Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Hmos Memleak Analysis

ASecurity

Analyzes HarmonyOS source code (ArkTS, JS, C/C++) to detect memory leaks.Use when (1) Performing static code analysis to catch potential leaks before deployment, (2) Reviewing PRs involving complex UI lifecycles or NAPI implementations,(3) Developing NAPI bridges between ArkTS and C++. Maps code to official specifications and applies heuristics for NAPI reference management and lifecycle synchronization.

2 stars
0 votes
0 copies
0 views
Added 9/22/2026
documentationpythongoc++api

Works with

api

Security Analysis

A100/100

Scanned 9/22/2026

Install to Claude Code

$npx -y skills add IsKenKenYa/skills --skill hmos-memleak-analysis --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Hmos Memleak Analysis?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Hmos Memleak Analysis
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/iskenkenya-hmos-memleak-analysis/badge)](https://www.skillsdirectory.com/skills/iskenkenya-hmos-memleak-analysis)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: hmos-memleak-analysis
description: Analyzes HarmonyOS source code (ArkTS, JS, C/C++) to detect memory leaks.Use when (1) Performing static code analysis to catch potential leaks before deployment, (2) Reviewing PRs involving complex UI lifecycles or NAPI implementations,(3) Developing NAPI bridges between ArkTS and C++. Maps code to official specifications and applies heuristics for NAPI reference management and lifecycle synchronization.
license: MIT
metadata:
    author: superliet
    version: 1.1.0
    category: memleak
---

# HarmonyOS Memory Leak Expert

## Analysis Workflow

1. **Language Routing**: Based on file extension:
   - `.ets`, `.ts`, `.js` → use `references/HarmonyOS_App_MemoryLeak_Specifications_arkts_js_api.md`,Before applying any code inspection rules
   - `.cpp`, `.c`, `.h` → use `references/HarmonyOS_App_MemoryLeak_Specifications_c_api.md`
   - The final report must include the analysis of the results of 'scripts/filter_on.py' and the results of the code review

2. **Script**
   - you MUST execute an external Python script `scripts/filter_on.py` and `scripts/filter_risk_func.py` with param `target source code dirpath`. Crucial Note: These candidates are NOT confirmed leaks. They are merely hypotheses or "leads" that require human-like verification.

3. **Core Heuristics**:
   - **Lifecycle Sync**: Use a listener similar to ''. The on() in TS must be deregistered as "aboutToDisappear()"/"onPageHide()" after its lifecycle ends. You can use scripts/filter_on.py to investigate possible on/off code involved
   - **NAPI Boundary**: Check `napi_create_reference` balanced with `napi_delete_reference`. Watch for missing `napi_handle_scope` in loops.
   - **Closure Retention**: Async callbacks capturing `this` cause leaks if component is destroyed before callback executes.
   - **Singleton/AppStorage**: Large objects in `AppStorage` need explicit cleanup strategy.

4. **Reporting Format(md)**: 
Report MUST list all issue file and generate a structured markdown report named memory_leak_analysis_report_<timestamp>.md
   - **FilePath**: (e.g., D:/xx/xxx/xxx.ts)
   - **LineNumber**: (e.g. 245)
   - **IssueType **: Category of the leak (e.g.,"Unreleased NAPI Reference", "Uncleared Timer", "Event Listener Leak", "Closure Retention", "Global Variable Accumulation")
   - **Severity**: [Major | Minor], Refer to the rules of HarmonyOS_Sapp_SemoryLeak_Specifications
   - **CodeSnippet**:  The relevant 5~10 lines of code surrounding the issue for quick context.
   - **SuggestedFix**:  Concrete code snippet or instruction to resolve the issue (e.g., "Add `clearTimeout` in `useEffect` cleanup").
   - **ConfidenceScore**: A score from 1-10 indicating the certainty of the finding (10 = Definite Leak). 

Attribution

IsKenKenYaIsKenKenYa
View sourceMore from IsKenKenYa →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Context Fundamentals

Understand the components, mechanics, and constraints of context in agent systems. Use when designing agent architectures, debugging context-related failures, or optimizing context usage.

179001 votes

release-notes

Draft release notes and changelog entries from git history or merged PRs between two refs (tags/SHAs/branches), including breaking changes, migrations, and upgrade steps. Use when the user asks for release notes, changelog updates, or a GitHub Release draft.

1301 votes

docs-style-guide

Documentation style guide enforcer by @planetabhi. Applies and reviews the writing style guide when authoring or editing product documentation and tutorials. Use to check prose for voice, tense, word choice, inclusive language, formatting, code block, UI, Markdown, and number/date conventions.

11 votes

Caveman Help

Quick-reference card for caveman modes, skills and commands. Trigger: /caveman-help or "caveman help".

1066600 votes

How It Works

Explain how claude-mem captures observations, when memory injection kicks in, and where data lives. Use when the user asks "how does claude-mem work?" or "what is this thing doing?".

942310 votes
View all in documentation →