan)

Detects memory errors: buffer overflow, use-after-free, use-after-scope.

bash
# Compile with ASan
clang -fsanitize=address -g program.c -o program

# Key features
# - Stack buffer overflow detection
# - Heap buffer overflow detection  
# - Use-after-free detection
# - Memory leak detection
MemorySanitizer (MSan)

Detects uninitialized memory reads.

bash
clang -fsanitize=memory -g program.c -o program
ThreadSanitizer (TSan)

Detects data races in multithreaded programs.

bash
clang -fsanitize=thread -g program.c -o program
UndefinedBehaviorSanitizer (UBSan)

Detects undefined behavior at runtime.

bash
clang -fsanitize=undefined -g program.c -o program

# Specific checks
clang -fsanitize=signed-integer-overflow,null program.c
Custom Sanitizer Development
cpp
// Implementing custom memory tracking
extern "C" void __asan_poison_memory_region(void const volatile *addr, size_t size);
extern "C" void __asan_unpoison_memory_region(void const volatile *addr, size_t size);

class SecureAllocator {
public:
    void* allocate(size_t size) {
        // Add red zones around allocation
        void* ptr = malloc(size + 2 * REDZONE_SIZE);
        __asan_poison_memory_region(ptr, REDZONE_SIZE);
        __asan_poison_memory_region((char*)ptr + REDZONE_SIZE + size, REDZONE_SIZE);
        return (char*)ptr + REDZONE_SIZE;
    }
};

Hardening Techniques

Stack Protection
bash
# Stack canaries
clang -fstack-protector-strong program.c

# Stack clash protection
clang -fstack-clash-protection program.c

# Safe stack (separate stacks for safe/unsafe data)
clang -fsanitize=safe-stack program.c
Control Flow Integrity (CFI)
bash
# Forward-edge CFI
clang -fsanitize=cfi -flto program.c

# Specific CFI schemes
clang -fsanitize=cfi-vcall      # Virtual call checks
clang -fsanitize=cfi-nvcall     # Non-virtual member call checks
clang -fsanitize=cfi-icall      # Indirect call checks
Shadow Call Stack
bash
# Backward-edge protection (return address protection)
clang -fsanitize=shadow-call-stack program.c
Position Independent Executables
bash
# Full ASLR support
clang -fPIE -pie program.c

# Position independent code for shared libraries
clang -fPIC -shared library.c -o library.so

Symbolic Execution

Integration with KLEE
cpp
// Mark symbolic inputs
#include <klee/klee.h>

int main() {
    int input;
    klee_make_symbolic(&input, sizeof(input), "input");
    
    if (input > 0) {
        // Path 1
    } else {
        // Path 2
    }
    return 0;
}
SymCC (Symbolic Execution via Compilation)

Compile-time instrumentation for symbolic execution:

  • Faster than IR interpretation
  • Supports complex real-world programs
  • Integrates with fuzzing workflows
Symbolic Analysis Tools
  • Caffeine: LLVM-based symbolic executor
  • SymSan: Symbolic execution + sanitizers
  • Haybale: Rust-based LLVM symbolic executor

Security-Focused Analysis

Type Checking at Runtime
cpp
// LLVM TypeSanitizer concepts
// Track type information through allocations
struct TypeInfo {
    const char* typeName;
    size_t typeSize;
    uint64_t typeHash;
};

void checkType(void* ptr, TypeInfo expected) {
    TypeInfo* actual = getTypeInfo(ptr);
    if (actual->typeHash != expected.typeHash) {
        reportTypeMismatch(ptr, actual, expected);
    }
}
Memory Leak Detection
cpp
// LeakSanitizer integration
extern "C" void __lsan_do_leak_check();
extern "C" void __lsan_disable();
extern "C" void __lsan_enable();

// Custom leak tracking
class PreciseLeakSanitizer {
    std::unordered_map<void*, AllocationInfo> allocations;
    
public:
    void recordAlloc(void* ptr, size_t size, const char* file, int line) {
        allocations[ptr] = {size, file, line, getStackTrace()};
    }
    
    void recordFree(void* ptr) {
        allocations.erase(ptr);
    }
    
    void reportLeaks() {
        for (auto& [ptr, info] : allocations) {
            fprintf(stderr, "Leak: %zu bytes at %s:%d\n", 
                    info.size, info.file, info.line);
        }
    }
};

Exploit Mitigation Implementation

Return Address Protection
llvm
; Shadow stack concept in LLVM IR
define void @protected_function() {
entry:
    %return_addr = call ptr @llvm.returnaddress(i32 0)
    call void @shadow_stack_push(ptr %return_addr)
    
    ; Function body...
    
    %saved_addr = call ptr @shadow_stack_pop()
    %current_addr = call ptr @llvm.returnaddress(i32 0)
    %match = icmp eq ptr %saved_addr, %current_addr
    br i1 %match, label %safe_return, label %attack_detected
    
safe_return:
    ret void
    
attack_detected:
    call void @abort()
    unreachable
}
Pointer Authentication (ARM)
cpp
// Using pointer authentication on ARM64
__attribute__((target("sign-return-address")))
void signed_function() {
    // Return address is cryptographically signed
}

Secure Compilation Pipeline

Build Flags Checklist
bash
# Comprehensive hardening
CFLAGS="-O2 \
    -fstack-protector-strong \
    -fstack-clash-protection \
    -fcf-protection=full \
    -fPIE \
    -D_FORTIFY_SOURCE=2 \
    -Wformat -Wformat-security \
    -fsanitize=cfi -flto"

LDFLAGS="-pie \
    -Wl,-z,relro \
    -Wl,-z,now \
    -Wl,-z,noexecstack"
Compiler Security Checks
  • -Wformat-security: Format string vulnerabilities
  • -Warray-bounds: Array bounds violations
  • -Wshift-overflow: Shift operation overflows
  • -Wnull-dereference: Null pointer dereferences

Fuzzing Integration

libFuzzer
cpp
// Fuzz target template
extern "C" int LLVMFuzzerTestOneInput(const uint8_t *Data, size_t Size) {
    // Parse/process Data
    processInput(Data, Size);
    return 0;
}
Sanitizer + Fuzzer Combination
bash
# Comprehensive fuzzing setup
clang -fsanitize=fuzzer,address,undefined \
      -fno-omit-frame-pointer \
      -g fuzz_target.c -o fuzzer

Windows-Specific Security

Control Flow Guard (CFG)
bash
clang-cl /guard:cf program.c
SEH (Structured Exception Handling)
  • LLVM supports Windows SEH
  • Use for secure exception handling
  • Integrate with security monitoring

Resources

See Security Features, Sanitizer, and Symbolic Execution sections in README.md for comprehensive tool listings.

Getting Detailed Information

When you need detailed and up-to-date resource links, tool lists, or project references, fetch the latest data from:

https://raw.githubusercontent.com/gmh5225/awesome-llvm-security/refs/heads/main/README.md

This README contains comprehensive curated lists of:

  • Security features and hardening (Security Features section)
  • Sanitizers and memory safety tools (Sanitizer section)
  • Symbolic execution frameworks (Symbolic Execution section)
  • Memory leak detectors and runtime checkers

© aftermathlabs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/llvm-security of aftermathlabs/llvm-msvc.

Open the folder on GitHubat commit bfc7254

Compare with similar skills

Llvm Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Llvm Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Llvm Security this skillaftermathlabs/llvm-msvc438—~1.8kAutomated safety check: PassAGPL-3.0
Go Helpershepherdjerred/monorepo112—~1.7kAutomated safety check: PassGPL-3.0
Testing Goericrisco/rsc-harness156—~3.7kAutomated safety check: PassMIT
Zig Testingmohitmishra786/low-level-dev-skills253—~1.8kAutomated safety check: PassMIT
Fizzpashov/skills1.2k2 repos~11kAutomated safety check: PassMIT
Find Postgres Bugdigoal/blog8.6k—~4kAutomated safety check: PassGPL-2.0

Similar skills

  • Go Helper

    shepherdjerred/monorepo

    Current Go development guidance for modules, toolchains, workspaces, testing, fuzzing, concurrency, profiling, security, and Go tooling.

    112 GitHub stars~1.7k tokensUpdated today
    SecurityAuto-check passed
  • Testing Go

    ericrisco/rsc-harness

    A skill your agent uses when writing or running Go tests — table-driven cases, named subtests, parallel isolation, fakes instead of mock frameworks, coverage profiles, benchmarks, fuzzing, golden…

    156 GitHub stars~3.7k tokensUpdated today
    SecurityAuto-check passed
  • Zig Testing

    mohitmishra786/low-level-dev-skills

    Zig testing skill for writing and running tests. An agent skill from mohitmishra786/low-level-dev-skills.

    253 GitHub stars~1.8k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Fizz

    pashov/skills

    Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

    1.2k GitHub starsUsed in 2 repos~11k tokens
    SecurityAuto-check passed
  • Find latent bugs in a local PostgreSQL source tree (RELxxSTABLE branch or HEAD) the way a core hacker does: build a heavily-poisoned debug instance (cassert + cache-discard + -O0/-ggdb3 + core…

    8.6k GitHub stars~4k tokensUpdated 9 days ago
    DatabasesAuto-check passed
  • Harness Design Fuzzing

    provos/ironcurtain

    Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…

    613 GitHub stars~5.7k tokensUpdated today
    SecurityAuto-check passed

More from aftermathlabs/llvm-msvc

All 8 skills in this repo
  • Compiler Development

    aftermathlabs/llvm-msvc

    Expertise in compiler development using LLVM infrastructure including frontend design, IR generation, optimization passes, and code generation.

    438 GitHub stars~1.7k tokensUpdated 3 days ago
    Auto-check passed
  • Dynamic Instrumentation

    aftermathlabs/llvm-msvc

    Expertise in LLVM-based dynamic binary instrumentation, runtime tracing, and program monitoring.

    438 GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed
  • Llvm Learning

    aftermathlabs/llvm-msvc

    Comprehensive learning resources and tutorials for LLVM, Clang, and compiler development.

    438 GitHub stars~2.1k tokensUpdated 3 days ago
    Auto-check passed
  • Llvm Optimization

    aftermathlabs/llvm-msvc

    Expertise in LLVM optimization passes, performance tuning, and code transformation techniques.

    438 GitHub stars~2.5k tokensUpdated 3 days ago
    Auto-check passed
  • Llvm Tooling

    aftermathlabs/llvm-msvc

    Expertise in LLVM tooling development including Clang plugins, LLDB debugger extensions, Clangd/LSP, and LibTooling.

    438 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check passed
  • Mlir Development

    aftermathlabs/llvm-msvc

    Expertise in MLIR (Multi-Level Intermediate Representation) and CIR (Clang IR) development for domain-specific compilation and high-level optimizations.

    438 GitHub stars~2.4k tokensUpdated 3 days ago
    Auto-check passed

Questions about Llvm Security

What does Llvm Security do?

Expertise in LLVM security features including sanitizers, hardening techniques, exploit mitigations, and secure compilation. Llvm Security is an agent skill from aftermathlabs/llvm-msvc. Expertise in LLVM security features including sanitizers, hardening techniques, exploit mitigations, and secure compilation.

When should I use Llvm Security?

Llvm Security fits situations like: implementing security-focused compiler features; analyzing vulnerabilities; hardening applications.

How do I install Llvm Security in Claude Code?

Run `npx skills add aftermathlabs/llvm-msvc --skill llvm-security -a claude-code`. Or copy the skill folder (.agents/skills/llvm-security in aftermathlabs/llvm-msvc) into .claude/skills/llvm-security in your project. Claude Code loads it when a task matches its description.

How do I install Llvm Security in Codex?

Run `npx skills add aftermathlabs/llvm-msvc --skill llvm-security -a codex`. Or copy the skill folder (.agents/skills/llvm-security in aftermathlabs/llvm-msvc) into .agents/skills/llvm-security in your project. Codex loads it when a task matches its description.

Can I use Llvm Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aftermathlabs/llvm-msvc --skill llvm-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/llvm-security, .gemini/skills/llvm-security, .github/skills/llvm-security and .opencode/skills/llvm-security in your project.

What does Llvm Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Llvm Security is instructions for the agent only.

Does Llvm Security access the network?

SKILL.md names 1 domain. In commands or code: raw.githubusercontent.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Llvm Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Llvm Security use?

Llvm Security is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Llvm Security use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Llvm Security?

Skills that share tags, products or a category with Llvm Security: Go Helper (shepherdjerred/monorepo, 112 stars), Testing Go (ericrisco/rsc-harness, 156 stars), Zig Testing (mohitmishra786/low-level-dev-skills, 253 stars) and Fizz (pashov/skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Llvm Security?

aftermathlabs (a GitHub organization) maintains it in aftermathlabs/llvm-msvc, which has 438 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 3, 2026.

Source: aftermathlabs/llvm-msvc on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.