Release Process
scragnog/HOT-Step-CPP
Runbook for cutting and publishing a HOT-Step CPP release via a v git tag that triggers the multi-platform CI build and drafts a GitHub Release.
Binary hardening skill for security-hardened C/C++ builds. An agent skill from mohitmishra786/low-level-dev-skills.
$ npx skills add mohitmishra786/low-level-dev-skills --skill binary-hardening -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mohitmishra786/low-level-dev-skills binary-hardening --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/runtimes/binary-hardening .claude/skills/binary-hardening && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "binary-hardening" agent skill from https://github.com/mohitmishra786/low-level-dev-skills/tree/main/skills/runtimes/binary-hardening into .claude/skills/binary-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "binary-hardening", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mohitmishra786/low-level-dev-skills/tree/main/skills/runtimes/binary-hardeningType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mohitmishra786/low-level-dev-skills --skill binary-hardening -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mohitmishra786/low-level-dev-skills binary-hardening --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/runtimes/binary-hardening .agents/skills/binary-hardening && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "binary-hardening" agent skill from https://github.com/mohitmishra786/low-level-dev-skills/tree/main/skills/runtimes/binary-hardening into .agents/skills/binary-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "binary-hardening", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mohitmishra786/low-level-dev-skills --skill binary-hardening -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mohitmishra786/low-level-dev-skills binary-hardening --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/runtimes/binary-hardening .cursor/skills/binary-hardening && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "binary-hardening" agent skill from https://github.com/mohitmishra786/low-level-dev-skills/tree/main/skills/runtimes/binary-hardening into .cursor/skills/binary-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "binary-hardening", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mohitmishra786/low-level-dev-skills.git --path skills/runtimes/binary-hardening--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mohitmishra786/low-level-dev-skills --skill binary-hardening -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mohitmishra786/low-level-dev-skills binary-hardening --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/runtimes/binary-hardening .gemini/skills/binary-hardening && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "binary-hardening" agent skill from https://github.com/mohitmishra786/low-level-dev-skills/tree/main/skills/runtimes/binary-hardening into .gemini/skills/binary-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "binary-hardening", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mohitmishra786/low-level-dev-skills binary-hardeningInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mohitmishra786/low-level-dev-skills --skill binary-hardening -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/runtimes/binary-hardening .github/skills/binary-hardening && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "binary-hardening" agent skill from https://github.com/mohitmishra786/low-level-dev-skills/tree/main/skills/runtimes/binary-hardening into .github/skills/binary-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "binary-hardening", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mohitmishra786/low-level-dev-skills --skill binary-hardening -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mohitmishra786/low-level-dev-skills binary-hardening --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/runtimes/binary-hardening .opencode/skills/binary-hardening && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "binary-hardening" agent skill from https://github.com/mohitmishra786/low-level-dev-skills/tree/main/skills/runtimes/binary-hardening into .opencode/skills/binary-hardening/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "binary-hardening", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
binary-hardeningBinary hardening skill for security-hardened C/C++ builds. An agent skill from mohitmishra786/low-level-dev-skills.
Binary Hardening is an agent skill from mohitmishra786/low-level-dev-skills. Binary hardening skill for security-hardened C/C++ builds. Use when enabling RELRO, PIE, stack canaries, FORTIFYSOURCE, CFI sanitizers, shadow stack, or seccomp-bpf syscall filtering. Covers checksec analysis, compiler and linker flags for hardened builds, and NSA/CISA-recommended mitigations. Activates on queries about binary hardening, checksec, RELRO, PIE, stack canaries, FORTIFYSOURCE, CFI, shadow stack, or seccomp.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/hardening-flags.md`).
It sits in DevOps & Cloud, covering Deployment. It works with C++. The repository describes itself as: A curated suite of AI agent skills for systems and low-level programming with C/C++, Rust, and Zig toolchains, covering compilers, debuggers, profilers, build systems…. The licence is MIT.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit bdc5847. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pipFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Binary Hardening loads about 2k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 111 tokens; SKILL.md has 382 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from mohitmishra786/low-level-dev-skills at commit bdc5847, republished under its MIT licence (© mohitmishra786). 382 words, ~1,993 tokens.
.claude/skills/binary-hardening/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Guide agents through enabling and verifying binary security mitigations: checksec analysis, compiler and linker hardening flags (RELRO, PIE, stack canaries, FORTIFY_SOURCE, CFI), hardware shadow stack, and seccomp-bpf syscall filtering for defense-in-depth.
# Install checksec
pip install checksec.py # or: apt install checksec
# Check a binary
checksec --file=./mybinary
checksec --file=/usr/bin/ssh
# Output example
# RELRO STACK CANARY NX PIE RPATH RUNPATH Symbols FORTIFY Fortified Fortifiable FILE
# Full RELRO Canary found NX PIE No RPATH No RUNPATH No Symbols Yes 6 10 ./mybinary
# Check all binaries in a directory
checksec --dir=/usr/bin| Protection | Good value | Concern |
|---|---|---|
| RELRO | Full RELRO | Partial / No RELRO |
| Stack Canary | Canary found | No canary |
| NX | NX enabled | NX disabled |
| PIE | PIE enabled | No PIE |
| FORTIFY | Yes | No |
# Full hardened build (GCC or Clang)
CFLAGS="-O2 -pipe \
-fstack-protector-strong \
-fstack-clash-protection \
-fcf-protection \
-D_FORTIFY_SOURCE=3 \
-D_GLIBCXX_ASSERTIONS \
-fPIE \
-Wformat -Wformat-security -Werror=format-security"
LDFLAGS="-pie \
-Wl,-z,relro \
-Wl,-z,now \
-Wl,-z,noexecstack \
-Wl,-z,separate-code"
gcc ${CFLAGS} -o prog main.c ${LDFLAGS}Flag reference:
| Flag | Protection | Notes |
|---|---|---|
-fstack-protector-strong | Stack canary | Stronger than -fstack-protector |
-fstack-clash-protection | Stack clash | Prevents huge stack allocations |
-fcf-protection | Intel CET (IBT+SHSTK) | x86 hardware CFI (kernel+CPU required) |
-D_FORTIFY_SOURCE=2 | Buffer overflow checks | Adds bounds checks to string/mem functions |
-D_FORTIFY_SOURCE=3 | Enhanced FORTIFY | GCC ≥12, Clang ≥12 |
-fPIE + -pie | PIE/ASLR | Position independent executable |
-Wl,-z,relro | Partial RELRO | Makes GOT read-only before main |
-Wl,-z,now | Full RELRO | Resolves all PLT at startup → GOT fully RO |
-Wl,-z,noexecstack | NX stack | Marks stack non-executable |
Clang's CFI prevents calling virtual functions through wrong types (vtable CFI) and indirect calls to mismatched functions:
# Clang CFI — requires LTO and visibility
clang -fsanitize=cfi -fvisibility=hidden -flto \
-O2 -fPIE -pie main.cpp -o prog
# Specific CFI checks
clang -fsanitize=cfi-vcall # virtual call type check
clang -fsanitize=cfi-icall # indirect call type check
clang -fsanitize=cfi-derived-cast # derived-to-base cast
clang -fsanitize=cfi-unrelated-cast # unrelated type cast
# Cross-DSO CFI (across shared libraries — more complex)
clang -fsanitize=cfi -fsanitize-cfi-cross-dso -flto -fPIC -shared# Microsoft CFG (Windows equivalent)
cl /guard:cf prog.c
link /guard:cf prog.obj# GCC canary options
-fno-stack-protector # disabled
-fstack-protector # protect functions with alloca or buffers > 8 bytes
-fstack-protector-strong # protect functions with local arrays/addresses taken
-fstack-protector-all # protect all functions (slowest, most complete)
# Verify canary presence
objdump -d prog | grep -A5 "__stack_chk"
readelf -s prog | grep "stack_chk"FORTIFY_SOURCE wraps unsafe libc functions (memcpy, strcpy, sprintf) with bounds-checked versions when the buffer size can be determined at compile time:
# Level 2 (GCC/Clang default for hardened builds)
-D_FORTIFY_SOURCE=2
# Runtime check: abort() on overflow
# Level 3 (GCC ≥12, catches more cases)
-D_FORTIFY_SOURCE=3
# Adds dynamic buffer size tracking for more coverage
# Check FORTIFY coverage
objdump -d prog | grep "__.*_chk" # fortified variants
checksec --file=prog | grep FORTIFY#include <seccomp.h>
void apply_seccomp_filter(void) {
scmp_filter_ctx ctx;
// Default: kill process on any non-allowlisted syscall
ctx = seccomp_init(SCMP_ACT_KILL_PROCESS);
// Allowlist needed syscalls
seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(read), 0);
seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(write), 0);
seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(exit_group), 0);
seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(brk), 0);
seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(mmap), 0);
// Apply filter (irreversible after this point)
seccomp_load(ctx);
seccomp_release(ctx);
}
// Call early in main(), after all setup
int main(void) {
// ... initialization ...
apply_seccomp_filter();
// ... restricted operation ...
}# Test seccomp filter with strace
strace -e trace=all ./prog 2>&1 | grep "killed by SIGSYS"
# Profile syscalls to build allowlist
strace -c ./prog # count all syscalls used# Full CET: SHSTK (shadow stack) + IBT (indirect branch tracking)
gcc -fcf-protection=full -O2 -o prog main.c
# Verify in binary
readelf -n prog | grep -E 'SHSTK|IBT'
readelf --notes prog | grep GNU_PROPERTY
# IBT landing pads in disassembly
objdump -d prog | grep endbr64
# CPU and kernel support
grep -m1 shstk /proc/cpuinfoRequires hardware CET support (Intel Tiger Lake+ for SHSTK/IBT; AMD Zen 3+ for shadow stack on supported SKUs) and a kernel built with CET enabled.
# Branch Target Identification + Pointer Authentication
gcc -mbranch-protection=standard -O2 -o prog main.c
# Or: -mbranch-protection=bti+pauth
readelf -n prog | grep -E 'BTI|PAC'
llvm-objdump -d prog | grep bti| Feature | Protects |
|---|---|
| BTI | Indirect branch to non-marked targets |
| PAC | Signed return addresses and pointers (ARMv8.3+) |
# Userspace MTE tagging (experimental, arm64 hardware)
clang -fsanitize=memtag -g -o prog main.c
# Check MTE CPU support
grep -m1 mte /proc/cpuinfoMTE assigns 4-bit tags to 16-byte granules — hardware detects tag mismatch on access.
# Recent glibc may enable shadow stack for CET when hardware supports SHSTK
ldd --version # feature availability varies by distro glibc build
# Explicit link with shadow stack support (toolchain dependent)
gcc -fcf-protection=full -Wl,-z,shstk -o prog main.c
# Verify GNU_PROPERTY_SHSTK in output
readelf -n prog | grep SHSTKShadow stack maintains a hardware-protected copy of return addresses separate from the data stack.
For the full hardening flags reference, see references/hardening-flags.md.
skills/runtimes/sanitizers for ASan/UBSan during developmentskills/observability/ebpf for seccomp-bpf program writing with libbpfskills/rust/rust-security for Rust's memory-safety hardening approachskills/binaries/elf-inspection to verify mitigations in ELF binaries© mohitmishra786, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/runtimes/binary-hardening of mohitmishra786/low-level-dev-skills.
Open the folder on GitHubat commit bdc5847
Binary Hardening next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Binary Hardening this skillmohitmishra786/low-level-dev-skills | 253 | — | ~2k | Automated safety check: Pass | MIT | |
| Release Processscragnog/HOT-Step-CPP | 173 | — | ~5.1k | Automated safety check: Pass | MIT | |
| Genie API Service Docsqualcomm/qai-appbuilder | 247 | — | ~840 | Automated safety check: Pass | Custom licence | |
| Kubeshark Installerkubeshark/kubeshark | 12k | — | ~3.6k | Automated safety check: Notes | Apache-2.0 | |
| GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb | 6.7k | — | ~4k | Automated safety check: Notes | Apache-2.0 | |
| KubeSphere ServiceMesh Managerkubesphere/kubesphere | 17k | — | ~2.4k | Automated safety check: Pass | Custom licence |
scragnog/HOT-Step-CPP
Runbook for cutting and publishing a HOT-Step CPP release via a v git tag that triggers the multi-platform CI build and drafts a GitHub Release.
qualcomm/qai-appbuilder
GenieAPIService technical documentation retrieval. An agent skill from qualcomm/qai-appbuilder.
kubeshark/kubeshark
Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.
GreptimeTeam/greptimedb
Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.
kubesphere/kubesphere
Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.
remotion-dev/remotion
Set up a Codex monitor for Vercel deployments and preview URLs.
mohitmishra786/low-level-dev-skills
Guides reading and writing AArch64 and ARM Thumb assembly: compiler output, inline asm, registers, the AAPCS calling convention and NEON or SVE basics.
mohitmishra786/low-level-dev-skills
Reference for RISC-V assembly on RV32 and RV64: register names and calling convention, extension naming, GCC and Clang inline asm, and QEMU with GDB debugging.
mohitmishra786/low-level-dev-skills
Explains x86-64 registers, the System V AMD64 calling convention, and how to read compiler-generated or inline assembly.
mohitmishra786/low-level-dev-skills
Guides your agent through Bazel for C/C++ projects: BUILD files, Bzlmod dependencies, toolchain registration, remote execution, dependency queries and sandbox debugging.
mohitmishra786/low-level-dev-skills
GNU binutils skill for binary manipulation and analysis. An agent skill from mohitmishra786/low-level-dev-skills.
mohitmishra786/low-level-dev-skills
Build acceleration skill for C/C++ projects. An agent skill from mohitmishra786/low-level-dev-skills.
Works with
Categories
Binary hardening skill for security-hardened C/C++ builds. An agent skill from mohitmishra786/low-level-dev-skills. Binary Hardening is an agent skill from mohitmishra786/low-level-dev-skills. Binary hardening skill for security-hardened C/C++ builds.
Binary Hardening fits situations like: seccomp-bpf syscall filtering; tasks that involve Deployment.
Run `npx skills add mohitmishra786/low-level-dev-skills --skill binary-hardening -a claude-code`. Or copy the skill folder (skills/runtimes/binary-hardening in mohitmishra786/low-level-dev-skills) into .claude/skills/binary-hardening in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mohitmishra786/low-level-dev-skills --skill binary-hardening -a codex`. Or copy the skill folder (skills/runtimes/binary-hardening in mohitmishra786/low-level-dev-skills) into .agents/skills/binary-hardening in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitmishra786/low-level-dev-skills --skill binary-hardening -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/binary-hardening, .gemini/skills/binary-hardening, .github/skills/binary-hardening and .opencode/skills/binary-hardening in your project.
Going by SKILL.md and its folder, Binary Hardening needs the command-line tools its instructions call (pip). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Binary Hardening is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 750 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Binary Hardening: Release Process (scragnog/HOT-Step-CPP, 173 stars), Genie API Service Docs (qualcomm/qai-appbuilder, 247 stars), Kubeshark Installer (kubeshark/kubeshark, 12k stars) and GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mohitmishra786 (a GitHub user) maintains it in mohitmishra786/low-level-dev-skills, which has 253 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on June 27, 2026.
Source: mohitmishra786/low-level-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.