Agent skill

Cpp Rules

by softspark in softspark/ai-toolkit

C++ coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.

Apache-2.0Auto-check passedDevelopment

Install Cpp Rules

skills CLI
$ npx skills add softspark/ai-toolkit --skill cpp-rules -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install softspark/ai-toolkit cpp-rules --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/app/skills/cpp-rules .claude/skills/cpp-rules && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cpp-rules
GitHub stars
179
Token cost
~3.4k tokens
SKILL.md length
1,591 words
Files
1
Skills in repo
112
Repo updated
First seen
Licence
Apache-2.0

At a glance

C++ coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.

  • Development work in your project
  • SKILL.md covers Naming, Modern C++ (17/20/23), Memory Management and Functions, plus 21 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cpp Rules is an agent skill from softspark/ai-toolkit. C++ coding rules: style, patterns, security, testing. Triggers: .cpp, .cc, .cxx, .hpp, .h, CMakeLists.txt, Makefile, GoogleTest, clang-tidy.

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. It works with C++. The repository describes itself as: Professional-grade AI coding toolkit: 94 skills, 44 agents, multi-platform (Claude, Cursor, Windsurf, Copilot, Gemini, Cline, Roo Code, Aider, Augment, Antigravity, Codex CLI… The licence is Apache-2.0.

When your agent uses it

  • Development work in your project

Example prompts

  • “/cpp-rules”

Requirements

  • Pre-approved tools (allowed-tools): Read

What it can do on your machine

Read from SKILL.md and the folder at commit d64db2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cpp Rules loads about 3.4k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 1,591 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from softspark/ai-toolkit at commit d64db2b, republished under its Apache-2.0 licence (© softspark). 1,591 words, ~3,375 tokens.

Download SKILL.mdSave it as .claude/skills/cpp-rules/SKILL.md (or your agent's skills folder).
name
cpp-rules
description
C++ coding rules: style, patterns, security, testing. Triggers: .cpp, .cc, .cxx, .hpp, .h, CMakeLists.txt, Makefile, GoogleTest, clang-tidy.
allowed-tools
Read
effort
medium
user-invocable
false

C++ Rules

These rules come from app/rules/cpp/ in ai-toolkit. They cover the project's standards for coding style, frameworks, patterns, security, and testing in C++. Apply them when writing or reviewing C++ code.

C++ Coding Style

Naming

  • PascalCase: classes, structs, enums, type aliases, concepts.
  • camelCase or snake_case: functions, methods, variables (be consistent per project).
  • UPPER_SNAKE: macros, compile-time constants.
  • Prefix member variables with m_ or suffix with _ (pick one convention).
  • Namespace names: lowercase, short (namespace io, namespace util).

Modern C++ (17/20/23)

  • Use auto for iterator types and complex template deductions.
  • Use std::optional<T> instead of sentinel values or pointers for optional returns.
  • Use std::variant over union types. Use std::visit for dispatch.
  • Use std::string_view for non-owning string parameters.
  • Use structured bindings: auto [key, value] = *map.begin();.
  • Use constexpr for compile-time evaluation. Prefer over macros.

Memory Management

  • Use RAII exclusively. Every resource acquisition is an initialization.
  • Use std::unique_ptr for exclusive ownership (default choice).
  • Use std::shared_ptr only when ownership is genuinely shared.
  • Never use raw new/delete. Use std::make_unique / std::make_shared.
  • Use std::span<T> (C++20) for non-owning views over contiguous data.

Functions

  • Pass small types by value. Pass large types by const&.
  • Use [[nodiscard]] on functions whose return value must not be ignored.
  • Use noexcept on functions that do not throw (move constructors, destructors).
  • Limit function parameters to 4. Use structs for configuration objects.
  • Use trailing return types for complex template return deductions.

Includes and Dependencies

  • Use #pragma once or include guards. Prefer #pragma once for simplicity.
  • Order: corresponding header, C++ stdlib, third-party, project headers.
  • Forward-declare in headers when possible to reduce compile times.
  • Minimize header dependencies. Use the Pimpl idiom for ABI stability.

Avoid

  • Raw pointers for ownership. Use smart pointers.
  • C-style casts. Use static_cast, dynamic_cast, const_cast.
  • Macros for constants or functions. Use constexpr and templates.
  • using namespace std; in headers. Acceptable in .cpp files with caution.
  • std::endl -- use '\n' (endl flushes the buffer unnecessarily).

Formatting

  • Use clang-format with a committed .clang-format file.
  • Use clang-tidy for static analysis and automated modernization.
  • Max line length: 100-120 characters.
  • Braces: use Allman or K&R consistently per project.

C++ Frameworks

CMake

  • Use modern CMake (3.14+): target-based, not directory-based.
  • Use target_link_libraries with PUBLIC/PRIVATE/INTERFACE visibility.
  • Use FetchContent for dependency management. Avoid manual submodule vendoring.
  • Set CMAKE_CXX_STANDARD 20 (or 23) at the project level.
  • Use target_compile_options for per-target flags, not global add_compile_options.
  • Export targets with install(TARGETS ... EXPORT ...) for library consumers.

Boost

  • Use Boost.Asio for async networking and I/O.
  • Use boost::beast for HTTP/WebSocket built on Asio.
  • Use boost::json or nlohmann/json for JSON parsing.
  • Prefer C++ stdlib equivalents when available (e.g., std::optional over boost::optional).
  • Link only the Boost libraries you actually use. Many are header-only.

Qt

  • Use signals and slots for event-driven communication.
  • Use QObject parent-child ownership for automatic memory management.
  • Use QML for declarative UI. Keep business logic in C++ backend.
  • Use QThread with worker objects (moveToThread), not subclassing QThread.
  • Use smart pointers for non-QObject resources. QObject children are auto-deleted.

gRPC

  • Define services in .proto files. Generate C++ stubs with protoc.
  • Use async server with CompletionQueue for high-throughput services.
  • Use grpc::ClientContext for per-call deadlines and metadata.
  • Use interceptors for logging, auth, and metrics.
  • Set deadlines on every RPC call to prevent hanging.

Networking (Asio)

  • Use io_context as the event loop. Run from one or more threads.
  • Use co_await (C++20 coroutines) with Asio for clean async code.
  • Use strand for serializing access to shared state across handlers.
  • Use steady_timer for timeouts and periodic tasks.
  • Handle errors via error_code parameter, not exceptions, in async callbacks.

Database

  • Use libpq (PostgreSQL) or SOCI for database access.
  • Use prepared statements exclusively. Never concatenate SQL strings.
  • Use connection pooling for multi-threaded server applications.
  • Use SQLite via sqlite3 C API with RAII wrappers for embedded use cases.

Package Management

  • Use vcpkg or Conan 2 for dependency management.
  • Pin dependency versions in vcpkg.json or conanfile.py.
  • Use CI caching for build artifacts and dependency downloads.
  • Prefer pre-built binary packages for CI speed.

C++ Patterns

Error Handling

  • Use exceptions for truly exceptional conditions. Use return types for expected failures.
  • Use std::expected<T, E> (C++23) or Result<T, E> pattern for recoverable errors.
  • Use std::error_code / std::error_category for system-level errors.
  • Use noexcept on functions that must not throw (destructors, move operations).
  • Catch by const&. Never catch by value (slicing) or pointer.

RAII Patterns

  • Wrap every resource (memory, file, lock, socket) in an RAII type.
  • Use std::lock_guard or std::scoped_lock for mutex management.
  • Use std::unique_lock when deferred locking or condition variables are needed.
  • Use std::fstream (auto-closes) instead of fopen/fclose.
  • Write custom RAII wrappers for C library resources (file descriptors, handles).

Smart Pointer Patterns

  • unique_ptr: default ownership model. Transfer with std::move.
  • shared_ptr: use only for genuinely shared ownership graphs.
  • weak_ptr: break cycles in shared_ptr graphs. Use lock() to access.
  • Factory functions should return unique_ptr. Let callers upgrade to shared_ptr.
  • Never pass smart pointers by reference. Pass T& or T* to non-owning consumers.

Concurrency

  • Use std::thread with std::jthread (C++20) for auto-joining threads.
  • Use std::mutex + std::scoped_lock for shared data protection.
  • Use std::atomic<T> for lock-free single-variable synchronization.
  • Use std::condition_variable for producer-consumer patterns.
  • Use std::async / std::future for simple parallel computation.
  • Use std::counting_semaphore (C++20) for resource pool limiting.

Template Patterns

  • Use CRTP for compile-time polymorphism (static dispatch).
  • Use concepts (C++20) to constrain template parameters with clear error messages.
  • Use if constexpr for compile-time branching in templates.
  • Use variadic templates and fold expressions for parameter packs.
  • Prefer constexpr functions over template metaprogramming when possible.

Design Patterns

  • Use std::variant + std::visit for type-safe visitor pattern.
  • Use std::function for type-erased callbacks and strategy pattern.
  • Use Pimpl idiom (unique_ptr<Impl>) for ABI stability and compilation firewall.
  • Use Builder pattern with method chaining for complex object construction.
  • Use std::move semantics in move constructors for efficient resource transfer.

Anti-Patterns

  • Raw new/delete: use smart pointers and containers.
  • Returning raw pointers from factory functions: return unique_ptr.
  • const_cast to remove constness: redesign the interface.
  • Deep inheritance hierarchies: prefer composition and templates.
  • Premature optimization over readability: profile first, optimize second.
Show full SKILL.md (632 more words)Show less

C++ Security

Buffer Overflow Prevention

  • Use std::string, std::vector, std::array instead of C arrays and char[].
  • Use std::span (C++20) for safe, bounds-checked views over contiguous data.
  • Never use strcpy, strcat, sprintf. Use std::string operations or snprintf.
  • Enable -D_FORTIFY_SOURCE=2 in release builds for runtime buffer checks.
  • Use at() for bounds-checked container access in untrusted input paths.

Memory Safety

  • Use smart pointers exclusively. Zero raw new/delete in application code.
  • Enable AddressSanitizer (-fsanitize=address) in development and CI builds.
  • Enable UndefinedBehaviorSanitizer (-fsanitize=undefined) in test builds.
  • Use -fstack-protector-strong for stack buffer overflow detection.
  • Use Valgrind for memory leak detection in integration tests.

Integer Safety

  • Check for overflow before arithmetic on untrusted integers.
  • Use std::numeric_limits<T>::max() for boundary checks.
  • Use unsigned types only for bit manipulation. Prefer signed for arithmetic.
  • Use static_cast explicitly. Never rely on implicit narrowing conversions.
  • Enable -Wconversion and -Wsign-conversion warnings.

Input Validation

  • Validate all external input: file data, network packets, command-line arguments.
  • Use std::stoi / std::stol with exception handling for string-to-number conversion.
  • Set maximum sizes for dynamic allocations based on untrusted input.
  • Validate file paths to prevent directory traversal (../).
  • Use allowlist validation for format specifiers and command strings.

Secure Coding

  • Use std::fill or explicit_bzero() to zero sensitive memory before deallocation.
  • Use constant-time comparison for secrets (avoid timing side-channels).
  • Use mlock() to prevent sensitive memory from being swapped to disk.
  • Compile with -fPIE -pie for position-independent executables (ASLR).
  • Enable -Werror in CI to prevent warnings from becoming vulnerabilities.

Dependencies

  • Audit third-party C libraries for known CVEs before inclusion.
  • Use vcpkg or Conan with pinned versions for reproducible builds.
  • Prefer well-maintained libraries with active security response teams.
  • Minimize C library usage. Prefer C++ standard library equivalents.

Concurrency Safety

  • Use std::mutex with std::scoped_lock for all shared data access.
  • Use std::atomic for lock-free single-variable operations.
  • Enable ThreadSanitizer (-fsanitize=thread) in test builds for race detection.
  • Avoid volatile for synchronization. It does not provide atomicity or ordering.
  • Use RAII lock guards. Never manually lock()/unlock().

Compiler Hardening

  • Enable all warnings: -Wall -Wextra -Wpedantic.
  • Use -D_GLIBCXX_ASSERTIONS for debug iterator and container checks.
  • Use -fno-exceptions only when exception safety is not required.
  • Link with -Wl,-z,relro,-z,now for full RELRO (GOT hardening).

C++ Testing

Framework

  • Use GoogleTest (gtest) as the primary test framework.
  • Use GoogleMock (gmock) for mocking interfaces and virtual classes.
  • Use Catch2 as a lightweight alternative (header-only, BDD-style).
  • Use CTest for test discovery and execution via CMake.

File Naming

  • Test files: foo_test.cpp or test_foo.cpp in a dedicated tests/ directory.
  • Mirror source directory structure in test directory.
  • One test file per source file or logical component.
  • Use CMakeLists.txt with add_test() to register tests.

Structure (GoogleTest)

  • Use TEST(SuiteName, TestName) for simple tests.
  • Use TEST_F(FixtureName, TestName) for tests sharing setup/teardown.
  • Use SetUp() / TearDown() in fixtures for per-test initialization.
  • Keep tests focused: one logical assertion per test case.

Assertions

  • Use EXPECT_* (non-fatal) by default. Use ASSERT_* only when continuation is meaningless.
  • EXPECT_EQ, EXPECT_NE, EXPECT_LT, EXPECT_GT for comparisons.
  • EXPECT_TRUE, EXPECT_FALSE for boolean conditions.
  • EXPECT_THROW(expr, ExceptionType) for exception testing.
  • EXPECT_THAT(value, matcher) with gmock matchers for complex assertions.

Parameterized Tests

  • Use INSTANTIATE_TEST_SUITE_P with testing::Values(...) for value-parameterized tests.
  • Use testing::Combine() for multi-dimensional parameterization.
  • Use TYPED_TEST_SUITE for type-parameterized tests across template types.
  • Prefer parameterized tests over copy-pasting similar test bodies.

Mocking (GoogleMock)

  • Define mock classes: MOCK_METHOD(ReturnType, MethodName, (Args), (Qualifiers)).
  • Use EXPECT_CALL(mock, Method(matchers)).WillOnce(Return(value)).
  • Use NiceMock<T> to suppress uninteresting call warnings.
  • Use StrictMock<T> to fail on any unexpected call.
  • Use dependency injection (constructor) to pass mock objects.

Build Integration

  • Use FetchContent or find_package to integrate gtest in CMake.
  • Enable BUILD_TESTING option to conditionally include tests.
  • Use ctest --output-on-failure for CI runs.
  • Use sanitizers in test builds: -fsanitize=address,undefined.

Best Practices

  • Test edge cases: empty input, max values, null pointers, boundary conditions.
  • Use RAII test fixtures for resource cleanup (no manual teardown).
  • Avoid testing private methods directly. Test through public API.
  • Use valgrind or ASan/UBSan in CI to detect memory errors.
  • Keep tests fast: mock I/O and external dependencies.

© softspark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in app/skills/cpp-rules of softspark/ai-toolkit.

Open the folder on GitHubat commit d64db2b

Compare with similar skills

Cpp Rules next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cpp Rules compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cpp Rules this skillsoftspark/ai-toolkit179—~3.4kAutomated safety check: PassApache-2.0
Qt C++ Code Reviewx-tools-author/x-tools1.1k2 repos~4.3kAutomated safety check: PassBSD-3-Clause
YugabyteDB ASH Instrumentationyugabyte/yugabyte-db11k—~4.5kAutomated safety check: PassCustom licence
pybind11 Release Preparationpybind/pybind1118k—~1.7kAutomated safety check: PassCustom licence
Qt Cpp ReviewSerial-Studio/Serial-Studio7.2k—~4.3kAutomated safety check: PassCustom licence
Paddle Eager GraphPaddlePaddle/Paddle24k—~562Automated safety check: PassApache-2.0

Similar skills

  • Qt C++ Code Review

    x-tools-author/x-tools

    Read-only review of Qt6 C++ code that combines a deterministic lint script with six parallel analysis agents and reports only high-confidence issues.

    1.1k GitHub starsUsed in 2 repos~4.3k tokens
    DevelopmentAuto-check passed
  • YugabyteDB ASH Instrumentation

    yugabyte/yugabyte-db

    Procedure for adding or changing YugabyteDB Active Session History wait states in TServer and DocDB C++ code, including the macro to use for sync and async paths.

    11k GitHub stars~4.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Opens the pybind11 release-preparation pull request: picking the release base, bumping the version in common.h and integrating the changelog, following docs/release.rst.

    18k GitHub stars~1.7k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Qt Cpp Review

    Serial-Studio/Serial-Studio

    Qt6/C++ deep code review for Serial Studio. An agent skill from Serial-Studio/Serial-Studio.

    7.2k GitHub stars~4.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Paddle Eager Graph

    PaddlePaddle/Paddle

    A skill your agent uses when navigating Paddle eager-mode (dynamic graph) source code, tracing forward/backward execution, debugging autograd issues, understanding PyLayer, or investigating…

    24k GitHub stars~562 tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • ONNX Runtime Source Build

    microsoft/onnxruntime

    Official

    Builds ONNX Runtime from source with its build scripts, explaining the update, build and test phases, key flags and where the build output lands.

    22k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed

More from softspark/ai-toolkit

All 112 skills in this repo
  • Prepare Test Env

    softspark/ai-toolkit

    Prepare or verify a project QA environment with source identity, readiness, browser access, evidence paths and owned cleanup.

    179 GitHub stars~1.8k tokensUpdated today
    Auto-check: notes
  • A11y Validate

    softspark/ai-toolkit

    Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.8k tokensUpdated today
    Auto-check: notes
  • Analyze

    softspark/ai-toolkit

    Analyzes code quality, complexity, patterns across codebase.

    179 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Autonomous Dev

    softspark/ai-toolkit

    Drives a brief, specification, issue or existing PR through implementation, review, tests and QA to a ready PR.

    179 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Brand Voice

    softspark/ai-toolkit

    Direct technical voice for docs, README, user-facing text. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • CI

    softspark/ai-toolkit

    Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).

    179 GitHub stars~1.1k tokensUpdated today
    Auto-check: notes

Works with

Categories

Questions about Cpp Rules

What does Cpp Rules do?

C++ coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit. Cpp Rules is an agent skill from softspark/ai-toolkit. C++ coding rules: style, patterns, security, testing.

When should I use Cpp Rules?

Cpp Rules fits situations like: development work in your project.

How do I install Cpp Rules in Claude Code?

Run `npx skills add softspark/ai-toolkit --skill cpp-rules -a claude-code`. Or copy the skill folder (app/skills/cpp-rules in softspark/ai-toolkit) into .claude/skills/cpp-rules in your project. Claude Code loads it when a task matches its description.

How do I install Cpp Rules in Codex?

Run `npx skills add softspark/ai-toolkit --skill cpp-rules -a codex`. Or copy the skill folder (app/skills/cpp-rules in softspark/ai-toolkit) into .agents/skills/cpp-rules in your project. Codex loads it when a task matches its description.

Can I use Cpp Rules in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add softspark/ai-toolkit --skill cpp-rules -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cpp-rules, .gemini/skills/cpp-rules, .github/skills/cpp-rules and .opencode/skills/cpp-rules in your project.

What does Cpp Rules need to run?

SKILL.md names no scripts, command-line tools or credentials: Cpp Rules is instructions for the agent only. Its frontmatter pre-approves these tools: Read.

Does Cpp Rules access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cpp Rules safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cpp Rules use?

Cpp Rules is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cpp Rules use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cpp Rules?

Skills that share tags, products or a category with Cpp Rules: Qt C++ Code Review (x-tools-author/x-tools, 1.1k stars), YugabyteDB ASH Instrumentation (yugabyte/yugabyte-db, 11k stars), pybind11 Release Preparation (pybind/pybind11, 18k stars) and Qt Cpp Review (Serial-Studio/Serial-Studio, 7.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cpp Rules?

softspark (a GitHub user) maintains it in softspark/ai-toolkit, which has 179 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on October 7, 2026.

Source: softspark/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.