Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add gmh5225/awesome-llvm-security --skill llvm-securitygit clone --depth 1 https://github.com/gmh5225/awesome-llvm-securityWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/gmh5225/awesome-llvm-security/llvm-security)<a href="https://agentmods.dev/skills/gmh5225/awesome-llvm-security/llvm-security"><img src="https://agentmods.dev/badge/skills/gmh5225/awesome-llvm-security/llvm-security/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/gmh5225/awesome-llvm-security/llvm-security"><img src="https://agentmods.dev/badge/skills/gmh5225/awesome-llvm-security/llvm-security.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00043 | $0.01806 |
| Opus 5 | $0.00022 | $0.00903 |
| Sonnet 5 | $0.00009 | $0.00361 |
| Haiku 4.5 | $0.00004 | $0.00181 |
Grade A, and why
llvm-security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 298 lines — stays where its author put it; the contents beside it link to each section on GitHub.
LLVM Security Skill
This skill covers LLVM-based security features, sanitizers, hardening mechanisms, and secure software development practices.
Sanitizers
AddressSanitizer (ASan)
Detects memory errors: buffer overflow, use-after-free, use-after-scope.
# Compile with ASan
clang -fsanitize=address -g program.c -o program
# Key features
# - Stack buffer overflow detection
# - Heap buffer overflow detection
# - Use-after-free detection
# - Memory leak detection
MemorySanitizer (MSan)
Detects uninitialized memory reads.
clang -fsanitize=memory -g program.c -o program
ThreadSanitizer (TSan)
Detects data races in multithreaded programs.
clang -fsanitize=thread -g program.c -o program
UndefinedBehaviorSanitizer (UBSan)
Detects undefined behavior at runtime.
clang -fsanitize=undefined -g program.c -o program
# Specific checks
clang -fsanitize=signed-integer-overflow,null program.c
Custom Sanitizer Development
// Implementing custom memory tracking
extern "C" void __asan_poison_memory_region(void const volatile *addr, size_t size);
extern "C" void __asan_unpoison_memory_region(void const volatile *addr, size_t size);
class SecureAllocator {
public:
void* allocate(size_t size) {
// Add red zones around allocation
void* ptr = malloc(size + 2 * REDZONE_SIZE);
__asan_poison_memory_region(ptr, REDZONE_SIZE);
__asan_poison_memory_region((char*)ptr + REDZONE_SIZE + size, REDZONE_SIZE);
return (char*)ptr + REDZONE_SIZE;
}
};
Hardening Techniques
Stack Protection
# Stack canaries
clang -fstack-protector-strong program.c
# Stack clash protection
clang -fstack-clash-protection program.c
# Safe stack (separate stacks for safe/unsafe data)
clang -fsanitize=safe-stack program.c
Control Flow Integrity (CFI)
# Forward-edge CFI
clang -fsanitize=cfi -flto program.c
# Specific CFI schemes
clang -fsanitize=cfi-vcall # Virtual call checks
clang -fsanitize=cfi-nvcall # Non-virtual member call checks
clang -fsanitize=cfi-icall # Indirect call checks
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 298 lines · 43 tokens per session scan A f3312a4ba2c2
llvm-security is a skill published in the GitHub repository gmh5225/awesome-llvm-security (880 stars, last pushed 25d ago), licensed MIT. It adds 43 tokens to every session and 1,806 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
clangd-graph-rag
This skill enables deep semantic and structural analysis of C/C++ codebases using a pre-built Neo4j GraphRAG. It provides insights into call chains, class hierarchies, macro causality, and type aliases.
zoom-meeting-sdk-unreal
Zoom Meeting SDK for Unreal Engine wrapper integrations. Use when building Unreal projects that embed Zoom meetings with C++ and Blueprint wrappers, including wrapper-to-SDK mapping concerns.
ax-cpp-gen
Use when writing C++ code with axllm for AxGen programs, forward calls, indexed multi-sampling, result pickers, streaming, tools, assertions, traces, usage, and output parsing.
doca-argp
Use this skill for hands-on DOCA Arg Parser CLI work on a shipped sample or new DOCA-using app — adding / removing / renaming flags; wiring docaargpinit → register params → docaargpstart → docaargpdestroy in order; picking a parameter type from the full public enum (DOCAARGPTYPESTRING, INT, BOOLEAN, DEVICE, DEVICEREP…
cpu-kernels
Provides guidance for writing, optimizing, and benchmarking C++ CPU kernels with SIMD intrinsics (AVX2/AVX512) for the Hugging Face kernels ecosystem. Includes a two-phase workflow: Phase 1 correctness (generic → AVX2) and Phase 2 performance exploration (AVX512 with branching trial loop), runtime CPU dispatch, OpenMP…
embedded-stm32
Best practices for embedded C/C++ development on STM32 microcontrollers using the HAL, covering peripherals, DMA, interrupts, memory constraints, and hardware-focused testing. Use when writing STM32 HAL code, configuring peripherals generated by STM32CubeMX, working with interrupts or DMA, debugging with SWD/JTAG…