Qt C++ Code Review
x-tools-author/x-tools
Read-only review of Qt6 C++ code that combines a deterministic lint script with six parallel analysis agents and reports only high-confidence issues.
C++ coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.
$ npx skills add softspark/ai-toolkit --skill cpp-rules -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install softspark/ai-toolkit cpp-rules --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/app/skills/cpp-rules .claude/skills/cpp-rules && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cpp-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/cpp-rules into .claude/skills/cpp-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cpp-rules", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/softspark/ai-toolkit/tree/main/app/skills/cpp-rulesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add softspark/ai-toolkit --skill cpp-rules -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install softspark/ai-toolkit cpp-rules --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/app/skills/cpp-rules .agents/skills/cpp-rules && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cpp-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/cpp-rules into .agents/skills/cpp-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cpp-rules", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add softspark/ai-toolkit --skill cpp-rules -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install softspark/ai-toolkit cpp-rules --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/app/skills/cpp-rules .cursor/skills/cpp-rules && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cpp-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/cpp-rules into .cursor/skills/cpp-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cpp-rules", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/softspark/ai-toolkit.git --path app/skills/cpp-rules--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add softspark/ai-toolkit --skill cpp-rules -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install softspark/ai-toolkit cpp-rules --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/app/skills/cpp-rules .gemini/skills/cpp-rules && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cpp-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/cpp-rules into .gemini/skills/cpp-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cpp-rules", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install softspark/ai-toolkit cpp-rulesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add softspark/ai-toolkit --skill cpp-rules -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .github/skills && cp -r skills-src/app/skills/cpp-rules .github/skills/cpp-rules && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cpp-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/cpp-rules into .github/skills/cpp-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cpp-rules", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add softspark/ai-toolkit --skill cpp-rules -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install softspark/ai-toolkit cpp-rules --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/app/skills/cpp-rules .opencode/skills/cpp-rules && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cpp-rules" agent skill from https://github.com/softspark/ai-toolkit/tree/main/app/skills/cpp-rules into .opencode/skills/cpp-rules/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cpp-rules", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cpp-rulesC++ coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.
Cpp Rules is an agent skill from softspark/ai-toolkit. C++ coding rules: style, patterns, security, testing. Triggers: .cpp, .cc, .cxx, .hpp, .h, CMakeLists.txt, Makefile, GoogleTest, clang-tidy.
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development. It works with C++. The repository describes itself as: Professional-grade AI coding toolkit: 94 skills, 44 agents, multi-platform (Claude, Cursor, Windsurf, Copilot, Gemini, Cline, Roo Code, Aider, Augment, Antigravity, Codex CLI… The licence is Apache-2.0.
Read from SKILL.md and the folder at commit d64db2b. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cpp Rules loads about 3.4k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 1,591 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from softspark/ai-toolkit at commit d64db2b, republished under its Apache-2.0 licence (© softspark). 1,591 words, ~3,375 tokens.
.claude/skills/cpp-rules/SKILL.md (or your agent's skills folder).These rules come from app/rules/cpp/ in ai-toolkit. They cover
the project's standards for coding style, frameworks, patterns,
security, and testing in C++. Apply them when writing or
reviewing C++ code.
m_ or suffix with _ (pick one convention).namespace io, namespace util).auto for iterator types and complex template deductions.std::optional<T> instead of sentinel values or pointers for optional returns.std::variant over union types. Use std::visit for dispatch.std::string_view for non-owning string parameters.auto [key, value] = *map.begin();.constexpr for compile-time evaluation. Prefer over macros.std::unique_ptr for exclusive ownership (default choice).std::shared_ptr only when ownership is genuinely shared.new/delete. Use std::make_unique / std::make_shared.std::span<T> (C++20) for non-owning views over contiguous data.const&.[[nodiscard]] on functions whose return value must not be ignored.noexcept on functions that do not throw (move constructors, destructors).#pragma once or include guards. Prefer #pragma once for simplicity.static_cast, dynamic_cast, const_cast.constexpr and templates.using namespace std; in headers. Acceptable in .cpp files with caution.std::endl -- use '\n' (endl flushes the buffer unnecessarily)..clang-format file.target_link_libraries with PUBLIC/PRIVATE/INTERFACE visibility.FetchContent for dependency management. Avoid manual submodule vendoring.CMAKE_CXX_STANDARD 20 (or 23) at the project level.target_compile_options for per-target flags, not global add_compile_options.install(TARGETS ... EXPORT ...) for library consumers.boost::beast for HTTP/WebSocket built on Asio.boost::json or nlohmann/json for JSON parsing.std::optional over boost::optional).QObject parent-child ownership for automatic memory management.QML for declarative UI. Keep business logic in C++ backend.QThread with worker objects (moveToThread), not subclassing QThread..proto files. Generate C++ stubs with protoc.CompletionQueue for high-throughput services.grpc::ClientContext for per-call deadlines and metadata.io_context as the event loop. Run from one or more threads.co_await (C++20 coroutines) with Asio for clean async code.strand for serializing access to shared state across handlers.steady_timer for timeouts and periodic tasks.error_code parameter, not exceptions, in async callbacks.libpq (PostgreSQL) or SOCI for database access.SQLite via sqlite3 C API with RAII wrappers for embedded use cases.vcpkg or Conan 2 for dependency management.vcpkg.json or conanfile.py.std::expected<T, E> (C++23) or Result<T, E> pattern for recoverable errors.std::error_code / std::error_category for system-level errors.noexcept on functions that must not throw (destructors, move operations).const&. Never catch by value (slicing) or pointer.std::lock_guard or std::scoped_lock for mutex management.std::unique_lock when deferred locking or condition variables are needed.std::fstream (auto-closes) instead of fopen/fclose.unique_ptr: default ownership model. Transfer with std::move.shared_ptr: use only for genuinely shared ownership graphs.weak_ptr: break cycles in shared_ptr graphs. Use lock() to access.unique_ptr. Let callers upgrade to shared_ptr.T& or T* to non-owning consumers.std::thread with std::jthread (C++20) for auto-joining threads.std::mutex + std::scoped_lock for shared data protection.std::atomic<T> for lock-free single-variable synchronization.std::condition_variable for producer-consumer patterns.std::async / std::future for simple parallel computation.std::counting_semaphore (C++20) for resource pool limiting.concepts (C++20) to constrain template parameters with clear error messages.if constexpr for compile-time branching in templates.constexpr functions over template metaprogramming when possible.std::variant + std::visit for type-safe visitor pattern.std::function for type-erased callbacks and strategy pattern.unique_ptr<Impl>) for ABI stability and compilation firewall.std::move semantics in move constructors for efficient resource transfer.new/delete: use smart pointers and containers.unique_ptr.const_cast to remove constness: redesign the interface.std::string, std::vector, std::array instead of C arrays and char[].std::span (C++20) for safe, bounds-checked views over contiguous data.strcpy, strcat, sprintf. Use std::string operations or snprintf.-D_FORTIFY_SOURCE=2 in release builds for runtime buffer checks.at() for bounds-checked container access in untrusted input paths.new/delete in application code.-fsanitize=address) in development and CI builds.-fsanitize=undefined) in test builds.-fstack-protector-strong for stack buffer overflow detection.std::numeric_limits<T>::max() for boundary checks.static_cast explicitly. Never rely on implicit narrowing conversions.-Wconversion and -Wsign-conversion warnings.std::stoi / std::stol with exception handling for string-to-number conversion.../).std::fill or explicit_bzero() to zero sensitive memory before deallocation.mlock() to prevent sensitive memory from being swapped to disk.-fPIE -pie for position-independent executables (ASLR).-Werror in CI to prevent warnings from becoming vulnerabilities.vcpkg or Conan with pinned versions for reproducible builds.std::mutex with std::scoped_lock for all shared data access.std::atomic for lock-free single-variable operations.-fsanitize=thread) in test builds for race detection.volatile for synchronization. It does not provide atomicity or ordering.lock()/unlock().-Wall -Wextra -Wpedantic.-D_GLIBCXX_ASSERTIONS for debug iterator and container checks.-fno-exceptions only when exception safety is not required.-Wl,-z,relro,-z,now for full RELRO (GOT hardening).foo_test.cpp or test_foo.cpp in a dedicated tests/ directory.CMakeLists.txt with add_test() to register tests.TEST(SuiteName, TestName) for simple tests.TEST_F(FixtureName, TestName) for tests sharing setup/teardown.SetUp() / TearDown() in fixtures for per-test initialization.EXPECT_* (non-fatal) by default. Use ASSERT_* only when continuation is meaningless.EXPECT_EQ, EXPECT_NE, EXPECT_LT, EXPECT_GT for comparisons.EXPECT_TRUE, EXPECT_FALSE for boolean conditions.EXPECT_THROW(expr, ExceptionType) for exception testing.EXPECT_THAT(value, matcher) with gmock matchers for complex assertions.INSTANTIATE_TEST_SUITE_P with testing::Values(...) for value-parameterized tests.testing::Combine() for multi-dimensional parameterization.TYPED_TEST_SUITE for type-parameterized tests across template types.MOCK_METHOD(ReturnType, MethodName, (Args), (Qualifiers)).EXPECT_CALL(mock, Method(matchers)).WillOnce(Return(value)).NiceMock<T> to suppress uninteresting call warnings.StrictMock<T> to fail on any unexpected call.FetchContent or find_package to integrate gtest in CMake.BUILD_TESTING option to conditionally include tests.ctest --output-on-failure for CI runs.-fsanitize=address,undefined.valgrind or ASan/UBSan in CI to detect memory errors.© softspark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in app/skills/cpp-rules of softspark/ai-toolkit.
Open the folder on GitHubat commit d64db2b
Cpp Rules next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cpp Rules this skillsoftspark/ai-toolkit | 179 | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| Qt C++ Code Reviewx-tools-author/x-tools | 1.1k | 2 repos | ~4.3k | Automated safety check: Pass | BSD-3-Clause | |
| YugabyteDB ASH Instrumentationyugabyte/yugabyte-db | 11k | — | ~4.5k | Automated safety check: Pass | Custom licence | |
| pybind11 Release Preparationpybind/pybind11 | 18k | — | ~1.7k | Automated safety check: Pass | Custom licence | |
| Qt Cpp ReviewSerial-Studio/Serial-Studio | 7.2k | — | ~4.3k | Automated safety check: Pass | Custom licence | |
| Paddle Eager GraphPaddlePaddle/Paddle | 24k | — | ~562 | Automated safety check: Pass | Apache-2.0 |
x-tools-author/x-tools
Read-only review of Qt6 C++ code that combines a deterministic lint script with six parallel analysis agents and reports only high-confidence issues.
yugabyte/yugabyte-db
Procedure for adding or changing YugabyteDB Active Session History wait states in TServer and DocDB C++ code, including the macro to use for sync and async paths.
pybind/pybind11
Opens the pybind11 release-preparation pull request: picking the release base, bumping the version in common.h and integrating the changelog, following docs/release.rst.
Serial-Studio/Serial-Studio
Qt6/C++ deep code review for Serial Studio. An agent skill from Serial-Studio/Serial-Studio.
PaddlePaddle/Paddle
A skill your agent uses when navigating Paddle eager-mode (dynamic graph) source code, tracing forward/backward execution, debugging autograd issues, understanding PyLayer, or investigating…
microsoft/onnxruntime
Builds ONNX Runtime from source with its build scripts, explaining the update, build and test phases, key flags and where the build output lands.
softspark/ai-toolkit
Prepare or verify a project QA environment with source identity, readiness, browser access, evidence paths and owned cleanup.
softspark/ai-toolkit
Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. An agent skill from softspark/ai-toolkit.
softspark/ai-toolkit
Analyzes code quality, complexity, patterns across codebase.
softspark/ai-toolkit
Drives a brief, specification, issue or existing PR through implementation, review, tests and QA to a ready PR.
softspark/ai-toolkit
Direct technical voice for docs, README, user-facing text. An agent skill from softspark/ai-toolkit.
softspark/ai-toolkit
Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).
Works with
Categories
C++ coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit. Cpp Rules is an agent skill from softspark/ai-toolkit. C++ coding rules: style, patterns, security, testing.
Cpp Rules fits situations like: development work in your project.
Run `npx skills add softspark/ai-toolkit --skill cpp-rules -a claude-code`. Or copy the skill folder (app/skills/cpp-rules in softspark/ai-toolkit) into .claude/skills/cpp-rules in your project. Claude Code loads it when a task matches its description.
Run `npx skills add softspark/ai-toolkit --skill cpp-rules -a codex`. Or copy the skill folder (app/skills/cpp-rules in softspark/ai-toolkit) into .agents/skills/cpp-rules in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add softspark/ai-toolkit --skill cpp-rules -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cpp-rules, .gemini/skills/cpp-rules, .github/skills/cpp-rules and .opencode/skills/cpp-rules in your project.
SKILL.md names no scripts, command-line tools or credentials: Cpp Rules is instructions for the agent only. Its frontmatter pre-approves these tools: Read.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cpp Rules is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cpp Rules: Qt C++ Code Review (x-tools-author/x-tools, 1.1k stars), YugabyteDB ASH Instrumentation (yugabyte/yugabyte-db, 11k stars), pybind11 Release Preparation (pybind/pybind11, 18k stars) and Qt Cpp Review (Serial-Studio/Serial-Studio, 7.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
softspark (a GitHub user) maintains it in softspark/ai-toolkit, which has 179 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on October 7, 2026.
Source: softspark/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.