Static Analysis

mohitmishra786/low-level-dev-skills/skills/build-systems/static-analysis

作者 mohitmishra786bdc58472fa9f無授權條款253 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫3 個月前更新

Static analysis skill for C/C++ codebases. Use when hardening code quality, triaging noisy builds, running clang-tidy, cppcheck, or scan-build, interpreting check categories, suppressing false positives, or integrating static analysis into CI. Activates on queries about clang-tidy checks, cppcheck, scan-build, compile_commands.json, code hardening, or static analysis warnings.

AI 產生的概覽

指導代理執行與分流 C/C++ 靜態分析工具,例如 clang-tidy、cppcheck 和 scan-build。

功能
此技能提供針對 C/C++ 程式碼庫選擇、執行與分流靜態分析工具的說明,涵蓋 clang-tidy、cppcheck 和 scan-build。內容包括產生 compile_commands.json、選擇檢查類別、撰寫 .clang-tidy 設定、抑制誤報,以及將分析整合到 CI。它另外附有一份關於 clang-tidy 檢查的參考文件。
適用情境
適用於強化 C/C++ 程式碼品質、處理靜態分析警告過多的建置,或設定 clang-tidy、cppcheck、scan-build 的情境。也適合關於檢查類別、誤報抑制、compile_commands.json,或將靜態分析加入 CI 的問題。
執行需求
不隨附指令碼,僅為說明文件。執行所述工具需要安裝 clang-tidy、cppcheck 和 scan-build,並需要 compile_commands.json 等編譯資料庫。

Static Analysis

Purpose

Guide agents through selecting, running, and triaging static analysis tools for C/C++ — clang-tidy, cppcheck, and scan-build — including suppression strategies and CI integration.

Triggers

  • "How do I run clang-tidy on my project?"
  • "What clang-tidy checks should I enable?"
  • "cppcheck is reporting false positives — how do I suppress them?"
  • "How do I set up scan-build for deeper analysis?"
  • "My build is noisy with static analysis warnings"
  • "How do I generate compile_commands.json for clang-tidy?"

Workflow

1. Generate compile_commands.json

clang-tidy requires a compilation database:

bash
# CMake (preferred)cmake -S . -B build -DCMAKE_EXPORT_COMPILE_COMMANDS=ONln -s build/compile_commands.json .
# Bear (for Make-based projects)bear -- make
# compiledb (alternative for Make)pip install compiledbcompiledb make

2. Run clang-tidy

bash
# Single fileclang-tidy src/foo.c -- -std=c11 -I include/
# Whole project via compile_commands.jsonrun-clang-tidy -p build/ -j$(nproc)
# With specific checks enabledclang-tidy -checks='bugprone-*,modernize-*,performance-*' src/foo.cpp
# Apply auto-fixesclang-tidy -checks='modernize-use-nullptr' -fix src/foo.cpp

3. Check category decision tree

text
Goal?├── Find real bugs            → bugprone-*, clang-analyzer-*├── Modernise C++ code        → modernize-*├── Follow core guidelines    → cppcoreguidelines-*├── Catch performance issues  → performance-*├── Security hardening        → cert-*, hicpp-*└── Readability / style       → readability-*, llvm-*
CategoryKey checksWhat it catches
bugprone-*use-after-move, integer-division, suspicious-memset-usageLikely bugs
modernize-*use-nullptr, use-override, use-autoC++11/14/17 idioms
cppcoreguidelines-*avoid-goto, pro-bounds-*, no-mallocC++ Core Guidelines
performance-*unnecessary-copy-initialization, avoid-endlPerformance regressions
clang-analyzer-*core.*, unix.*, security.*Path-sensitive bugs
cert-*err34-c, str51-cppCERT coding standard

4. .clang-tidy configuration file

yaml
# .clang-tidy — place at project rootChecks: >  bugprone-*,  modernize-*,  performance-*,  -modernize-use-trailing-return-type,  -bugprone-easily-swappable-parametersWarningsAsErrors: 'bugprone-*,clang-analyzer-*'HeaderFilterRegex: '^(src|include)/.*'CheckOptions:  - key: modernize-loop-convert.MinConfidence    value: reasonable  - key: readability-identifier-naming.VariableCase    value: camelCase

5. Suppress false positives

cpp
// Suppress a single lineint result = riskyOp(); // NOLINT(bugprone-signed-char-misuse)
// Suppress a block// NOLINTNEXTLINE(cppcoreguidelines-avoid-magic-numbers)constexpr int BUFFER_SIZE = 4096;
// Suppress whole function[[clang::suppress("bugprone-*")]]void legacy_code() { /* ... */ }

Or in .clang-tidy:

yaml
# Exclude third-party directoriesHeaderFilterRegex: '^(src|include)/.*'# Disable specific checksChecks: '-bugprone-easily-swappable-parameters'

6. Run cppcheck

bash
# Basic runcppcheck --enable=all --std=c11 src/
# With compile_commands.jsoncppcheck --project=build/compile_commands.json
# Include specific checks and suppress noisecppcheck --enable=warning,performance,portability \         --suppress=missingIncludeSystem \         --suppress=unmatchedSuppression \         --error-exitcode=1 \         src/
# Generate XML report for CIcppcheck --xml --xml-version=2 src/ 2> cppcheck-report.xml
--enable= valueWhat it checks
warningUndefined behaviour, bad practices
performanceRedundant operations, inefficient patterns
portabilityNon-portable constructs
informationConfiguration and usage notes
allEverything above

7. Path-sensitive analysis with scan-build

bash
# Intercept a Make buildscan-build make
# Intercept CMake buildscan-build cmake --build build/
# Show HTML reportscan-view /tmp/scan-build-*/
# With specific checkersscan-build -enable-checker security.insecureAPI.gets \           -enable-checker alpha.unix.cstring.BufferOverlap \           make

scan-build finds deeper bugs than clang-tidy: use-after-free across functions, dead stores from logic errors, null dereferences on complex paths.

8. CI integration

yaml
# GitHub Actions- name: Static analysis  run: |    cmake -S . -B build -DCMAKE_EXPORT_COMPILE_COMMANDS=ON    run-clang-tidy -p build -j$(nproc) -warnings-as-errors '*'
- name: cppcheck  run: |    cppcheck --enable=warning,performance \             --suppress=missingIncludeSystem \             --error-exitcode=1 \             src/

For clang-tidy check details, see references/clang-tidy-checks.md [blocked].

Related skills

  • Use skills/compilers/clang for Clang toolchain and diagnostic flags
  • Use skills/compilers/gcc for GCC warnings as complementary analysis
  • Use skills/runtimes/sanitizers for runtime bug detection alongside static analysis
  • Use skills/build-systems/cmake for CMAKE_EXPORT_COMPILE_COMMANDS setup

來源與署名

來源:mohitmishra786/low-level-dev-skills位於skills/build-systems/static-analysis提交bdc5847

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架