Qt C++ Code Review
x-tools-author/x-tools
Read-only review of Qt6 C++ code that combines a deterministic lint script with six parallel analysis agents and reports only high-confidence issues.
Find and fix unsafe buffer operations in a C++ file by removing UNSAFETODO markers and replacing unsafe raw pointers/C-style functions with base::span and standard safe containers.
$ npx skills add nwjs/chromium.src --skill spanify-buffers -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nwjs/chromium.src spanify-buffers --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/projects/code-health/spanify-buffers .claude/skills/spanify-buffers && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "spanify-buffers" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/projects/code-health/spanify-buffers into .claude/skills/spanify-buffers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spanify-buffers", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nwjs/chromium.src/tree/main/agents/projects/code-health/spanify-buffersType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nwjs/chromium.src --skill spanify-buffers -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nwjs/chromium.src spanify-buffers --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agents/projects/code-health/spanify-buffers .agents/skills/spanify-buffers && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "spanify-buffers" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/projects/code-health/spanify-buffers into .agents/skills/spanify-buffers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spanify-buffers", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nwjs/chromium.src --skill spanify-buffers -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nwjs/chromium.src spanify-buffers --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agents/projects/code-health/spanify-buffers .cursor/skills/spanify-buffers && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "spanify-buffers" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/projects/code-health/spanify-buffers into .cursor/skills/spanify-buffers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spanify-buffers", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nwjs/chromium.src.git --path agents/projects/code-health/spanify-buffers--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nwjs/chromium.src --skill spanify-buffers -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nwjs/chromium.src spanify-buffers --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agents/projects/code-health/spanify-buffers .gemini/skills/spanify-buffers && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "spanify-buffers" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/projects/code-health/spanify-buffers into .gemini/skills/spanify-buffers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spanify-buffers", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nwjs/chromium.src spanify-buffersInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nwjs/chromium.src --skill spanify-buffers -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .github/skills && cp -r skills-src/agents/projects/code-health/spanify-buffers .github/skills/spanify-buffers && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "spanify-buffers" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/projects/code-health/spanify-buffers into .github/skills/spanify-buffers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spanify-buffers", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nwjs/chromium.src --skill spanify-buffers -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nwjs/chromium.src spanify-buffers --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nwjs/chromium.src.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agents/projects/code-health/spanify-buffers .opencode/skills/spanify-buffers && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "spanify-buffers" agent skill from https://github.com/nwjs/chromium.src/tree/main/agents/projects/code-health/spanify-buffers into .opencode/skills/spanify-buffers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spanify-buffers", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
spanify-buffersFind and fix unsafe buffer operations in a C++ file by removing UNSAFETODO markers and replacing unsafe raw pointers/C-style functions with base::span and standard safe containers.
Spanify Buffers is an agent skill from nwjs/chromium.src. Find and fix unsafe buffer operations in a C++ file by removing UNSAFETODO markers and replacing unsafe raw pointers/C-style functions with base::span and standard safe containers. Use when the user asks to fix unsafe buffer warnings or -Wunsafe-buffer-usage errors. Don't use for other types of memory safety bugs like Use-After-Free, locking, or data races.
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/reviewer_guidelines.md` and `references/unsafe_buffers.md`).
It sits in Development, covering Code quality. It works with C++ and Git. The repository describes itself as: Chromium codebase with NW.js modifications. Based on https://chromium.googlesource.com/chromium/src.git. The licence is BSD-3-Clause.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit a9e8946. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Spanify Buffers loads about 3.7k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 95 tokens; SKILL.md has 1,580 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from nwjs/chromium.src at commit a9e8946, republished under its BSD-3-Clause licence (© nwjs). 1,580 words, ~3,740 tokens.
.claude/skills/spanify-buffers/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Role: You are an expert C++ developer, specializing in memory safety and modern C++ idioms for the Chromium project.
Goal: Your task is to fix all unsafe buffer operations in a given C++ file.
You will do this by removing UNSAFE_TODO() markers and
#pragma allow_unsafe_buffers directives, and then resolving the resulting
-Wunsafe-buffer-usage compiler errors by applying established patterns for
safe, idiomatic, and high-quality buffer handling in Chromium.
Core Task: You will be given a single C++ file path.
UNSAFE_TODO or
#pragma allow_unsafe_buffers).CRITICAL: DO NOT USE grep. The Chromium repository is too large for
grep -r, and it will cause a timeout. You MUST use rg (ripgrep) for all text
searches.
run_shell_command(rg "search_term").remote_code_search or codebase_investigator for
more precise architectural lookups.run_shell_command(fdfind "filename").Read the File: Get the content of the file provided in the prompt.
Identify -WUnsafe-buffer-usage opt-outs:
UNSAFE_TODO(...): Remove the macro wrapper, leaving the code
inside.#pragma allow_unsafe_buffers: Remove the entire
#ifdef UNSAFE_BUFFERS_BUILD...#endif block.Check for a compiler error related to unsafe buffer usage. If none exists, report this to the user in your response/walkthrough, stating that no unsafe code was found.
Fix the Code: Apply the Core Principles, Code Quality & Idioms, and Patterns & Fixes below. Use compiler errors as a guide, but also proactively improve the surrounding code.
std::array is a good refactoring.codebase_investigator tool to find all its call sites and update them.
This is critical for success.memcmp,
strcmp, pointer arithmetic) and fix them as well.Verify the Fix: You should ensure your fix compiles. Verify your changes
by compiling on one of the local build directories configured in the
workspace (e.g., under the out/ directory, such as out/Default or
out/linux-rel) to catch compilation errors early.
Recommended Local Verification: You can build the entire target or just
the object file to save time. Identify your local build directory (typically
in out/):
# Build the object file (fastest):
autoninja -C out/<build-dir> obj/{path/to/file.o}
# Or build the whole target:
autoninja -C out/<build-dir> {target_name}Note: To find the object file path, you can use
gn outputs out/<build-dir> {path/to/file.cc}.
If this fails, analyze the error and iterate.
Test: After a successful build, if you modified a test file, run:
./tools/autotest.py -C out/<build-dir> {test_file_path}If the test fails, you must fix the test code.
Self-Review:
references/reviewer_guidelines.md.Format and Finalize:
git cl format to clean up your changes.git diff to ensure they are correct and neat.Follow the Chromium guidelines on buffers located in references/unsafe_buffers.md
Your code must be easy to read and maintain.
base::span or std::ranges approach
exists.UNSAFE_BUFFERS() block MUST have a // SAFETY:
comment that is clear, technically accurate, and easy for a human reviewer to
verify.CRITICAL: You MUST use the exact, complete commands provided for verification. Do not add, remove, or change any arguments or flags.
CRITICAL: ALWAYS use base::span instead of std::span. std::span is
forbidden in Chromium.
CRITICAL: The base::span(T* pointer, size_t size) constructor is also
unsafe.
CRITICAL: Do not use std::<container>(pointer, pointer + size). This is not
safe, but not yet marked as unsafe in the codebase.
CRITICAL: Do not use std::<container>(begin_iterator, end_iterator) where the
iterators are from raw pointers. This is not safe, but not yet marked as
unsafe in the codebase.
UNSAFE_BUFFERS() if at all possible. If a safe fix is
impossible (e.g., a complex third-party API), you may use it but you MUST
justify in a // SAFETY: comment why other safe options (like subspan or
span iterators) are not available, and why the code is safe. If you cannot fix
it, inform the user in your response/walkthrough and explain why.UNSAFE_TODO(...) markers. Your task is to eliminate them.+, ++, ptr[i]).reinterpret_cast. Use safe casting functions like
base::as_byte_span() or base::as_writable_byte_span().sscanf, be
mindful of subtle parsing behavior and ensure your replacement preserves the
original logic.base::SpanReader::Read...() methods, to ensure operations complete
successfully.Your goal is not just to make the code safe, but also to make it clean, modern, and idiomatic. Always prefer higher-level abstractions over manual operations.
base library has many powerful
utilities. Use them whenever possible.base::ToVector(span) instead of vector.assign(span.begin(), span.end()).base::SpanWriter and base::SpanReader for serializing/deserializing
data.std::ranges::contains(container, element) instead of
.find(...) != .npos.base::wcslcpy instead of platform-specific APIs like lstrcpynW.for (const auto& element : base_span)
over index-based loops.std::ranges algorithms (e.g.,
std::ranges::copy, std::ranges::fill) over manual loops.std::array for fixed-size stack arrays.std::string_view for read-only string-like data. Use
base::as_string_view(span_of_chars) to safely convert a span of characters
to a view.array.fill() instead of std::ranges::fill(array, ...)).base::span features like .first(N) and .last(N) for
expressiveness.base::span<const T> if the underlying
buffer is not modified.#include (e.g., <array>, <string_view>,
"base/containers/span.h"). Remove any headers that are no longer used. Run
git cl format to sort them.base::span::copy_from is already safe for empty spans (no
if (!span.empty()) needed), and smart pointers default to nullptr.This section provides a more detailed guide on how to handle common unsafe
buffer patterns. While the examples are illustrative, you should always refer to
docs/unsafe_buffers.md for the complete and authoritative guide.
Problem: A function takes a raw pointer and a size as separate arguments.
// Before
void ProcessData(const uint8_t* data, size_t size);Fix: Replace the pointer and size with a single base::span.
// After
#include "base/containers/span.h"
void ProcessData(base::span<const uint8_t> data);Important: After changing a function signature, you must find and update all its call sites. Use the compiler errors to locate them.
Problem: A local variable is declared as a C-style array.
// Before
int scores[10];Fix: Convert the C-style array to a std::array. If this array is a
class member, refactor the class definition itself.
// After
#include <array>
std::array<int, 10> scores;Tip: For string literals, prefer constexpr std::string_view or
std::to_array.
// Example
constexpr std::string_view kMyString = "Hello";
constexpr auto kMyOtherString = std::to_array("World");Problem: Using pointer arithmetic (+, ++) or the subscript operator
([]) on a raw pointer.
// Before
const char* p = "hello";
char c = p[1]; // Unsafe access
p++; // Unsafe arithmeticFix: First, ensure the raw pointer is replaced by a safe container like
base::span or std::string_view. Then, use the container's methods for safe
access and manipulation.
// After
std::string_view p = "hello";
char c = p[1]; // Safe, bounds-checked access
p = p.substr(1); // Safe manipulationTip: Use methods like .subspan(), .first(), and .last() to create
views into parts of a span without raw pointer arithmetic.
Problem: Usage of unsafe C-style memory functions.
Fix: Replace them with their safe C++ or base library equivalents.
memcpy, memmove → base::span::copy_from(),
base::span::copy_prefix_from(), or a proper copy constructor/assignment.memset → std::ranges::fill() or preferably = {} zero-initialization or
std::array::fill() for fixed-size arrays. If possible, prefer
initialization in the class definition over inside the constructor body.memcmp, strcmp → operator== on two spans or std::string_viewsstrlen → .size() or .length() on the safe container// Before
char src[] = "test";
char dst[5];
memcpy(dst, src, 5);
// After
auto src_span = base::span(src);
std::array<char, 5> dst;
dst.copy_from(src_span);Problem: Constructing a container from a pair of raw pointers.
// Before
const char* ptr = "some_string";
std::vector<char> vec(ptr, ptr + 11);Fix: This is a critical anti-pattern. You must trace the pointer back to
its origin and refactor the code to provide a safe container (base::span,
std::vector, etc.) from the start. Do not simply wrap the raw pointers
in a base::span. Do not use std::begin()/end() on raw pointers or pointer
arithmetic.
// After
std::string_view str = "some_string";
std::vector<char> vec = base::ToVector(str);Compiler Errors are Your Friend: When you change a function signature, the compiler will tell you exactly where you need to update the call sites. Use this information to guide your changes.
Look for Safe Alternatives: If you encounter a class that returns a raw
pointer (e.g., obj->GetRawPtr()), check the class definition for a safer
alternative like obj->GetSpan() or obj->AsSpan(). If you are forced to
use .data() to pass a pointer to a function, first check if a span-based
overload of that function is available.
net::IOBuffer: If you see a net::IOBuffer being used with ->data(),
use its built-in span methods like io_buffer->first(len) or
io_buffer->span() instead.
Small, Atomic Changes: Try to make small, incremental changes. This makes it easier to identify the source of any new compilation errors.
© nwjs, BSD-3-Clause. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in agents/projects/code-health/spanify-buffers of nwjs/chromium.src.
Open the folder on GitHubat commit a9e8946
Spanify Buffers next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Spanify Buffers this skillnwjs/chromium.src | 160 | — | ~3.7k | Automated safety check: Pass | BSD-3-Clause | |
| Qt C++ Code Reviewx-tools-author/x-tools | 1.1k | 2 repos | ~4.3k | Automated safety check: Pass | BSD-3-Clause | |
| WebRTC Include Cleanerwebrtc-sdk/webrtc | 446 | 1 repos | ~545 | Automated safety check: Pass | BSD-3-Clause | |
| Skill Doctorwarpdotdev/common-skills | 608 | 2 repos | ~2.6k | Automated safety check: Pass | MIT | |
| pybind11 Release Preparationpybind/pybind11 | 18k | — | ~1.7k | Automated safety check: Pass | Custom licence | |
| Qt Cpp ReviewSerial-Studio/Serial-Studio | 7.2k | — | ~4.3k | Automated safety check: Pass | Custom licence |
x-tools-author/x-tools
Read-only review of Qt6 C++ code that combines a deterministic lint script with six parallel analysis agents and reports only high-confidence issues.
webrtc-sdk/webrtc
Runs the WebRTC include-cleaner tool to add missing and remove unused C++ include directives before uploading a CL or after refactoring.
warpdotdev/common-skills
Grades agent skills by scoring agent conversations for efficiency, code quality, procedure compliance, and verbosity, then drafts concrete skill edits and a shareable report.
pybind/pybind11
Opens the pybind11 release-preparation pull request: picking the release base, bumping the version in common.h and integrating the changelog, following docs/release.rst.
Serial-Studio/Serial-Studio
Qt6/C++ deep code review for Serial Studio. An agent skill from Serial-Studio/Serial-Studio.
pybind/pybind11
Walks a maintainer through publishing a pybind11 release after the preparation PR merges, with preflight checks, confirmations before each push and a GitHub release.
nwjs/chromium.src
Extracts raw trace data from Perfetto traces, runs arbitrary SQL queries for custom follow-up analysis, and applies expert cognitive principles (Tiered Flow Analysis, Semantic Mismatch, Redundancy)…
nwjs/chromium.src
Autonomous multi-agent performance optimization loop for Chromium and V8.
nwjs/chromium.src
Automated Tracing & Performance Telemetry in Chromium using Perfetto and Telemetry benchmarks.
nwjs/chromium.src
Queries Chrome commit, version, release, and milestone metadata.
nwjs/chromium.src
Search and reference Chromium documentation from the local docs index, including design docs, APIs, and development guides.
nwjs/chromium.src
Diagnose Chromium GN dependency and include-visibility failures, including BUILD.gn deps/publicdeps, DEPS include rules, private headers, and circular dependencies.
Categories
Find and fix unsafe buffer operations in a C++ file by removing UNSAFETODO markers and replacing unsafe raw pointers/C-style functions with base::span and standard safe containers. src. Find and fix unsafe buffer operations in a C++ file by removing UNSAFETODO markers and replacing unsafe raw pointers/C-style functions with base::span and standard safe containers.
Spanify Buffers fits situations like: the user asks to fix unsafe buffer warnings; -Wunsafe-buffer-usage errors; other types of memory safety bugs like Use-After-Free.
Run `npx skills add nwjs/chromium.src --skill spanify-buffers -a claude-code`. Or copy the skill folder (agents/projects/code-health/spanify-buffers in nwjs/chromium.src) into .claude/skills/spanify-buffers in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nwjs/chromium.src --skill spanify-buffers -a codex`. Or copy the skill folder (agents/projects/code-health/spanify-buffers in nwjs/chromium.src) into .agents/skills/spanify-buffers in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nwjs/chromium.src --skill spanify-buffers -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spanify-buffers, .gemini/skills/spanify-buffers, .github/skills/spanify-buffers and .opencode/skills/spanify-buffers in your project.
Going by SKILL.md and its folder, Spanify Buffers needs the command-line tools its instructions call (git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Spanify Buffers is published under the BSD-3-Clause licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Spanify Buffers: Qt C++ Code Review (x-tools-author/x-tools, 1.1k stars), WebRTC Include Cleaner (webrtc-sdk/webrtc, 446 stars), Skill Doctor (warpdotdev/common-skills, 608 stars) and pybind11 Release Preparation (pybind/pybind11, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nwjs (a GitHub organization) maintains it in nwjs/chromium.src, which has 160 GitHub stars. The repository holds 64 skills in this directory. The repository was last updated on October 3, 2026.
Source: nwjs/chromium.src on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.