project-setup

A setup and build-hardening review for cross-platform C++17 projects, especially Node.js native add-ons built with node-gyp or node-addon-api. It checks build settings, analysis tools, portability, and code-maintenance practices.

In plain words
What is it for?
Use it to review binding.gyp files, compiler and linker protections, sanitizers, static analysis, CI setup, and practices such as ownership and exception handling across the C interface.
Why use it?
It shows which protective build and analysis controls are present, missing, unsuitable, or still need checking. It distinguishes preventive improvements from proven bugs.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/photostructure/coding-skills/project-setup
Any agent
npx skills add photostructure/coding-skills --skill project-setup
Clone the repo
git clone --depth 1 https://github.com/photostructure/coding-skills

Made for: Claude Code, Codex.

Per session 170 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 3,059 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00170 $0.03059
Opus 5 $0.00085 $0.01529
Sonnet 5 $0.00034 $0.00612
Haiku 4.5 $0.00017 $0.00306

Measured yesterday against content hash db3c1a3fb513, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

project-setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/cpp/skills/project-setup/SKILL.md · 235 lines

How it starts

The opening of the file, as written. The whole thing — 235 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Native C/C++ Project Setup & Hardening

Assess a cross-platform modern-C++ (C++17) project — especially a Node.js native addon built with node-gyp and node-addon-api — against a practical, evidence-based baseline for build hardening, analysis tooling, portability, and maintainable code. Report applicable preventive-control gaps even when no defect is currently proven, while clearly distinguishing hardening advice from actual bugs.

Use the OpenSSF Compiler Options Hardening Guide as the compiler/linker backbone, the C++ Core Guidelines for code conventions, CERT C/C++ and the sanitizer/tool docs for analysis, and official node-gyp / Node-API documentation for the addon toolchain. See ATTRIBUTION.md.

Boundary with resource review

Keep this skill separate from resource-review:

This skill (project-setup) The resource-review skill
Asks whether applicable controls meet a baseline Asks whether a memory/resource defect exists
Reports evidence-backed best-practice gaps Reports only proven defects
Uses Met / Gap / Not applicable / Needs verification Uses Critical / High / Medium / Low
Prioritizes Essential / Recommended / Optional Prioritizes impact and trigger reachability

A missing stack protector or an unset sanitizer job is a hardening Gap, not a vulnerability. If the assessment uncovers an actual defect (a real leak, use-after-free, or race), list it separately under Escalate to resource review and recommend the resource-review skill; do not mix it into hardening counts or assign it a CVSS-style severity.

Core rules

  • Applicability before compliance. Profile the project and select only controls that match its real build systems, target OSes/arches, threading, prebuild strategy, and vendored dependencies.
  • Effective behavior over presence. A flag in one conditions branch, a sanitizer script that never runs in CI, or a .clang-tidy with WarningsAsErrors: '' is not proof the control is effective on the shipped build.
  • Research globally, report locally. Read the whole binding.gyp/CMake, CI workflows, scripts, and common.gypi defaults to resolve what the compiler actually receives; report only on the requested scope.
  • Credit toolchain defaults. Mark a control Met when the toolchain or node-gyp common.gypi already provides it (MSVC /GS, /DYNAMICBASE, /NXCOMPAT are on by default; Release builds optimize). Do not flag a default-on protection as missing.
  • Arch-gate the dangerous flags. Some hardening flags hard-error on the wrong architecture (-fcf-protection=full is x86-only; -mbranch-protection is arm64-only). Recommending them ungated breaks the build — always require a target_arch condition.
  • No cargo-cult controls. Record Not applicable when a control has no relevant surface (TSan on a strictly single-threaded synchronous addon; -Wl,-z,* on a macOS-only build), with one-line reasoning.
  • Sanitizer-aware. _FORTIFY_SOURCE must be off in AddressSanitizer builds. Standard-library hardening assertions are independent and may remain enabled unless the project's exact toolchain demonstrates a conflict; a hardening recommendation that breaks the sanitizer build is a Gap, not an improvement.
  • No auto-apply. Propose changes; edit only when the user explicitly asks.

Read the full file on GitHub · 235 lines

Files

What ships with it

9 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 235 lines · 170 tokens per session scan A db3c1a3fb513

Subscribe to this mod's changes

project-setup is a skill published in the GitHub repository photostructure/coding-skills (3 stars, last pushed 2d ago), licensed MIT. It adds 170 tokens to every session and 3,059 once invoked, about $0.0009 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

github-pr-review

Handles PR review comments and feedback resolution. Use when user wants to resolve PR comments, handle review feedback, fix review comments, address PR review, check review status, respond to reviewer, verify PR readiness, review PR comments, analyze review feedback, evaluate PR comments, assess review suggestions, or…

fvadicamo/dev-agent-skills · 95 tokens

privacy-guard

Prevents private infrastructure details (node hostnames, internal project names, local usernames and personal emails, absolute home paths, private and VPN IP ranges) from leaking into public repositories through commits, PRs, docs or release artifacts. Use when working in a public or soon-to-be-public repo, before…

fvadicamo/dev-agent-skills · 128 tokens

decision-records

Creates, supersedes and validates decision records (ADRs) against the convention a collection already follows, instead of imposing a published one. Use when the user wants to record a decision, write an ADR, supersede an existing decision, audit or lint a decisions folder, check that an ADR index is in sync, or asks…

fvadicamo/dev-agent-skills · 113 tokens

github-pr-creation

Creates GitHub Pull Requests with automated validation and task tracking. Use when user wants to create PR, open pull request, submit for review, or check if ready for PR. Analyzes commits, validates task completion, generates Conventional Commits title and description, suggests labels. NOTE - for merging existing…

fvadicamo/dev-agent-skills · 75 tokens

github-pr-merge

Merges GitHub Pull Requests after validating pre-merge checklist. Use when user wants to merge PR, close PR, finalize PR, complete merge, approve and merge, or execute merge. Runs pre-merge validation (tests, lint, CI, comments), confirms with user, merges with proper format, handles post-merge cleanup.

fvadicamo/dev-agent-skills · 72 tokens

git-commit

Creates git commits following Conventional Commits format with type/scope/subject. Use when user wants to commit changes, create commit, save work, or stage and commit. Enforces project-specific conventions from CLAUDE.md.

fvadicamo/dev-agent-skills · 49 tokens