Foundatio
FoundatioFx/Foundatio
A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.
Reference vocabulary for memory-safety vulnerabilities in native C/C++ code — bug-class taxonomy, common arithmetic patterns that lead to corruption, dispatch-family discipline, type-confusion…
$ npx skills add provos/ironcurtain --skill memory-safety-c-cpp -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install provos/ironcurtain memory-safety-c-cpp --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/provos/ironcurtain.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cpp .claude/skills/memory-safety-c-cpp && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "memory-safety-c-cpp" agent skill from https://github.com/provos/ironcurtain/tree/master/src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cpp into .claude/skills/memory-safety-c-cpp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memory-safety-c-cpp", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/provos/ironcurtain/tree/master/src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cppType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add provos/ironcurtain --skill memory-safety-c-cpp -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install provos/ironcurtain memory-safety-c-cpp --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/provos/ironcurtain.git skills-src && mkdir -p .agents/skills && cp -r skills-src/src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cpp .agents/skills/memory-safety-c-cpp && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "memory-safety-c-cpp" agent skill from https://github.com/provos/ironcurtain/tree/master/src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cpp into .agents/skills/memory-safety-c-cpp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memory-safety-c-cpp", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add provos/ironcurtain --skill memory-safety-c-cpp -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install provos/ironcurtain memory-safety-c-cpp --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/provos/ironcurtain.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cpp .cursor/skills/memory-safety-c-cpp && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "memory-safety-c-cpp" agent skill from https://github.com/provos/ironcurtain/tree/master/src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cpp into .cursor/skills/memory-safety-c-cpp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memory-safety-c-cpp", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/provos/ironcurtain.git --path src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cpp--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add provos/ironcurtain --skill memory-safety-c-cpp -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install provos/ironcurtain memory-safety-c-cpp --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/provos/ironcurtain.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cpp .gemini/skills/memory-safety-c-cpp && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "memory-safety-c-cpp" agent skill from https://github.com/provos/ironcurtain/tree/master/src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cpp into .gemini/skills/memory-safety-c-cpp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memory-safety-c-cpp", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install provos/ironcurtain memory-safety-c-cppInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add provos/ironcurtain --skill memory-safety-c-cpp -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/provos/ironcurtain.git skills-src && mkdir -p .github/skills && cp -r skills-src/src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cpp .github/skills/memory-safety-c-cpp && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "memory-safety-c-cpp" agent skill from https://github.com/provos/ironcurtain/tree/master/src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cpp into .github/skills/memory-safety-c-cpp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memory-safety-c-cpp", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add provos/ironcurtain --skill memory-safety-c-cpp -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install provos/ironcurtain memory-safety-c-cpp --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/provos/ironcurtain.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cpp .opencode/skills/memory-safety-c-cpp && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "memory-safety-c-cpp" agent skill from https://github.com/provos/ironcurtain/tree/master/src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cpp into .opencode/skills/memory-safety-c-cpp/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memory-safety-c-cpp", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
memory-safety-c-cppReference vocabulary for memory-safety vulnerabilities in native C/C++ code — bug-class taxonomy, common arithmetic patterns that lead to corruption, dispatch-family discipline, type-confusion…
Memory Safety C Cpp is an agent skill from provos/ironcurtain. Reference vocabulary for memory-safety vulnerabilities in native C/C++ code — bug-class taxonomy, common arithmetic patterns that lead to corruption, dispatch-family discipline, type-confusion idioms, use-after-free patterns, and exploitability factors. Read when analyzing, hypothesizing, designing harnesses for, or triaging findings against C/C++ code with sanitizer support (ASAN/UBSAN/TSAN/MSan). Not applicable to managed runtimes (JVM, .NET) or scripting languages — those have their own skills.
Its SKILL.md is about 5.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It works with C++, .NET and Model Context Protocol. The repository describes itself as: A secure runtime for autonomous AI agents. Policy from plain-English constitutions. (https://ironcurtain.dev). The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 8f9c75a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Memory Safety C Cpp loads about 5.6k tokens when it runs. Until then it costs about 131 tokens; SKILL.md has 2,753 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from provos/ironcurtain at commit 8f9c75a, republished under its Apache-2.0 licence (© provos). 2,753 words, ~5,575 tokens.
.claude/skills/memory-safety-c-cpp/SKILL.md (or your agent's skills folder).Reference vocabulary for native C/C++ code with sanitizer support. Catalogs the bug classes, patterns, and exploitability factors a memory-safety investigation needs to reason about.
Identifiers below are the canonical IDs to use when naming a bug class in any artifact. Map each to the oracle that catches it and the root-cause CWE.
| Bug class | Oracle | Root-cause CWE | Where it lives |
|---|---|---|---|
heap_overflow | ASAN heap-buffer-overflow | CWE-122 | Read or write past a heap allocation |
stack_overflow | ASAN stack-buffer-overflow | CWE-121 | Read or write past a stack frame buffer |
out_of_bounds_read | ASAN OOB-read | CWE-125 | Generic OOB load — distinct from heap/stack only by site |
out_of_bounds_write | ASAN OOB-write | CWE-787 | Generic OOB store |
use_after_free | ASAN heap-use-after-free | CWE-416 | Pointer dereferenced after the allocation it pointed to was freed |
double_free | ASAN attempting double-free | CWE-415 | free() called twice on the same allocation |
integer_overflow | UBSAN signed-integer-overflow / unsigned-integer-overflow | CWE-190 | Arithmetic produces a value outside the type's range |
type_confusion | ASAN OOB or UBSAN vptr | CWE-843 | A value is interpreted as a different type than it was created with — frequently across vtable / dispatch-table boundaries |
format_string | ASAN OOB / UBSAN | CWE-134 | Attacker-controlled bytes reach the format-spec argument of a printf-family call |
null_deref | SIGSEGV (caught by ASAN as SEGV on unknown address 0x000000000000) | CWE-476 | Dereference of a pointer the attacker can force to NULL |
uninitialized_memory | MSan use-of-uninitialized-value | CWE-457 | Read of memory before it was written |
race_condition | TSAN data race | CWE-362 | Concurrent unsynchronized access (a TOCTOU is a special case where the racing accesses are check-then-use) |
memory_leak | LSan / ASAN leak report | CWE-401 | Heap allocation lost without free() |
CWE precision rule. Always cite the root-cause CWE, not the consequence CWE. An integer overflow that leads to an undersized heap allocation and a subsequent OOB write is CWE-190 (the arithmetic bug), not CWE-122 (the consequence). A strncpy using the wrong size constant is CWE-806 (buffer access using size of source buffer), not CWE-120 (generic buffer overflow).
These are the high-yield sites to look for whenever the surface processes attacker-controlled lengths, counts, offsets, or indices. Each is a pattern, not a procedure — the same pattern fires across many surfaces (parsers, codecs, compression, RPC framing, allocator wrappers).
Integer overflow into allocation size. Attacker controls a count n. Code computes n * sizeof(T) (or n + header) and passes the result to malloc/new[]. The multiplication or addition wraps; the allocation is undersized; subsequent indexed writes overflow. The named violation site is the multiplication or addition, not the OOB write — the OOB write is the consequence.
Signed/unsigned mixing at a comparison. A signed integer is compared against an unsigned length (or vice versa). The signed value is implicitly converted to unsigned, turning negative values into very large positives. A "guard" of the form if (i < len) ... admits every negative i when len is unsigned.
Type narrowing at a storage boundary. A wider type (computed precisely) is stored into a narrower container (int → uint16_t, size_t → uint32_t, double → float). The maximum value the source can reach exceeds the destination's range. Trace every write where source and destination types differ in width.
Unbounded growth meeting fixed-size storage. A counter or accumulator grows without a hard cap, then is stored in or compared against a fixed-width field. When the counter reaches the maximum representable value of the storage type, the comparison flips or the stored value collides with a sentinel.
Sentinel and magic value reachability. Identify every sentinel or magic value the code uses (-1, 0, NULL, 0xFFFF, INT_MAX, special tags). For each, ask whether any computed value — through normal execution, overflow, truncation, or wrapping — can equal the sentinel. Counters that grow toward a sentinel are a high-yield target.
Off-by-one at a buffer boundary. Loop bound is <= instead of <, or vice versa. strncpy writes a non-null-terminated string. memcpy length is len + 1 where +1 was meant for a separate terminator.
Check-use separation (TOCTOU). A value is validated in one place and consumed in another. Between check and use, the value can change — through concurrent access, callbacks, re-reads from shared / global state, or intervening function calls that mutate it.
Arithmetic result range vs destination range. A multiplication, addition, or shift produces a value that exceeds the range of its destination type or comparison operand. Worth tracing whether intermediate computations widen the type before narrowing.
These produce memory corruption without an arithmetic root cause. They cluster around contract violations between functions — a writer leaves a buffer in a state the reader does not expect, or a sink assumes an invariant the source did not enforce. Apply alongside the arithmetic patterns; the bug at any given site may be in either category, and a surface that admits one usually admits both.
Missing null-termination on string sinks. A function copies n bytes from a (count, ptr) pair into a buffer without appending a NUL. A downstream printf("%s", ...), strlen, strcat, or strchr reads past the allocation searching for a terminator that does not exist. Particularly common in parsing routines that copy attacker-controlled strings field-by-field; the named violation site is the read sink, but the root cause is the writer's missing terminator.
Format-string controlled by attacker. Attacker bytes reach the format-string argument of a printf-family call (printf(user) instead of printf("%s", user)). Yields memory disclosure via %s / %n and crashes via malformed specifiers. Trace every variadic-print call where the first argument is not a compile-time constant.
Length pair desynchronized from buffer. A (ptr, len) interface is called with len exceeding the allocation behind ptr. Common when the length is read from input and the pointer is allocated to a different size, or when the buffer was reallocated but a stale length is used elsewhere. The bound check happens in one function; the read or write happens in another that assumes the check was honored.
Sentinel-driven iteration without an independent bound. A loop walks until it hits a sentinel (NUL, 0xFFFF, end-marker tag) without a hard cap. If the data lacks the sentinel — because validation did not enforce it, or the attacker stripped it — iteration runs past the buffer. Pairs naturally with terminated-string or terminated-list assumptions on input that has not been verified to terminate.
Print, dump, and diagnostic paths trust upstream invariants. Print and dump routines often assume the data they receive has already been validated — terminated, bounded, well-formed — because they run after the parser. If validation skipped fields the print path consumes (common for "diagnostic" or "verbose" outputs), the print path becomes the OOB-read site even though the bug is the validator's omission. Every code path used only by -v / -D / --debug flags is its own attack surface that typically gets less validation attention than the main path.
When the target dispatches over a typed surface — a per-bps codec table, a per-message-type handler array, a per-opcode switch, a per-mode initializer, a per-format decoder — every variant is its own attack surface. Variants commonly share a contract on paper but differ in per-element arithmetic, buffer sizes, or guard placement.
C++ adds a class of bugs that don't appear in pure C surfaces:
static_cast<Derived*>(base_ptr) where base_ptr does not point to a Derived. Subsequent virtual calls invoke the wrong method; subsequent member accesses read or write at the wrong offsets.this runs after the object's destructor has already started — common in callback handlers, signal handlers, and worker-thread teardown. vptr may have been overwritten or freed.std::variant, tagged union, or void*-keyed map records one type but is read as another, often after a refactor that added a new variant tag without updating every consumer.UBSAN's vptr check (-fsanitize=vptr) catches some of these; the rest surface as heap-use-after-free or as silent corruption.
UAFs cluster around lifetime confusion, not single-line bugs. The high-yield search patterns:
string_view, span, or raw pointer derived from it is held. The reference dereferences memory the container has moved or freed.Each memory-safety primitive class has natural scaling axes — the dimensions along which a minimum trigger can be pushed to characterize what an attacker can actually do with the primitive. Discover exercises these axes to produce adversary-maximal evidence; triage scores on the demonstrated extent. Mirrored from vulnerability-triage's Primitive extent section so this skill (loaded by discover and analyze) carries the same canonical enumeration triage uses.
If this list and vulnerability-triage's Primitive extent section drift, fix both at once — triage's scoring rule and discover's evidence-gathering rule must reference the same axes.
Whether a confirmed sanitizer crash is a real security risk depends on the runtime environment. This is reference material for triage, not a procedure.
Mitigation timeline (shifts what's reachable):
| Mitigation | Effect |
|---|---|
| Full RELRO | No GOT, no .fini_array, no .init_array writeable at runtime |
| glibc 2.34+ | __malloc_hook / __free_hook removed |
| glibc 2.38+ | %n may be blocked in some configurations — check empirically |
| Stack canary + no infoleak | Cannot overflow past the canary without first leaking it |
| ASLR + no infoleak | Cannot find absolute addresses to write |
Constraint rules to apply:
strcpy copy writes the 6 low bytes of an address before the NULL byte stops it; the upper 2 bytes are not written. This bounds what a strcpy-based primitive can land.tcache poisoning, unsorted_bin attacks, and house-of-* techniques all have version windows. Cite the deployed glibc, not the latest.libc is not the same as a gadget that's reachable from the crash state.When a sanitizer crash is NOT a security bug:
malloc failure inside a path that the production environment never reaches under attacker pressure.The triage discipline is to anchor severity on what the harness actually demonstrated under production-equivalent conditions, not on the theoretical maximum implied by the crash class. A Tier-1 harness with hardening stripped tells you nothing about production outcomes.
Hypotheses must be value-level, not pattern-level.
Bad: "Supplying 24+ bytes overwrites the return address."
Good: "At input offset 24, RIP=0x4141414141414141 → SIGSEGV at attacker-controlled address."
Bad: "There may be integer overflow in the parser."
Good: "When the input field at <file>:<line> exceeds 2^31 - 1, the multiplication at <file>:<line> wraps to a negative int, and the subsequent malloc(n * sizeof(T)) allocates fewer bytes than the loop at <file>:<line> then writes."
A well-formed memory-safety hypothesis names: (1) the input value or shape that triggers the pattern, (2) the named arithmetic / dereference / lifetime site that violates, (3) the oracle that should fire (specific ASAN error class, UBSAN check, TSAN race, or assertion), and (4) the root-cause CWE.
A finding is supported only by observable evidence: a crash, sanitizer trace, changed output, callback fired, file read, error message, or measurable state change. "Ran without error" is not evidence. If the expected effect is not observed, either the harness is wrong or the bug is not triggered — diagnose which; do not paper over.
When claiming a finding is exploitable, the supporting evidence must answer all three:
If any of the three cannot be answered from the artifacts alone, the finding is not yet exploitable — it is a detector hit awaiting demonstration.
-D_FORTIFY_SOURCE, without stack canaries, without ASLR, or with custom allocators tells you nothing about the production binary's behavior. The triage question is "what does the production build do under this input," not "what does my Tier-1 reproduction show."© provos, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cpp of provos/ironcurtain.
Open the folder on GitHubat commit 8f9c75a
Memory Safety C Cpp next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Memory Safety C Cpp this skillprovos/ironcurtain | 613 | — | ~5.6k | Automated safety check: Pass | Apache-2.0 | |
| FoundatioFoundatioFx/Foundatio | 2.1k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| Microsoft DocsMicrosoftDocs/mcp | 1.9k | 1 repos | ~723 | Automated safety check: Pass | CC-BY-4.0 | |
| Bump LibdatadogDataDog/dd-trace-dotnet | 573 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Ue Code AuthoringJasonMa0012/MooaToon | 749 | — | ~1.9k | Automated safety check: Notes | Custom licence | |
| .NET MAUI Dependency Flow Guidedotnet/maui | 23k | — | ~10k | Automated safety check: Pass | MIT |
FoundatioFx/Foundatio
A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.
MicrosoftDocs/mcp
Understand Microsoft technologies by querying official documentation.
DataDog/dd-trace-dotnet
Update/bump the libdatadog native library version in dd-trace-dotnet.
JasonMa0012/MooaToon
A skill your agent uses when writing or modifying UE C++ (classes, actors, components, subsystems, interfaces, function libraries) with Rider MCP available.
dotnet/maui
Adds MAUI-specific guardrails on top of the maestro-cli skill and Maestro MCP tools for darc, BAR, and channel or feed lookups in dotnet/maui.
debugmcp/mcp-debugger
A skill your agent uses when investigating a bug, failing test, or unexpected runtime behavior and the mcp-debugger MCP server is available — drives real step-through debuggers (breakpoints, stack…
provos/ironcurtain
Reference vocabulary for designing instrumented harnesses that drive vulnerability discovery — design classes (trigger-driven vs coverage-driven), tiered scope (T1 isolated function / T2…
provos/ironcurtain
Markdown formatting conventions for email summary documents — heading depth, list style, line length, emoji policy, and a mandatory provenance footer.
provos/ironcurtain
Reference for Gmail's search query syntax — operators like is:sent, newerthan:, from:, has:attachment, label:, and how they compose.
provos/ironcurtain
Canonical shape of the .workflow/emails/emails.json file passed between the fetch and summarize states — required fields (sender, recipient, subject, date, body), types, and field semantics.
provos/ironcurtain
Tone and length conventions for email summaries — voice, verb tense, what to include vs omit, and target sentence count.
provos/ironcurtain
Reference vocabulary for interpreting vulnerability findings — detector-vs-impact distinction, severity anchoring on demonstrated evidence, the eleven-item interpretation rubric, delegation…
Works with
Reference vocabulary for memory-safety vulnerabilities in native C/C++ code — bug-class taxonomy, common arithmetic patterns that lead to corruption, dispatch-family discipline, type-confusion…. Memory Safety C Cpp is an agent skill from provos/ironcurtain. Reference vocabulary for memory-safety vulnerabilities in native C/C++ code — bug-class taxonomy, common arithmetic patterns that lead to corruption, dispatch-family discipline, type-confusion idioms, use-after-free patterns, and exploitability factors.
Run `npx skills add provos/ironcurtain --skill memory-safety-c-cpp -a claude-code`. Or copy the skill folder (src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cpp in provos/ironcurtain) into .claude/skills/memory-safety-c-cpp in your project. Claude Code loads it when a task matches its description.
Run `npx skills add provos/ironcurtain --skill memory-safety-c-cpp -a codex`. Or copy the skill folder (src/workflow/workflows/vuln-discovery/skills/memory-safety-c-cpp in provos/ironcurtain) into .agents/skills/memory-safety-c-cpp in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add provos/ironcurtain --skill memory-safety-c-cpp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/memory-safety-c-cpp, .gemini/skills/memory-safety-c-cpp, .github/skills/memory-safety-c-cpp and .opencode/skills/memory-safety-c-cpp in your project.
SKILL.md names no scripts, command-line tools or credentials: Memory Safety C Cpp is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Memory Safety C Cpp is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.6k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Memory Safety C Cpp: Foundatio (FoundatioFx/Foundatio, 2.1k stars), Microsoft Docs (MicrosoftDocs/mcp, 1.9k stars), Bump Libdatadog (DataDog/dd-trace-dotnet, 573 stars) and Ue Code Authoring (JasonMa0012/MooaToon, 749 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
provos (a GitHub user) maintains it in provos/ironcurtain, which has 613 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 7, 2026.
Source: provos/ironcurtain on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.