Agent skill

Vcv Static Analysis

by clone45 in clone45/voxglitch

Run the VCV Rack library's static-analysis check on voxglitch locally, before submitting a release.

GPL-3.0Auto-check passedSecurity

Install Vcv Static Analysis

skills CLI
$ npx skills add clone45/voxglitch --skill vcv-static-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install clone45/voxglitch vcv-static-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/clone45/voxglitch.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/vcv-static-analysis .claude/skills/vcv-static-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vcv-static-analysis
GitHub stars
131
Token cost
~1.2k tokens
SKILL.md length
547 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
GPL-3.0

At a glance

Run the VCV Rack library's static-analysis check on voxglitch locally, before submitting a release.

  • Preparing a plugin submission
  • SKILL.md covers Run it, Fixing uninitialized members, Checking a build and Reading the results, plus 2 more sections
  • Calls python3
  • The library files a Static analysis issues ticket

What it does

Vcv Static Analysis is an agent skill from clone45/voxglitch. Run the VCV Rack library's static-analysis check on voxglitch locally, before submitting a release. Use when preparing a plugin submission, when the library files a "Static analysis issues" ticket, when asked to check for new cppcheck warnings, or when asked to fix uninitialized member variables.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Static analysis and SAST. The licence is GPL-3.0.

When your agent uses it

  • Preparing a plugin submission
  • The library files a Static analysis issues ticket
  • Asked to check for new cppcheck warnings
  • Asked to fix uninitialized member variables

Example prompts

  • “Static analysis issues”
  • “/vcv-static-analysis”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 0baadb5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vcv Static Analysis loads about 1.2k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 547 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from clone45/voxglitch at commit 0baadb5, republished under its GPL-3.0 licence (© clone45). 547 words, ~1,168 tokens.

Download SKILL.mdSave it as .claude/skills/vcv-static-analysis/SKILL.md (or your agent's skills folder).
name
vcv-static-analysis
description
Run the VCV Rack library's static-analysis check on voxglitch locally, before submitting a release. Use when preparing a plugin submission, when the library files a "Static analysis issues" ticket, when asked to check for new cppcheck warnings, or when asked to fix uninitialized member variables.

VCV Rack static analysis

The VCV library runs rack-integration-tools at integration time and files a "Static analysis issues" ticket when it finds problems (first seen on voxglitch as issue #281, August 2026). This reproduces that run locally so a release can be checked before submitting.

Run it

bash
python3 scripts/static_analysis/analyze.py

About 5 seconds. Exits 1 if anything appears that isn't in the committed baseline; prints only what's new.

The very first run on a machine builds cppcheck 2.21.1 into ~/.cache/voxglitch-static-analysis/ (one time, 2-4 minutes, needs git, cmake, a C++ compiler). Every run after that reuses it. Say so before starting if it's going to build, so the wait isn't a surprise.

Other flags:

--alllist every current finding, not just new ones
--update-baselineaccept the current state (use after deliberately fixing or accepting findings)
--xml out.xmlkeep the raw cppcheck XML

Fixing uninitialized members

The single largest category. Rack widgets are configured after construction, so cppcheck can't see the assignment and warns.

bash
python3 scripts/static_analysis/fix_uninitialized.py           # preview
python3 scripts/static_analysis/fix_uninitialized.py --apply   # write

Then build, then run analyze.py again — findings are reported at the constructor line, so one reported location can hide several members and a second pass often finds more. Repeat until clean.

Always verify a pointer is genuinely assigned before use before accepting a = nullptr. It's almost always right (it turns a garbage-pointer dereference into an immediate null crash), but confirm the wiring exists rather than assuming.

Checking a build

There's no working make in WSL here (the checked-in build/ holds Windows paths and breaks the dependency files). To syntax-check what the Makefile actually compiles:

bash
S=../Rack-SDK
for f in src/*.cpp src/modules/*.cpp; do
  g++ -fsyntax-only -std=c++11 -DARCH_LIN -Isrc -I$S/include -I$S/dep/include "$f" || echo "FAILED: $f"
done

35 translation units. Note -Isrc only — adding -Isrc/vgLib-2.0 shadows Rack's own common.hpp and produces a flood of bogus errors.

Show full SKILL.md (275 more words)Show less

Reading the results

Findings split into voxglitch code and vendored third-party — currently just dr_wav.h/dr_mp3.h, which are dr_libs. The maintainer has said he ignores those as too noisy. Vendored findings are not voxglitch's to fix — say so rather than "fixing" vendored code.

Note the library's invocation passes no dep/ suppression, so any vendored code kept under src/ lands in its report.

Known-benign, currently in the baseline:

  • duplInheritedMember (7) — KaisekiSamplePlayer methods that genuinely extend SamplePlayer (trigger, step, stepReverse, stop, loadSample, releaseSample, initialize). SamplePlayer has no vtable and is used by nine other modules, with step/stepReverse on the per-sample audio path, so these were left shadowing deliberately. Latent, not live: every call site holds the derived type and nothing casts to a SamplePlayer pointer or reference. Watch for that changing.
  • dangerousTypeCast (2) — old-style C casts in KaisekiReceiver.hpp.

Do not draft the issue reply

Bret writes the replies to cschol's tickets himself. Offer analysis and code fixes; don't offer to write or post the comment.

How this matches the library's run

The invocation in analyze.py is copied from the issue body verbatim:

cppcheck --std=c++11 --max-configs=1 --enable=warning -j 8 -q --xml <304 files>

The file list is derived (src/**/*.cpp sorted, then src/**/*.hpp sorted; no .h), which reproduces the library's 304-file list exactly and stays correct as modules are added. Verified against issue #281: all 189 reported findings reproduce, none missing.

The version matters. dangerousTypeCast only exists from cppcheck 2.18.0; Ubuntu's apt ships 2.7, which silently misses three of the checks entirely. That's why it's pinned and built rather than installed.

Note the library's command has no dep/ suppression, which is why vendored oscpack and dr_libs appear at all. cschol's documented flags elsewhere do use -i.../dep -i.../tests, so this may change.

© clone45, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/vcv-static-analysis of clone45/voxglitch.

Open the folder on GitHubat commit 0baadb5

Compare with similar skills

Vcv Static Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vcv Static Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vcv Static Analysis this skillclone45/voxglitch131—~1.2kAutomated safety check: PassGPL-3.0
Semgrepvigolium/piolium1401 repos~2.4kAutomated safety check: NotesMIT
C To AstNarwhal-Lab/MagicSkills316—~1.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
LLM Sast ScannerSunWeb3Sec/llm-sast-scanner286—~6.2kAutomated safety check: PassNone
Sast SemgrepAgentSecOps/SecOpsAgentKit2202 repos~2.4kAutomated safety check: PassCustom licence

Similar skills

  • Semgrep

    vigolium/piolium

    Run Semgrep static analysis scan on a codebase using parallel subagents.

    140 GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • C To Ast

    Narwhal-Lab/MagicSkills

    Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

    316 GitHub stars~1.1k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated today
    SecurityAuto-check: notes
  • LLM Sast Scanner

    SunWeb3Sec/llm-sast-scanner

    General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.

    286 GitHub stars~6.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Sast Semgrep

    AgentSecOps/SecOpsAgentKit

    Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

    220 GitHub starsUsed in 2 repos~2.4k tokens
    SecurityAuto-check passed
  • Triage Codeql

    netdata/netdata

    Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

    81k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes

More from clone45/voxglitch

  • Release Check

    clone45/voxglitch

    Pre-release readiness check for the voxglitch plugin, run before submitting a version to the VCV Rack library.

    131 GitHub stars~781 tokensUpdated 23 days ago
    Auto-check passed

Categories

Questions about Vcv Static Analysis

What does Vcv Static Analysis do?

Run the VCV Rack library's static-analysis check on voxglitch locally, before submitting a release. Vcv Static Analysis is an agent skill from clone45/voxglitch. Run the VCV Rack library's static-analysis check on voxglitch locally, before submitting a release.

When should I use Vcv Static Analysis?

Vcv Static Analysis fits situations like: preparing a plugin submission; the library files a Static analysis issues ticket; asked to check for new cppcheck warnings; asked to fix uninitialized member variables.

How do I install Vcv Static Analysis in Claude Code?

Run `npx skills add clone45/voxglitch --skill vcv-static-analysis -a claude-code`. Or copy the skill folder (.claude/skills/vcv-static-analysis in clone45/voxglitch) into .claude/skills/vcv-static-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Vcv Static Analysis in Codex?

Run `npx skills add clone45/voxglitch --skill vcv-static-analysis -a codex`. Or copy the skill folder (.claude/skills/vcv-static-analysis in clone45/voxglitch) into .agents/skills/vcv-static-analysis in your project. Codex loads it when a task matches its description.

Can I use Vcv Static Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add clone45/voxglitch --skill vcv-static-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vcv-static-analysis, .gemini/skills/vcv-static-analysis, .github/skills/vcv-static-analysis and .opencode/skills/vcv-static-analysis in your project.

What does Vcv Static Analysis need to run?

Going by SKILL.md and its folder, Vcv Static Analysis needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Vcv Static Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vcv Static Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vcv Static Analysis use?

Vcv Static Analysis is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vcv Static Analysis use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vcv Static Analysis?

Skills that share tags, products or a category with Vcv Static Analysis: Semgrep (vigolium/piolium, 140 stars), C To Ast (Narwhal-Lab/MagicSkills, 316 stars), Semgrep Security Scan (trailofbits/skills, 7.4k stars) and LLM Sast Scanner (SunWeb3Sec/llm-sast-scanner, 286 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vcv Static Analysis?

clone45 (a GitHub user) maintains it in clone45/voxglitch, which has 131 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on September 14, 2026.

Source: clone45/voxglitch on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.