Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Port From Cpp

ASecurity

Port C++ into Rust — RAII and smart pointers onto ownership, templates onto generics and traits, exceptions onto Result, the STL onto Rust collections, and the traps (move semantics, implicit conversions, undefined behaviour, iterator invalidation). Use when porting, rewriting, or migrating C++, a C++ library, or a C++ application into Rust, when replacing a C++ module with Rust behind the existing build, or when the user asks how a C++ construct such as unique_ptr, shared_ptr, a template, or...

2 stars
0 votes
0 copies
1 views
Added 9/19/2026
developmentrustgoc++bashexpresstestinggit

Works with

cli

Security Analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned 9/19/2026

$npx -y skills add rewrite-rs/skills --skill port-from-cpp --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Port From Cpp?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Port From Cpp
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/rewrite-rs-port-from-cpp/badge)](https://www.skillsdirectory.com/skills/rewrite-rs-port-from-cpp)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: port-from-cpp
description: Port C++ into Rust — RAII and smart pointers onto ownership, templates onto generics and traits, exceptions onto Result, the STL onto Rust collections, and the traps (move semantics, implicit conversions, undefined behaviour, iterator invalidation). Use when porting, rewriting, or migrating C++, a C++ library, or a C++ application into Rust, when replacing a C++ module with Rust behind the existing build, or when the user asks how a C++ construct such as unique_ptr, shared_ptr, a template, or an STL container translates to Rust.
---

# Port from C++

## A construct mapping and a boundary, nothing else

This skill maps C++ to Rust and owns the C++ boundary. The parity
contract, the five phases, and the anti-patterns are `/port-to-rust`,
which runs first and stays running through the port. C is a separate
skill — the mechanics overlap, the idioms do not — so a C codebase
with a `.cpp` extension is still `/port-from-c` territory in everything
but the build.

## The end state, and the C++ default

`/port-to-rust` names three end states. In C++ terms: A, a standalone
Rust binary or library replacing the C++ entirely; B, a Rust core with
a permanent C++-callable surface, real when the deliverable is a
library other C++ code links; and C, a bridge that carries the
migration module by module and is deleted at cut-over. **C is the
default for C++**, more than for any other language in this set: a
large C++ codebase cannot be replaced in one step, and the seam — a
Rust `staticlib` linked into the existing build — lets leaf modules
move one at a time. The bridge is disposable scaffolding that must
still be *sound*, and that tension is what this skill manages; the
mechanics are in `BOUNDARY.md`.

## The traps that break parity silently

The body carries these five because each one produces a port that
passes a naive test suite and is wrong; the full table is `MAPPING.md`.

| Trap | What actually differs |
|---|---|
| Undefined behaviour was doing something | Signed overflow, strict aliasing violations, reading uninitialized memory, and out-of-bounds access are undefined in C++ and defined-or-rejected in Rust. Any behaviour the source got from UB is behaviour the port cannot reproduce and must not try to — it is found, recorded, and decided, and it is one of the few legitimate reasons for a port to differ from its source |
| Move semantics are not the same move | A C++ move leaves a valid, unspecified object behind and runs a destructor on it; a Rust move is a bitwise transfer with no hook and no leftover object. Code that reads a moved-from C++ object is doing something the port cannot express, and self-referential types that relied on move constructors need a different design entirely |
| Implicit conversions | C++ converts between numeric types, applies integer promotion, and calls converting constructors without a cast. Rust requires every conversion to be written, so a port surfaces conversions the source never made visible — and each one is a place a value could have been truncated silently |
| Iterator and reference invalidation | A `push_back` may reallocate and invalidate every outstanding iterator and reference; C++ tolerates the pattern until it does not. Rust rejects the pattern at compile time, so the port must restructure — usually with indices — and the restructuring is where the design gets clearer, not where it gets worse |
| Exceptions cross layers invisibly | An exception propagates through frames that never mention it, including destructors that run on the way out. Mapping to `Result` makes every propagation point visible and surfaces error paths the source never named — `/rust-errors`. Note the `noexcept` boundary: a C++ function that promises not to throw becomes an infallible signature, and one that did throw becomes `Result` |

## Mapping, in one line

`MAPPING.md` holds the full table; a row is a starting point, not a
rewrite rule. Where the source behaviour was undefined there is no
row — there is a contract decision.

## RAII maps, and this is the good news

Destructors map to `Drop`, `unique_ptr` to `Box`, `shared_ptr` to
`Arc` (or `Rc` where single-threaded), `weak_ptr` to `Weak`,
references to `&`/`&mut`, and `const` to immutability by default.
Reach for `Arc`/`Rc` only where the C++ genuinely shared ownership,
not everywhere a `shared_ptr` appeared — `shared_ptr` is often used
where a `unique_ptr` or a plain reference would have done, and
copying that habit into Rust produces the reference-counted soup
`/ownership-not-clone` exists to prevent. `Drop` cannot fail, so a
destructor that could throw becomes an explicit `close()`/`finish()`
returning `Result`.

## Templates are generics until they are not

Simple templates map to generics with trait bounds; SFINAE and
concepts map to bounds; CRTP usually maps to a plain trait; template
specialization maps to distinct trait impls. Where a template was doing
compile-time computation or reflection, the honest answer is often a
macro or a build script — a template metaprogram is usually
reimplemented rather than translated. Multiple inheritance and virtual
bases have no mapping and become composition.

## The test suite is the corpus, and the sanitizers are evidence

A GoogleTest or Catch2 suite is characterization input: the cases are
inputs, the assertions are the recorded behaviour. C++ ports have one
advantage no other language in this set does: running the source
under ASan, UBSan, and TSan before porting tells you which behaviours
are UB and therefore not part of the contract. Run it before any Rust
exists — the characterization pass of `/port-to-rust`; harness shapes
are `/rust-testing`.

## Verification

Both sides:

```bash
cargo test --all-features
cargo clippy --all-targets --all-features   # add -- -D warnings only if the target repo has no lint config
cargo miri test                              # any module with unsafe, including every FFI shim
ctest            # or the existing C++ test command — the source still passes while both run
```

Plus the source-side sanitizer run (`-fsanitize=address,undefined`),
whose findings belong in the contract as behaviour that is explicitly
not reproduced. Then the differential run over the recorded corpus,
reported with its denominator, plus the corpus requirement: at least
one case per trap — an input at a signed-overflow boundary, a
container operation that would have invalidated an iterator, a
narrowing conversion, and an input that threw.

Attribution

rewrite-rsrewrite-rs
View sourceSee grades on GitHubMore from rewrite-rs →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Clean Code

Pragmatic coding standards - concise, direct, no over-engineering, no unnecessary comments

304955 votes

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

285172 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2222 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Tanstack Start

Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per ...

10311 votes
View all in development →