Agent skill

C To Ast

by Narwhal-Lab in Narwhal-Lab/MagicSkills

Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

MITAuto-check passedSecurity

Install C To Ast

skills CLI
$ npx skills add Narwhal-Lab/MagicSkills --skill c-to-ast -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Narwhal-Lab/MagicSkills c-to-ast --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Narwhal-Lab/MagicSkills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skill_template/c_2_ast .claude/skills/c-to-ast && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
c-to-ast
GitHub stars
316
Token cost
~1.1k tokens
SKILL.md length
552 words
Files
8 (incl. scripts)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

  • Works in 6 steps: Navigate to the Skill scripts directory → Handle the input C source → Run the AST extraction script → …
  • Analyzing C programs
  • SKILL.md covers Purpose, When to Use, Instructions and Output Format, plus 4 more sections
  • Runs Python scripts from its folder; calls python3

What it does

C To Ast is an agent skill from Narwhal-Lab/MagicSkills. Parse C source code into an Abstract Syntax Tree (AST). Use when analyzing C programs, understanding code structure, performing static analysis, or preparing code for further program analysis (e.g., CFG, DFG, vulnerability detection).

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts (for example `reference.md`, `scripts/c_2_ast.py` and `scripts/save_c.py`).

It sits in Security, covering Static analysis and SAST and Skill authoring. It works with Python. The repository describes itself as: MagicSkills:Stop copying skills between agents. MagicSkills turns scattered SKILL.md folders into reusable, composable, tool-ready capabilities. The licence is MIT.

When your agent uses it

  • Analyzing C programs
  • Understanding code structure
  • Performing static analysis
  • Preparing code for further program analysis (e.g.

Example prompts

  • “/c-to-ast”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Navigate to the Skill scripts directory
  2. Handle the input C source
  3. Run the AST extraction script
  4. Do not modify the source code
  5. Return the AST output verbatim
  6. If parsing fails

What it can do on your machine

Read from SKILL.md and the folder at commit 00f3e86. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 6 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

C To Ast loads about 1.1k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 552 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from Narwhal-Lab/MagicSkills at commit 00f3e86, republished under its MIT licence (© Narwhal-Lab). 552 words, ~1,116 tokens.

Download SKILL.mdSave it as .claude/skills/c-to-ast/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
c-to-ast
description
Parse C source code into an Abstract Syntax Tree (AST). Use when analyzing C programs, understanding code structure, performing static analysis, or preparing code for further program analysis (e.g., CFG, DFG, vulnerability detection).

C to AST Skill

Purpose

This Skill converts C source code into its Abstract Syntax Tree (AST) representation.

Use this Skill when you need to:

  • Understand the structure of a C program
  • Analyze functions, statements, and expressions
  • Prepare C code for static analysis or security analysis
  • Transform C code into an intermediate representation (AST)
  • Feed structured code information into downstream tools or agents

The AST is generated using a Python-based C parser and printed directly to standard output.


When to Use

Apply this Skill when the user asks to:

  • “Parse this C code”
  • “Convert this C file to an AST”
  • “Show me the AST of this C program”
  • “Analyze the structure of this C code”
  • “Extract syntax tree / abstract syntax tree from C”

This Skill is especially useful in compiler frontends, program analysis, and security research workflows.


Instructions

Follow these steps strictly and in order:

  1. Navigate to the Skill scripts directory

    • Change working directory to the scripts/ directory under this skill:
      scripts/
  2. Handle the input C source

    • If the user provides a path to a .c file, use it directly.
    • If the user provides inline C code as a string, you must first save it to a C source file using the provided script:
      bash
      python3 save_c.py --input "<C code string>" --output <output_dir> --filename <filename>.c
    • Ensure the generated file has a .c extension and is successfully written to disk.
  3. Run the AST extraction script

    • Convert the C source file to its Abstract Syntax Tree by executing:
      bash
      python3 c_2_ast.py --input <path_to_c_file>
  4. Do not modify the source code

    • This Skill is strictly read-only.
    • Do not rewrite, reformat, optimize, or otherwise alter the C code.
  5. Return the AST output verbatim

    • The script prints the AST directly to standard output.
    • Return the output exactly as produced.
    • Do not summarize, paraphrase, or restructure the AST.
    • Preserve indentation, hierarchy, and node ordering.
  6. If parsing fails

    • Report the exact error message produced by the script.
    • Suggest likely causes, such as:
      • Missing or unsupported header files
      • Unsupported C extensions (e.g., compiler-specific syntax)
      • Invalid or incomplete C syntax

Show full SKILL.md (206 more words)Show less

Output Format

The output is a tree-structured textual AST, for example:


FileAST:
FuncDef:
Decl: main
FuncDecl:
TypeDecl:
IdentifierType: ['int']
Compound:
FuncCall:
ID: puts
ExprList:
Constant: string, "Hello"
Return:
Constant: int, 0

This output represents the syntactic structure of the C program and can be consumed by downstream tools.


Additional Resources

For deeper understanding of:

  • AST node types
  • pycparser internal representation
  • Meaning of specific syntax tree nodes
  • Limitations of the C grammar supported

see the accompanying reference document:

➡️ reference.md

Only read this file when more detailed or theoretical information is required.
For standard AST extraction tasks, this Skill file alone is sufficient.


Notes and Limitations

  • The AST follows standard C syntax (C89/C99 subset).
  • Some compiler-specific extensions (e.g., GCC attributes) may not be supported.
  • Header files are handled using a minimal fake libc environment.
  • Macro-heavy or highly platform-specific code may require preprocessing.

Examples

Example 1: Simple AST extraction

User request:

Convert this C file to an AST.

Action:

bash
python3 c_2_AST.py --input example.c

Result:

  • The AST is printed directly.

Example 2: Security analysis preparation

User request:

I want to analyze this C program for vulnerabilities.

Action:

  • First, extract the AST using this Skill.
  • Then, pass the AST to a vulnerability analysis or pattern-matching process.

Best Practices

  • Use this Skill before any deep code analysis.
  • Treat the AST as an intermediate representation.
  • Combine with CFG/DFG or semantic analysis for advanced tasks.

End of Skill.

© Narwhal-Lab, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts) in skill_template/c_2_ast of Narwhal-Lab/MagicSkills.

  • SKILL.md
  • reference.md
  • scripts/.gitignore
  • scripts/c_2_ast.py
  • scripts/save_c.py
  • scripts/source.c
  • scripts/temp.c
  • scripts/test.c

Open the folder on GitHubat commit 00f3e86

Compare with similar skills

C To Ast next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

C To Ast compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
C To Ast this skillNarwhal-Lab/MagicSkills316—~1.1kAutomated safety check: PassMIT
Security Setupluongnv89/skills131—~4.5kAutomated safety check: PassMIT
Python API Consistency ValidatorArabelaTso/Skills-4-SE253—~609Automated safety check: PassApache-2.0
CodeQL Security Scantrailofbits/skills7.5k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence
Skylosduriantaco/skylos846—~620Automated safety check: PassApache-2.0

Similar skills

  • Security Setup

    luongnv89/skills

    Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.

    131 GitHub stars~4.5k tokensUpdated today
    SecurityAuto-check passed
  • Python API Consistency Validator

    ArabelaTso/Skills-4-SE

    Validate API consistency between two versions of Python libraries.

    253 GitHub stars~609 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.5k GitHub stars~4.6k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Skylos

    duriantaco/skylos

    Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

    846 GitHub stars~620 tokensUpdated today
    SecurityAuto-check passed
  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 26 days ago
    SecurityAuto-check: notes

Works with

Categories

Questions about C To Ast

What does C To Ast do?

Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills. C To Ast is an agent skill from Narwhal-Lab/MagicSkills. Parse C source code into an Abstract Syntax Tree (AST).

When should I use C To Ast?

C To Ast fits situations like: analyzing C programs; understanding code structure; performing static analysis; preparing code for further program analysis (e.g.

How do I install C To Ast in Claude Code?

Run `npx skills add Narwhal-Lab/MagicSkills --skill c-to-ast -a claude-code`. Or copy the skill folder (skill_template/c_2_ast in Narwhal-Lab/MagicSkills) into .claude/skills/c-to-ast in your project. Claude Code loads it when a task matches its description.

How do I install C To Ast in Codex?

Run `npx skills add Narwhal-Lab/MagicSkills --skill c-to-ast -a codex`. Or copy the skill folder (skill_template/c_2_ast in Narwhal-Lab/MagicSkills) into .agents/skills/c-to-ast in your project. Codex loads it when a task matches its description.

Can I use C To Ast in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Narwhal-Lab/MagicSkills --skill c-to-ast -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/c-to-ast, .gemini/skills/c-to-ast, .github/skills/c-to-ast and .opencode/skills/c-to-ast in your project.

What does C To Ast need to run?

Going by SKILL.md and its folder, C To Ast needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does C To Ast access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is C To Ast safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does C To Ast use?

C To Ast is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does C To Ast use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to C To Ast?

Skills that share tags, products or a category with C To Ast: Security Setup (luongnv89/skills, 131 stars), Python API Consistency Validator (ArabelaTso/Skills-4-SE, 253 stars), CodeQL Security Scan (trailofbits/skills, 7.5k stars) and Kedro Security Review (kedro-org/kedro, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains C To Ast?

Narwhal-Lab (a GitHub organization) maintains it in Narwhal-Lab/MagicSkills, which has 316 GitHub stars. The repository was last updated on April 8, 2026.

Source: Narwhal-Lab/MagicSkills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.