Static Analysis
Purpose
Guide agents through selecting, running, and triaging static analysis tools for C/C++ — clang-tidy, cppcheck, and scan-build — including suppression strategies and CI integration.
Triggers
- "How do I run clang-tidy on my project?"
- "What clang-tidy checks should I enable?"
- "cppcheck is reporting false positives — how do I suppress them?"
- "How do I set up scan-build for deeper analysis?"
- "My build is noisy with static analysis warnings"
- "How do I generate compile_commands.json for clang-tidy?"
Workflow
1. Generate compile_commands.json
clang-tidy requires a compilation database:
2. Run clang-tidy
3. Check category decision tree
4. .clang-tidy configuration file
5. Suppress false positives
Or in .clang-tidy:
6. Run cppcheck
7. Path-sensitive analysis with scan-build
scan-build finds deeper bugs than clang-tidy: use-after-free across functions, dead stores from logic errors, null dereferences on complex paths.
8. CI integration
For clang-tidy check details, see references/clang-tidy-checks.md [blocked].
Related skills
- Use
skills/compilers/clangfor Clang toolchain and diagnostic flags - Use
skills/compilers/gccfor GCC warnings as complementary analysis - Use
skills/runtimes/sanitizersfor runtime bug detection alongside static analysis - Use
skills/build-systems/cmakeforCMAKE_EXPORT_COMPILE_COMMANDSsetup


