Agent skill

Static Analysis

by mohitmishra786 in mohitmishra786/low-level-dev-skills

Static analysis skill for C/C++ codebases. An agent skill from mohitmishra786/low-level-dev-skills.

MITAuto-check passedSecurity

Install Static Analysis

skills CLI
$ npx skills add mohitmishra786/low-level-dev-skills --skill static-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitmishra786/low-level-dev-skills static-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/build-systems/static-analysis .claude/skills/static-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
static-analysis
GitHub stars
253
Token cost
~1.4k tokens
SKILL.md length
238 words
Files
2 (incl. references)
Skills in repo
138
Repo updated
First seen
Licence
MIT

At a glance

Static analysis skill for C/C++ codebases. An agent skill from mohitmishra786/low-level-dev-skills.

  • Works in 8 steps: Generate compile_commands.json → Run clang-tidy → Check category decision tree → …
  • Hardening code quality
  • SKILL.md covers Purpose, Triggers, Workflow and Related skills
  • Calls cmake, pip and make

What it does

Static Analysis is an agent skill from mohitmishra786/low-level-dev-skills. Static analysis skill for C/C++ codebases. Use when hardening code quality, triaging noisy builds, running clang-tidy, cppcheck, or scan-build, interpreting check categories, suppressing false positives, or integrating static analysis into CI. Activates on queries about clang-tidy checks, cppcheck, scan-build, compilecommands.json, code hardening, or static analysis warnings.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/clang-tidy-checks.md`).

It sits in Security, covering Static analysis and SAST. It works with C++. The repository describes itself as: A curated suite of AI agent skills for systems and low-level programming with C/C++, Rust, and Zig toolchains, covering compilers, debuggers, profilers, build systems…. The licence is MIT.

When your agent uses it

  • Hardening code quality
  • Triaging noisy builds
  • Running clang-tidy
  • Interpreting check categories

Example prompts

  • “/static-analysis”

Requirements

  • Python 3

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Generate compile_commands.json
  2. Run clang-tidy
  3. Check category decision tree
  4. .clang-tidy configuration file
  5. Suppress false positives
  6. Run cppcheck
  7. Path-sensitive analysis with scan-build
  8. CI integration

What it can do on your machine

Read from SKILL.md and the folder at commit bdc5847. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cmake
    • pip
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Static Analysis loads about 1.4k tokens when it runs, and up to ~2.2k if it reads all its reference files. Until then it costs about 99 tokens; SKILL.md has 238 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~99
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitmishra786/low-level-dev-skills at commit bdc5847, republished under its MIT licence (© mohitmishra786). 238 words, ~1,433 tokens.

Download SKILL.mdSave it as .claude/skills/static-analysis/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
static-analysis
description
Static analysis skill for C/C++ codebases. Use when hardening code quality, triaging noisy builds, running clang-tidy, cppcheck, or scan-build, interpreting check categories, suppressing false positives, or integrating static analysis into CI. Activates on queries about clang-tidy checks, cppcheck, scan-build, compile_commands.json, code hardening, or static analysis warnings.

Static Analysis

Purpose

Guide agents through selecting, running, and triaging static analysis tools for C/C++ — clang-tidy, cppcheck, and scan-build — including suppression strategies and CI integration.

Triggers

  • "How do I run clang-tidy on my project?"
  • "What clang-tidy checks should I enable?"
  • "cppcheck is reporting false positives — how do I suppress them?"
  • "How do I set up scan-build for deeper analysis?"
  • "My build is noisy with static analysis warnings"
  • "How do I generate compile_commands.json for clang-tidy?"

Workflow

1. Generate compile_commands.json

clang-tidy requires a compilation database:

bash
# CMake (preferred)
cmake -S . -B build -DCMAKE_EXPORT_COMPILE_COMMANDS=ON
ln -s build/compile_commands.json .

# Bear (for Make-based projects)
bear -- make

# compiledb (alternative for Make)
pip install compiledb
compiledb make
2. Run clang-tidy
bash
# Single file
clang-tidy src/foo.c -- -std=c11 -I include/

# Whole project via compile_commands.json
run-clang-tidy -p build/ -j$(nproc)

# With specific checks enabled
clang-tidy -checks='bugprone-*,modernize-*,performance-*' src/foo.cpp

# Apply auto-fixes
clang-tidy -checks='modernize-use-nullptr' -fix src/foo.cpp
3. Check category decision tree
text
Goal?
├── Find real bugs            → bugprone-*, clang-analyzer-*
├── Modernise C++ code        → modernize-*
├── Follow core guidelines    → cppcoreguidelines-*
├── Catch performance issues  → performance-*
├── Security hardening        → cert-*, hicpp-*
└── Readability / style       → readability-*, llvm-*
CategoryKey checksWhat it catches
bugprone-*use-after-move, integer-division, suspicious-memset-usageLikely bugs
modernize-*use-nullptr, use-override, use-autoC++11/14/17 idioms
cppcoreguidelines-*avoid-goto, pro-bounds-*, no-mallocC++ Core Guidelines
performance-*unnecessary-copy-initialization, avoid-endlPerformance regressions
clang-analyzer-*core.*, unix.*, security.*Path-sensitive bugs
cert-*err34-c, str51-cppCERT coding standard
4. .clang-tidy configuration file
yaml
# .clang-tidy — place at project root
Checks: >
  bugprone-*,
  modernize-*,
  performance-*,
  -modernize-use-trailing-return-type,
  -bugprone-easily-swappable-parameters
WarningsAsErrors: 'bugprone-*,clang-analyzer-*'
HeaderFilterRegex: '^(src|include)/.*'
CheckOptions:
  - key: modernize-loop-convert.MinConfidence
    value: reasonable
  - key: readability-identifier-naming.VariableCase
    value: camelCase
5. Suppress false positives
cpp
// Suppress a single line
int result = riskyOp(); // NOLINT(bugprone-signed-char-misuse)

// Suppress a block
// NOLINTNEXTLINE(cppcoreguidelines-avoid-magic-numbers)
constexpr int BUFFER_SIZE = 4096;

// Suppress whole function
[[clang::suppress("bugprone-*")]]
void legacy_code() { /* ... */ }

Or in .clang-tidy:

yaml
# Exclude third-party directories
HeaderFilterRegex: '^(src|include)/.*'
# Disable specific checks
Checks: '-bugprone-easily-swappable-parameters'
6. Run cppcheck
bash
# Basic run
cppcheck --enable=all --std=c11 src/

# With compile_commands.json
cppcheck --project=build/compile_commands.json

# Include specific checks and suppress noise
cppcheck --enable=warning,performance,portability \
         --suppress=missingIncludeSystem \
         --suppress=unmatchedSuppression \
         --error-exitcode=1 \
         src/

# Generate XML report for CI
cppcheck --xml --xml-version=2 src/ 2> cppcheck-report.xml
--enable= valueWhat it checks
warningUndefined behaviour, bad practices
performanceRedundant operations, inefficient patterns
portabilityNon-portable constructs
informationConfiguration and usage notes
allEverything above
7. Path-sensitive analysis with scan-build
bash
# Intercept a Make build
scan-build make

# Intercept CMake build
scan-build cmake --build build/

# Show HTML report
scan-view /tmp/scan-build-*/

# With specific checkers
scan-build -enable-checker security.insecureAPI.gets \
           -enable-checker alpha.unix.cstring.BufferOverlap \
           make

scan-build finds deeper bugs than clang-tidy: use-after-free across functions, dead stores from logic errors, null dereferences on complex paths.

8. CI integration
yaml
# GitHub Actions
- name: Static analysis
  run: |
    cmake -S . -B build -DCMAKE_EXPORT_COMPILE_COMMANDS=ON
    run-clang-tidy -p build -j$(nproc) -warnings-as-errors '*'

- name: cppcheck
  run: |
    cppcheck --enable=warning,performance \
             --suppress=missingIncludeSystem \
             --error-exitcode=1 \
             src/

For clang-tidy check details, see references/clang-tidy-checks.md.

  • Use skills/compilers/clang for Clang toolchain and diagnostic flags
  • Use skills/compilers/gcc for GCC warnings as complementary analysis
  • Use skills/runtimes/sanitizers for runtime bug detection alongside static analysis
  • Use skills/build-systems/cmake for CMAKE_EXPORT_COMPILE_COMMANDS setup

© mohitmishra786, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/build-systems/static-analysis of mohitmishra786/low-level-dev-skills.

  • SKILL.md
  • references/clang-tidy-checks.md

Open the folder on GitHubat commit bdc5847

Compare with similar skills

Static Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Static Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Static Analysis this skillmohitmishra786/low-level-dev-skills253—~1.4kAutomated safety check: PassMIT
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Zeroization Audittrailofbits/skills7.4k4 repos~5.9kAutomated safety check: NotesCC-BY-SA-4.0
Constant-Time Analysistrailofbits/skills7.4k—~3.3kAutomated safety check: NotesCC-BY-SA-4.0
Taint Instrumentation AssistantArabelaTso/Skills-4-SE253—~2.9kAutomated safety check: PassApache-2.0
Codeqlgithub/awesome-copilot40k1 repos~3.4kAutomated safety check: PassMIT

Similar skills

  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated today
    SecurityAuto-check: notes
  • Zeroization Audit

    trailofbits/skills

    Official

    Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis.

    7.4k GitHub starsUsed in 4 repos~5.9k tokens
    SecurityAuto-check: notes
  • Constant-Time Analysis

    trailofbits/skills

    Official

    Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

    7.4k GitHub stars~3.3k tokensUpdated today
    SecurityAuto-check: notes
  • Taint Instrumentation Assistant

    ArabelaTso/Skills-4-SE

    Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations.

    253 GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Codeql

    github/awesome-copilot

    Official

    Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI.

    40k GitHub starsUsed in 1 repo~3.4k tokens
    SecurityAuto-check passed
  • Cpp Style

    LuisaGroup/LuisaCompute

    C++ naming, formatting, static analysis, and RTTI rules for LuisaCompute.

    1.1k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed

More from mohitmishra786/low-level-dev-skills

All 138 skills in this repo
  • ARM and AArch64 Assembly

    mohitmishra786/low-level-dev-skills

    Guides reading and writing AArch64 and ARM Thumb assembly: compiler output, inline asm, registers, the AAPCS calling convention and NEON or SVE basics.

    253 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • RISC-V Assembly Guide

    mohitmishra786/low-level-dev-skills

    Reference for RISC-V assembly on RV32 and RV64: register names and calling convention, extension naming, GCC and Clang inline asm, and QEMU with GDB debugging.

    253 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • x86-64 Assembly Reference

    mohitmishra786/low-level-dev-skills

    Explains x86-64 registers, the System V AMD64 calling convention, and how to read compiler-generated or inline assembly.

    253 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Bazel for C and C++

    mohitmishra786/low-level-dev-skills

    Guides your agent through Bazel for C/C++ projects: BUILD files, Bzlmod dependencies, toolchain registration, remote execution, dependency queries and sandbox debugging.

    253 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Binary Hardening

    mohitmishra786/low-level-dev-skills

    Binary hardening skill for security-hardened C/C++ builds. An agent skill from mohitmishra786/low-level-dev-skills.

    253 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed
  • Binutils

    mohitmishra786/low-level-dev-skills

    GNU binutils skill for binary manipulation and analysis. An agent skill from mohitmishra786/low-level-dev-skills.

    253 GitHub stars~1.2k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Questions about Static Analysis

What does Static Analysis do?

Static analysis skill for C/C++ codebases. An agent skill from mohitmishra786/low-level-dev-skills. Static Analysis is an agent skill from mohitmishra786/low-level-dev-skills. Static analysis skill for C/C++ codebases.

When should I use Static Analysis?

Static Analysis fits situations like: hardening code quality; triaging noisy builds; running clang-tidy; interpreting check categories.

How do I install Static Analysis in Claude Code?

Run `npx skills add mohitmishra786/low-level-dev-skills --skill static-analysis -a claude-code`. Or copy the skill folder (skills/build-systems/static-analysis in mohitmishra786/low-level-dev-skills) into .claude/skills/static-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Static Analysis in Codex?

Run `npx skills add mohitmishra786/low-level-dev-skills --skill static-analysis -a codex`. Or copy the skill folder (skills/build-systems/static-analysis in mohitmishra786/low-level-dev-skills) into .agents/skills/static-analysis in your project. Codex loads it when a task matches its description.

Can I use Static Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitmishra786/low-level-dev-skills --skill static-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/static-analysis, .gemini/skills/static-analysis, .github/skills/static-analysis and .opencode/skills/static-analysis in your project.

What does Static Analysis need to run?

Going by SKILL.md and its folder, Static Analysis needs the command-line tools its instructions call (cmake, pip and make). Our summary lists: Python 3.

Does Static Analysis access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Static Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Static Analysis use?

Static Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Static Analysis use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 782 tokens, read only when the agent opens those files.

What are the alternatives to Static Analysis?

Skills that share tags, products or a category with Static Analysis: CodeQL Security Scan (trailofbits/skills, 7.4k stars), Zeroization Audit (trailofbits/skills, 7.4k stars), Constant-Time Analysis (trailofbits/skills, 7.4k stars) and Taint Instrumentation Assistant (ArabelaTso/Skills-4-SE, 253 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Static Analysis?

mohitmishra786 (a GitHub user) maintains it in mohitmishra786/low-level-dev-skills, which has 253 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on June 27, 2026.

Source: mohitmishra786/low-level-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.