Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Clang

ASecurity

Use when a C or C++ build uses clang and needs diagnostics, optimization remarks, clang-tidy, ThinLTO with lld, LLVM PGO, or a GCC-to-Clang migration. Not for LLVM IR work: use llvm.

54 stars
0 votes
0 copies
0 views
Added 9/20/2026
ai-agentsgoc++performance

Security Analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned 9/20/2026

$npx -y skills add OutlineDriven/outline-driven-development --skill clang --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Clang?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Clang
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/outlinedriven-clang-outline-driven-development/badge)](https://www.skillsdirectory.com/skills/outlinedriven-clang-outline-driven-development)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: clang
description: 'Use when a C or C++ build uses clang and needs diagnostics, optimization remarks, clang-tidy, ThinLTO with lld, LLVM PGO, or a GCC-to-Clang migration. Not for LLVM IR work: use llvm.'
---

# Clang

## Contract

| Field | Bound contract |
|---|---|
| Trigger | A project compiles with `clang` or `clang++` and the user asks for better diagnostics, wants to see what the optimizer did or skipped, wants static analysis with clang-tidy, needs LTO through lld or LLVM PGO, or is moving a GCC build to Clang. |
| Authority | Read-only. The skill emits flags, commands, and readings to chat; `clang-tidy --fix` is shown but the user runs it. Rollback is not needed because no project file is written. No remote mutation. |
| Side effect | Chat output. Scratch compiles target a scratch file, never the project tree. |
| Done | The requested flag set or command is reported, every flag in it is confirmed against the installed Clang, and every remark or diagnostic in the request has a reading and a next action. |

## Inputs

- Compiler version: required, from `clang --version`. The current stable line is LLVM/Clang 23.1.0; Apple's `clang` reports an Apple version and lags upstream.
- The task: required. One of diagnostics, remarks, static analysis, LTO, PGO, GCC migration, or macOS specifics.
- Source file or compile command that reproduces the question: required for diagnostics and remarks.
- Linker available (`ld.lld`, `ld64`, GNU `ld`): required for LTO questions.

## Procedure

1. Confirm the compiler and driver: run `clang --version`. On macOS, `xcrun clang` resolves to the Xcode toolchain; Homebrew LLVM installs a separate upstream `clang`. Done when: the vendor and version are recorded.
2. Map GCC flags to Clang where they differ. Clang accepts most GCC driver flags. Differences that matter: `-Oz` shrinks harder than `-Os`; `-flto=thin` selects ThinLTO; `-fprofile-instr-generate` and `-fprofile-instr-use` select LLVM's own PGO format while `-fprofile-generate` and `-fprofile-use` keep the GCC-compatible format; `-Weverything` enables every warning and suits a one-off audit, not a production build; `--analyze` runs the Clang Static Analyzer where GCC has `-fanalyzer`. Attributes differ: gate GCC-only attributes with `__has_attribute(name)`. Done when: each GCC flag in the request has its Clang spelling or a note that it is unchanged.
3. Tune diagnostics with confirmed flags: `-ferror-limit=N` stops after N errors (default 20); `-fno-elide-type` prints full template types; `-fdiagnostics-show-template-tree` shows a tree diff for template mismatches; `-ftemplate-backtrace-limit=N` bounds the instantiation backtrace; `-fdiagnostics-parseable-fixits` emits fix-its in a machine-readable form; `-fdiagnostics-format=vi` or `msvc` changes the location format. Fix-it hints already print inline by default. Done when: the diagnostic flags are stated with their effect.
4. Read optimization remarks. Emit them with `-Rpass=<regex>` (transform happened), `-Rpass-missed=<regex>` (transform skipped), `-Rpass-analysis=<regex>` (why), for example `clang -O2 -Rpass-analysis=loop-vectorize src.c`. Save all remarks with `-fsave-optimization-record`, which writes `<object>.opt.yaml` next to the object file. Interpret: an inline remark on a hot path is good; `loop not vectorized: loop control flow is not understood` calls for restructuring the loop; a reordering-safety remark calls for `__restrict__` or `#pragma clang loop vectorize(assume_safety)` after the user proves no aliasing. Done when: each remark in the request has a reading and a next action.
5. Run static analysis. Built-in analyzer: `clang --analyze -Xanalyzer -analyzer-output=text src.c`. clang-tidy: `clang-tidy src.cpp -- -std=c++20 -I<dir>` for one file, `-p build/` against `compile_commands.json` (generate it with `cmake -DCMAKE_EXPORT_COMPILE_COMMANDS=ON`), `run-clang-tidy -j<N> -p build/` for the tree, `-checks='clang-analyzer-*,bugprone-*,modernize-*,performance-*'` to select families, `--fix` to apply fix-its in place. Suppress one line with `// NOLINT(check-name)` or the following line with `// NOLINTNEXTLINE(check-name)`. Done when: the analysis command and check families match the code class.
6. Configure LTO. Full: `clang -O2 -flto -fuse-ld=lld`. Thin: `clang -O2 -flto=thin -fuse-ld=lld`. Confirm the linker with `clang -fuse-ld=lld -Wl,--version`. ThinLTO links faster than full LTO on large programs; measure the code-quality difference on the project rather than assuming a ratio. `-fwhole-program-vtables` and `-fvirtual-function-elimination` need LTO. On macOS the default linker is `ld64`; `-fuse-ld=lld` needs an upstream LLVM install. Done when: the LTO mode, linker, and confirmation command are stated.
7. Configure PGO: `clang -O2 -fprofile-instr-generate` to instrument, run the workload (writes `default.profraw`; set `LLVM_PROFILE_FILE="prog-%p.profraw"` for parallel runs), `llvm-profdata merge -output=prog.profdata *.profraw`, then `clang -O2 -fprofile-instr-use=prog.profdata`. Sampling-based profiles use `-fprofile-sample-use=<file>`. The full flow, context-sensitive PGO, and BOLT: use pgo. Done when: the four PGO commands are listed.
8. Handle macOS specifics when asked: set the deployment target with `-mmacosx-version-min=X.Y`; sanitizer runtimes are injected at load, so do not strip a sanitized binary; `xcrun clang` selects the Xcode toolchain. Done when: the macOS points relevant to the request are stated.
9. Confirm every flag against the installed Clang with a scratch compile; drop any the driver rejects and say so. Done when: no unconfirmed flag remains.

## Failure and recovery

| Failure class | Behavior |
|---|---|
| Version unknown | Run or request `clang --version`; do not guess. |
| Flag rejected by the driver | Remove it, report the rejection, offer the nearest supported flag. `--show-fixits` is one such flag: it does not exist, fix-its print by default. |
| `-fuse-ld=lld` fails | Report that lld is not installed for this toolchain and fall back to the system linker with `-flto`. |
| Remark regex matches nothing | Widen to `-Rpass-missed=.*` on the one file, then narrow. |
| `compile_commands.json` missing | Give the CMake export command, or run clang-tidy with explicit `--` flags on one file. |

## Output

A chat report with the flag set or command for the task, a reading of every diagnostic or remark supplied, and a confirmation line naming the Clang version the flags were checked against and any flag dropped.

Attribution

OutlineDrivenOutlineDriven
View sourceSee grades on GitHubMore from OutlineDriven →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698431 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →