cpp-review-patterns

cpp-review-patterns is a skill for Claude Code, Codex from mickeyyaya/refactoring-skills. It costs 85 tokens per session (4,703 once invoked), scanned A, original, MIT.

A C++ code-review guide for memory and resource handling, undefined behavior, templates, const correctness, move semantics, and common design mistakes.

In plain words
What is it for?
Reviewing C++ pull requests, especially code involving hardware resources, exceptions, public interfaces, or performance-critical paths.
Why use it?
C++ code can leak resources, behave incorrectly only in optimized builds, or leave moved objects and templates in unsafe or confusing states.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/mickeyyaya/refactoring-skills/cpp-review-patterns
Any agent
npx skills add mickeyyaya/refactoring-skills --skill cpp-review-patterns
Clone the repo
git clone --depth 1 https://github.com/mickeyyaya/refactoring-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for cpp-review-patterns

README.md
[![agentmods](https://agentmods.dev/badge/skills/mickeyyaya/refactoring-skills/cpp-review-patterns.svg)](https://agentmods.dev/skills/mickeyyaya/refactoring-skills/cpp-review-patterns)
Your own site
<a href="https://agentmods.dev/skills/mickeyyaya/refactoring-skills/cpp-review-patterns"><img src="https://agentmods.dev/badge/skills/mickeyyaya/refactoring-skills/cpp-review-patterns.svg" alt="Measured on agentmods" height="20"></a>
Per session 85 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 4,703 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00085 $0.04703
Opus 5 $0.00043 $0.02351
Sonnet 5 $0.00017 $0.00941
Haiku 4.5 $0.00009 $0.00470

Measured 5d ago against content hash fd5e64ea529f, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

cpp-review-patterns scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/cpp-review-patterns/SKILL.md · 401 lines

How it starts

The opening of the file, as written. The whole thing — 401 lines — stays where its author put it; the contents beside it link to each section on GitHub.

C++ Code Review Patterns

Overview

C++ combines the expressive power of high-level abstractions with direct control over hardware resources — and pays for it with a class of bugs that no compiler or runtime can fully prevent. A reviewer trained on Java, Python, or even Rust will miss the failure modes that are unique to C++: resource leaks that appear only under exceptions, undefined behavior that silently produces wrong results in optimized builds, template errors that require a compiler archaeology dig to interpret, and move semantics that invalidate objects in ways that look valid at a glance.

This guide covers six areas where C++ code most commonly fails in review or in production: memory management and RAII, undefined behavior, template pitfalls, const correctness, move semantics, and systemic anti-patterns. Each section includes before/after code examples and severity rules calibrated to real-world impact.

Load this skill when reviewing any C++ PR that touches resource acquisition, performance-critical hot paths, public APIs, or code that must be exception-safe. Cross-reference review-accuracy-calibration before posting: many C++ issues are compiler-detectable with the right flags (-Wall -Wextra -fsanitize=address,undefined), and findings backed by sanitizer evidence are C4; findings based on code reading alone are typically C3.

Quick Reference

Review Dimension Severity Primary Red Flag
Raw new/delete without RAII HIGH new not paired with a smart pointer or RAII wrapper
Missing custom destructor HIGH Class owns a raw pointer but has no destructor, or has destructor but no copy/move ops
Shared ownership overuse MEDIUM shared_ptr where unique_ptr suffices; creates circular reference risk
Signed integer overflow CRITICAL Arithmetic on int with no overflow guard; UB in optimized builds
Use-after-free / dangling reference CRITICAL Pointer or reference to a destroyed object or invalidated container element
Uninitialized variable HIGH POD type declared without initializer; value is indeterminate
Strict aliasing violation HIGH reinterpret_cast between unrelated pointer types without memcpy
Template error message opacity LOW–MEDIUM Deep template instantiation with no static_assert guard
Missing concept constraint MEDIUM C++20 template accepting any type where only a subset is valid
Non-const method on logically const object MEDIUM Method mutates only cached state without mutable; blocks use in const contexts
std::move on const object HIGH std::move(const T) silently falls back to copy; intent unclear
Missing noexcept on move constructor MEDIUM Move constructor not noexcept; std::vector reallocation copies instead of moves
C-style cast MEDIUM–HIGH (T*)ptr hides the cast category; prefer static_cast, reinterpret_cast, or bit_cast
Exception in destructor CRITICAL Throwing from a destructor during stack unwinding calls std::terminate
Macro with side-effect argument HIGH Macro argument evaluated multiple times; use inline function or constexpr

Read the full file on GitHub · 401 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 401 lines · 85 tokens per session scan A fd5e64ea529f

Subscribe to this mod's changes

cpp-review-patterns is a skill published in the GitHub repository mickeyyaya/refactoring-skills (6 stars, last pushed 5mo ago), licensed MIT. It adds 85 tokens to every session and 4,703 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

new-cpp-lint

Create a new C++ lint rule, test it, run it across the codebase, and selectively apply fixes. Usage - /new-cpp-lint.

FastLED/FastLED · 41 tokens

doca-argp

Use this skill for hands-on DOCA Arg Parser CLI work on a shipped sample or new DOCA-using app — adding / removing / renaming flags; wiring docaargpinit → register params → docaargpstart → docaargpdestroy in order; picking a parameter type from the full public enum (DOCAARGPTYPESTRING, INT, BOOLEAN, DEVICE, DEVICEREP…

NVIDIA/skills · 267 tokens

ax-cpp-gen

Use when writing C++ code with axllm for AxGen programs, forward calls, indexed multi-sampling, result pickers, streaming, tools, assertions, traces, usage, and output parsing.

ax-llm/ax · 48 tokens

add-uint-support

Add unsigned integer (uint) type support to PyTorch operators by updating ATDISPATCH macros. Use when adding support for uint16, uint32, uint64 types to operators, kernels, or when user mentions enabling unsigned types, barebones unsigned types, or uint support.

pytorch/pytorch · 60 tokens

cuda-index-width

Choose 32-bit vs 64-bit index math in PyTorch CUDA kernels. Use when fixing large-tensor indexing overflows, deciding whether to use int64t, canUse32BitIndexMath, CUDAKERNELLOOPTYPE, or ATDISPATCHINDEXTYPES, and when considering binary-size or performance impact of index-type templating.

pytorch/pytorch · 71 tokens

cpu-kernels

Provides guidance for writing, optimizing, and benchmarking C++ CPU kernels with SIMD intrinsics (AVX2/AVX512) for the Hugging Face kernels ecosystem. Includes a two-phase workflow: Phase 1 correctness (generic → AVX2) and Phase 2 performance exploration (AVX512 with branching trial loop), runtime CPU dispatch, OpenMP…

huggingface/kernels · 89 tokens