Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

C

ASecurity

Language-specific super-code guidelines for c.

7 stars
0 votes
0 copies
0 views
Added 9/22/2026
documentationgo

Works with

mcp

Security Analysis

A100/100

Scanned 9/22/2026

$npx -y skills add JantonioFC/skillsbank --skill c --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of C?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for C
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/jantoniofc-skillsbank-97b6dad4/badge)](https://www.skillsdirectory.com/skills/jantoniofc-skillsbank-97b6dad4)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: c
description: "Language-specific super-code guidelines for c."
risk: safe
source: community
date_added: "2026-06-16"
---
# C: Idiomatic Efficiency Reference

## Table of Contents
1. [Memory Management](#memory)
2. [Pointers & Arrays](#pointers)
3. [Error Handling](#errors)
4. [Strings](#strings)
5. [Structs & Enums](#structs)
6. [Preprocessor & Headers](#preprocessor)
7. [Anti-patterns specific to C](#antipatterns)

---

## 1. Memory Management {#memory}

```c
// ❌ malloc without checking return value
char *buf = malloc(size);
strcpy(buf, src);

// ✅
char *buf = malloc(size);
if (!buf) return -ENOMEM;
memcpy(buf, src, size);
```

```c
// ❌ Casting malloc result (unnecessary in C, hides missing #include)
int *p = (int *)malloc(n * sizeof(int));

// ✅
int *p = malloc(n * sizeof *p);
```

```c
// ❌ free without nulling (dangling pointer risk in long-lived scope)
free(ptr);
// ... later code might use ptr

// ✅
free(ptr);
ptr = NULL;
```

```c
// ❌ Forgetting to free on early-return paths
char *a = malloc(100);
char *b = malloc(200);
if (!b) return -1; // leaks a

// ✅ — single cleanup label
char *a = NULL, *b = NULL;
a = malloc(100);
if (!a) goto cleanup;
b = malloc(200);
if (!b) goto cleanup;
// ... use a, b ...
cleanup:
    free(b);
    free(a);
```

**Use `sizeof *ptr` instead of `sizeof(Type)` — it stays correct when the type changes.**

---

## 2. Pointers & Arrays {#pointers}

```c
// ❌ Manual array size tracking
void process(int *arr, int len) { ... }
process(data, 10);

// ✅ — pass size alongside pointer, or use a struct
typedef struct { int *data; size_t len; } IntSlice;
```

```c
// ❌ Pointer arithmetic where array indexing is clearer
*(arr + i) = value;

// ✅
arr[i] = value;
```

```c
// ❌ VLA in production code (stack overflow risk, optional in C11+)
int arr[n];

// ✅
int *arr = malloc(n * sizeof *arr);
if (!arr) return -ENOMEM;
// ... use arr ...
free(arr);
```

---

## 3. Error Handling {#errors}

```c
// ❌ Using magic numbers for error returns
if (do_thing() == -1) { ... }

// ✅ — define or use named error codes
#include <errno.h>
if (do_thing() < 0) {
    perror("do_thing");
    return errno;
}
```

```c
// ❌ Deeply nested error checks
int r1 = step1();
if (r1 == 0) {
    int r2 = step2();
    if (r2 == 0) {
        int r3 = step3();
        // ...
    }
}

// ✅ — early return / goto cleanup
if (step1() < 0) goto fail;
if (step2() < 0) goto fail;
if (step3() < 0) goto fail;
return 0;
fail:
    cleanup();
    return -1;
```

**`goto cleanup` is idiomatic C for resource teardown — don't avoid it out of principle.**

---

## 4. Strings {#strings}

```c
// ❌ strcpy without bounds checking
strcpy(dest, src);

// ✅
strncpy(dest, src, sizeof(dest) - 1);
dest[sizeof(dest) - 1] = '\0';
// or better: snprintf(dest, sizeof(dest), "%s", src);
```

```c
// ❌ strcmp misuse
if (str == "hello") { ... } // compares pointers, not content

// ✅
if (strcmp(str, "hello") == 0) { ... }
```

```c
// ❌ Building strings with repeated strcat (O(n²))
char result[1024] = "";
for (int i = 0; i < n; i++) {
    strcat(result, items[i]);
}

// ✅ — track write position
char result[1024];
int pos = 0;
for (int i = 0; i < n && pos < (int)sizeof(result); i++) {
    pos += snprintf(result + pos, sizeof(result) - pos, "%s", items[i]);
}
```

**Prefer `snprintf` over `sprintf` — always.**

---

## 5. Structs & Enums {#structs}

```c
// ❌ Bare struct requiring `struct` keyword everywhere
struct point { int x, y; };
struct point p = {1, 2};

// ✅
typedef struct { int x, y; } Point;
Point p = {1, 2};
```

```c
// ❌ Uninitialized struct
Point p;
use(p.x); // UB

// ✅
Point p = {0};
```

```c
// ❌ Magic integer constants
if (state == 3) { ... }

// ✅
typedef enum { STATE_IDLE, STATE_RUNNING, STATE_DONE } State;
if (state == STATE_DONE) { ... }
```

---

## 6. Preprocessor & Headers {#preprocessor}

```c
// ❌ Macro where inline function works (no type safety, double eval)
#define MAX(a, b) ((a) > (b) ? (a) : (b))
MAX(x++, y) // x incremented twice if x > y

// ✅
static inline int max_int(int a, int b) { return a > b ? a : b; }
```

```c
// ❌ No include guard
// my_header.h
struct Foo { int x; };

// ✅
#ifndef MY_HEADER_H
#define MY_HEADER_H
struct Foo { int x; };
#endif
// or: #pragma once (widely supported, not standard)
```

**Keep macros for conditional compilation and constants. Use `static inline` for logic.**

---

## 7. Anti-patterns specific to C {#antipatterns}

| Anti-pattern | Preferred |
|---|---|
| `sprintf` | `snprintf` with buffer size |
| `gets` | `fgets` (gets is removed in C11) |
| Casting `malloc` result | let implicit `void*` conversion work |
| `sizeof(Type)` in malloc | `sizeof *ptr` |
| VLA for large/runtime arrays | heap allocation |
| `void*` callbacks without context param | pass `void *ctx` alongside function pointer |
| Global mutable state | pass state through struct pointers |
| `assert` for runtime error handling | proper error return codes |
| Missing `const` on read-only pointer params | `const char *str` |
| Mixing signed/unsigned in comparisons | use consistent types, cast explicitly |



## Limitations
- These are language-specific guidelines and do not cover overall architectural decisions.
- Over-compression might reduce readability; apply judgement.

Attribution

JantonioFCJantonioFC
View sourceSee grades on GitHubMore from JantonioFC →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Context Fundamentals

Understand the components, mechanics, and constraints of context in agent systems. Use when designing agent architectures, debugging context-related failures, or optimizing context usage.

179001 votes

Architecture Diagram Creator

Create comprehensive HTML architecture diagrams with data flows, business context, and system architecture.

6661 votes

release-notes

Draft release notes and changelog entries from git history or merged PRs between two refs (tags/SHAs/branches), including breaking changes, migrations, and upgrade steps. Use when the user asks for release notes, changelog updates, or a GitHub Release draft.

1301 votes

docs-style-guide

Documentation style guide enforcer by @planetabhi. Applies and reviews the writing style guide when authoring or editing product documentation and tutorials. Use to check prose for voice, tense, word choice, inclusive language, formatting, code block, UI, Markdown, and number/date conventions.

11 votes

Docx

Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files) or Word templates (.dotx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', '.dotx', or requests to produce professional documents with formatting like tables of contents, headings, page numbers, or letterheads. Also use when extracting or reorganizing content from .docx or .dotx files, inserting or replacing images in documents, performing find-and-replace in W...

1798860 votes
View all in documentation →