Reproduce and triage sanitizer and Valgrind findings against iccDEV tools with authoritative exit-code and stack-frame handling.

BSD-3-ClauseAuto-check passedDevelopment

Install Sanitizer Repro

skills CLI
$ npx skills add InternationalColorConsortium/iccDEV --skill sanitizer-repro -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install InternationalColorConsortium/iccDEV sanitizer-repro --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/InternationalColorConsortium/iccDEV.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/sanitizer-repro .claude/skills/sanitizer-repro && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sanitizer-repro
GitHub stars
183
Token cost
~1.4k tokens
SKILL.md length
574 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
BSD-3-Clause

At a glance

Reproduce and triage sanitizer and Valgrind findings against iccDEV tools with authoritative exit-code and stack-frame handling.

  • Works in 10 steps: For a CodeQL alert, establish… → Build from a clean CMake cache with… → Verify sanitizer linkage before claiming… → …
  • Development work in your project
  • SKILL.md covers Workflow, Uninitialized-memory and race…, Build and References
  • Calls cmake and make

What it does

Sanitizer Repro is an agent skill from InternationalColorConsortium/iccDEV. Reproduce and triage sanitizer and Valgrind findings against iccDEV tools with authoritative exit-code and stack-frame handling.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The repository describes itself as: iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. The licence is BSD-3-Clause.

When your agent uses it

  • Development work in your project

Example prompts

  • “/sanitizer-repro”

Requirements

  • Pre-approved tools (allowed-tools): bash, read, grep, glob, shell(git:*)

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. For a CodeQL alert, establish profile-to-tool reachability before creating a
  2. Build from a clean CMake cache with sanitizer flags.
  3. Verify sanitizer linkage before claiming coverage.
  4. Run the exact reproduction command and capture exit code plus stderr.
  5. Classify exit codes: 0 success, 1-127 graceful failure, 128+ signal.
  6. Attribute root cause from sanitizer stack frames, not PoC filenames.
  7. Inspect tool argument semantics before writing a one-liner. If a tool
  8. For sanitizer noise triage, distinguish runtime suppressions from compile-time
  9. Minimize reproduction steps while keeping them copy-pasteable. When a
  10. File or update issues using the canonical security format.

What it can do on your machine

Read from SKILL.md and the folder at commit 3c2425d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • bash
    • read
    • grep
    • glob
    • shell(git:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cmake
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sanitizer Repro loads about 1.4k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 574 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from InternationalColorConsortium/iccDEV at commit 3c2425d, republished under its BSD-3-Clause licence (© InternationalColorConsortium). 574 words, ~1,381 tokens.

Download SKILL.mdSave it as .claude/skills/sanitizer-repro/SKILL.md (or your agent's skills folder).
name
sanitizer-repro
description
Reproduce and triage sanitizer and Valgrind findings against iccDEV tools with authoritative exit-code and stack-frame handling.
allowed-tools
bash, read, grep, glob, shell(git:*)

Sanitizer Reproduction

Use this skill for security advisories, crash reports, fuzzing artifacts, or manual findings involving iccDEV command-line tools.

Workflow

  1. For a CodeQL alert, establish profile-to-tool reachability before creating a PoC. Trace parser, Begin(), and Apply() return propagation. If setup rejects the field and every tool caller propagates failure, classify the alert as a query false positive and add a guarded plus unguarded query test; do not force reachability with a direct API call that violates the contract.
  2. Build from a clean CMake cache with sanitizer flags.
  3. Verify sanitizer linkage before claiming coverage.
  4. Run the exact reproduction command and capture exit code plus stderr.
  5. Classify exit codes: 0 success, 1-127 graceful failure, 128+ signal.
  6. Attribute root cause from sanitizer stack frames, not PoC filenames.
  7. Inspect tool argument semantics before writing a one-liner. If a tool appends channel numbers, expands prefixes, or parses config files, preserve that behavior in the command instead of copying artifacts to synthetic names.
  8. For sanitizer noise triage, distinguish runtime suppressions from compile-time ignorelists:
    • Use Testing/silence.txt only for recoverable runtime UBSAN suppressions.
    • Use .github/ci/ubsan-ignorelist.txt plus a rebuild for fatal Clang IntegerSanitizer noise from known-benign sites.
    • Verify normal GCC and Clang builds still configure and compile; GCC ignores the Clang-only compile-time ignorelist path.
    • Keep patterns narrow. Standard-library implementation paths such as */include/c++/*/bits/... can be noise; project-owned Icc*, Tools, IccConnect, AFL, and CFL paths stay actionable unless a separate source fix or issue proves otherwise.
  9. Minimize reproduction steps while keeping them copy-pasteable. When a maintainer asks for no substitutions, the command must start with the tool binary and use literal arguments only; do not use shell variables, loops, mktemp, or copy helpers.
  10. File or update issues using the canonical security format.
Show full SKILL.md (282 more words)Show less

Uninitialized-memory and race matrix

Do not treat ASAN or UBSAN as coverage for uninitialized reads. Use each lane for its own signal:

  • Run Memcheck and Helgrind against a non-sanitized build. Do not stack Valgrind on an ASAN build.
  • Run TSan separately for data races; it does not replace MSan or Memcheck.
  • Run MSan only when dependent runtime code is also instrumented. A normal distro libstdc++, libc++, or libxml2 can leave destination shadow bytes poisoned after initializing them and produce misleading reports.
  • Do not suppress a sequence of STL frames to make MSan advance. Build the pinned instrumented libc++ runtime, then rerun the same input and controls.

Build the repository runtime and run the JSON, XML, and threaded controls with:

bash
.github/scripts/iccdev-build-msan-libcxx.sh --prefix /tmp/iccdev-msan-libcxx
.github/scripts/iccdev-msan-taint-qa.sh \
  --source-dir "$PWD" \
  --build-dir /tmp/iccdev-msan-build \
  --runtime-dir /tmp/iccdev-msan-libcxx

Despite its historical name, iccdev-build-msan-libcxx.sh installs pinned, instrumented libc++, libc++abi, and libxml2. A plain -DENABLE_MSAN=ON build instruments iccDEV itself but not distribution dependencies; do not classify reports from those libraries as iccDEV bugs.

For Valgrind-assisted taint tracing, configure with -DCMAKE_BUILD_TYPE=Debug -DICCDEV_ENABLE_TAINT_TRACE=ON, set ICC_TAINT_TRACE=1, and use .github/scripts/iccdev-taint-trace-qa.sh. The trace helpers inspect shadow state before formatting values, so logging must never dereference poisoned or unaddressable storage. Release, RelWithDebInfo, and MinSizeRel builds always compile these diagnostics out, even if the option is explicitly requested. After #2543, malformed parametric-curve arrays are rejection controls; the nonnumeric colorant PCS fixture remains the positive uninitialized-read proof.

Build

bash
cd Build && rm -rf CMakeCache.txt CMakeFiles/
CC=clang CXX=clang++ cmake Cmake -DCMAKE_BUILD_TYPE=Debug -DENABLE_TOOLS=ON -DENABLE_ASAN=ON -DENABLE_UBSAN=ON -DENABLE_INTEGER_SANITIZER=ON -DENABLE_FLOAT_SANITIZER=ON
make -j"$(nproc)"
nm Tools/IccDumpProfile/iccDumpProfile | grep -c __asan

Use CC=clang, not C=clang; after any failed compiler configure, delete both CMakeCache.txt and CMakeFiles/ before retrying. Do not enable coverage for a sanitizer reproduction because coverage instrumentation can mask findings.

For fatal Clang IntegerSanitizer noise that requires the compile-time ignorelist:

bash
CC=clang CXX=clang++ cmake -S Build/Cmake -B build-intsan \
  -DENABLE_TOOLS=ON \
  -DENABLE_INTEGER_SANITIZER=ON \
  -DUBSAN_IGNORELIST=.github/ci/ubsan-ignorelist.txt
cmake --build build-intsan --target iccApplyNamedCmm -j"$(nproc)"

Verify CMake prints -fsanitize-ignorelist= in the final sanitizer flags before claiming that an ignorelist entry was tested.

References

  • ../../prompts/reproduce-security-issue.prompt.md
  • ../../prompts/file-security-issue.prompt.md
  • ../../prompts/SECURITY_ISSUE_FORMAT.md
  • ../../../docs/bisect.md
  • ../json-config-regression/SKILL.md

© InternationalColorConsortium, BSD-3-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/sanitizer-repro of InternationalColorConsortium/iccDEV.

Open the folder on GitHubat commit 3c2425d

Compare with similar skills

Sanitizer Repro next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sanitizer Repro compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sanitizer Repro this skillInternationalColorConsortium/iccDEV183—~1.4kAutomated safety check: PassBSD-3-Clause
Vercel Composition Patternssupabase/supabase111k58 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k4 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 58 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from InternationalColorConsortium/iccDEV

All 23 skills in this repo
  • Afl Smoke

    InternationalColorConsortium/iccDEV

    Run or update the iccDEV AFL++ manual smoke workflow, seeds, and maintainer documentation.

    183 GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check passed
  • Avx2 Clut Diagnostics

    InternationalColorConsortium/iccDEV

    Diagnose runtime-dispatched AVX2 3D CLUT interpolation, collect trace evidence, validate vector and masked-tail output, and prepare optimization handoff data.

    183 GitHub stars~850 tokensUpdated 2 days ago
    Auto-check passed
  • Clusterfuzzlite

    InternationalColorConsortium/iccDEV

    Build, test, or update the iccDEV ClusterFuzzLite libFuzzer integration across ASan, UBSan, and MSan.

    183 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • iOS Clut Editor

    InternationalColorConsortium/iccDEV

    Build, review, and maintain the ios-clut-editor profile and 3D CLUT editing proof-of-concept app without repeating prior iOS review-loop failures.

    183 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • iOS Manual Examples

    InternationalColorConsortium/iccDEV

    Maintain the manual iOS example app CMake projects, local Xcode build helpers, device signing guard rails, and documentation.

    183 GitHub stars~796 tokensUpdated 2 days ago
    Auto-check passed
  • JSON Config Regression

    InternationalColorConsortium/iccDEV

    Validate iccDEV JSON/profile config parser changes with fail-closed regression gates and CLI exercises.

    183 GitHub stars~469 tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Sanitizer Repro

What does Sanitizer Repro do?

Reproduce and triage sanitizer and Valgrind findings against iccDEV tools with authoritative exit-code and stack-frame handling. Sanitizer Repro is an agent skill from InternationalColorConsortium/iccDEV. Reproduce and triage sanitizer and Valgrind findings against iccDEV tools with authoritative exit-code and stack-frame handling.

When should I use Sanitizer Repro?

Sanitizer Repro fits situations like: development work in your project.

How do I install Sanitizer Repro in Claude Code?

Run `npx skills add InternationalColorConsortium/iccDEV --skill sanitizer-repro -a claude-code`. Or copy the skill folder (.github/skills/sanitizer-repro in InternationalColorConsortium/iccDEV) into .claude/skills/sanitizer-repro in your project. Claude Code loads it when a task matches its description.

How do I install Sanitizer Repro in Codex?

Run `npx skills add InternationalColorConsortium/iccDEV --skill sanitizer-repro -a codex`. Or copy the skill folder (.github/skills/sanitizer-repro in InternationalColorConsortium/iccDEV) into .agents/skills/sanitizer-repro in your project. Codex loads it when a task matches its description.

Can I use Sanitizer Repro in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add InternationalColorConsortium/iccDEV --skill sanitizer-repro -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sanitizer-repro, .gemini/skills/sanitizer-repro, .github/skills/sanitizer-repro and .opencode/skills/sanitizer-repro in your project.

What does Sanitizer Repro need to run?

Going by SKILL.md and its folder, Sanitizer Repro needs the command-line tools its instructions call (cmake and make). Its frontmatter pre-approves these tools: bash, read, grep, glob, shell(git:*).

Does Sanitizer Repro access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sanitizer Repro safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sanitizer Repro use?

Sanitizer Repro is published under the BSD-3-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sanitizer Repro use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sanitizer Repro?

Skills that share tags, products or a category with Sanitizer Repro: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sanitizer Repro?

InternationalColorConsortium (a GitHub organization) maintains it in InternationalColorConsortium/iccDEV, which has 183 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 9, 2026.

Source: InternationalColorConsortium/iccDEV on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.