xmake-policy

xmake-policy is a skill for Claude Code from xmake-io/xmake-skills. It costs 85 tokens per session (2,054 once invoked), scanned A, original, Apache-2.0.

A collection of named build switches configured with set_policy in xmake.lua. Policies control features such as warnings, link-time optimization, sanitizers, C++ modules, ccache, and package download behavior.

In plain words
What is it for?
Use it to enable or disable a build behavior for every target or for one target, and to read that setting from xmake scripts.
Why use it?
It gives project-wide or target-specific settings a consistent name instead of requiring compiler-specific flags throughout the build script.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the xmake-skills plugin — 58 skills shipped together

Good fit Use it to enable or disable a build behavior for every target or for one target, and to read that setting from xmake scripts.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/xmake-io/xmake-skills/xmake-policy
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add xmake-io/xmake-skills --skill xmake-policy
Clone the repo
git clone --depth 1 https://github.com/xmake-io/xmake-skills

Made for: Claude Code.

Or install xmake-skills, the plugin that ships this one along with the rest of its 58 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for xmake-policy

README.md
[![agentmods](https://agentmods.dev/badge/skills/xmake-io/xmake-skills/xmake-policy/github.svg)](https://agentmods.dev/skills/xmake-io/xmake-skills/xmake-policy)
Your own site
<a href="https://agentmods.dev/skills/xmake-io/xmake-skills/xmake-policy"><img src="https://agentmods.dev/badge/skills/xmake-io/xmake-skills/xmake-policy/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for xmake-policy

Your own site · 80×15
<a href="https://agentmods.dev/skills/xmake-io/xmake-skills/xmake-policy"><img src="https://agentmods.dev/badge/skills/xmake-io/xmake-skills/xmake-policy.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 85 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,054 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector pass 7 Sept 2026
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00085 $0.02054
Opus 5 $0.00043 $0.01027
Sonnet 5 $0.00017 $0.00411
Haiku 4.5 $0.00009 $0.00205

Measured 12d ago against content hash 8af86140e13c, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

xmake-policy scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/project-config/xmake-policy/SKILL.md · 233 lines

How it starts

The opening of the file, as written. The whole thing — 233 lines — stays where its author put it; the contents beside it link to each section on GitHub.

set_policy — Feature Toggles

Policies are named feature toggles xmake exposes via set_policy("<name>", <value>). They replace ad-hoc flags with a stable, versioned API — enabling a feature like "C++20 modules" or "address sanitizer" is a single call that works across compilers.

Policies live in xmake.lua and can be set at project or target scope.

1. Basic usage

-- project-wide
set_policy("build.warning", true)

target("app")
    -- per-target
    set_policy("build.optimization.lto", true)
    set_policy("build.sanitizer.address", true)
  • Project-scope (at top of xmake.lua) — applies to every target.
  • Target-scope (inside target(...)) — only that target.
  • Target values override the project value.

Reading a policy from script:

on_load(function (target)
    if target:policy("build.warning") then
        ...
    end
end)

2. Commonly-used policies, grouped

Compilation / warnings

set_policy("build.warning",             true)        -- show compile warnings (default off)
set_policy("check.auto_ignore_flags",   false)       -- don't auto-filter unknown flags
set_policy("check.auto_map_flags",      false)       -- don't auto-map gcc→msvc flag names

Optimization / linking

set_policy("build.optimization.lto",    true)        -- enable LTO
set_policy("build.merge_archive",       true)        -- merge all static archives into one
set_policy("build.release.strip",       true)        -- strip release binaries (v3.0.8+)
set_policy("build.rpath",               true)        -- auto-emit rpath for shared deps
set_policy("install.rpath",             true)        -- same at install time
set_policy("build.intermediate_directory", true)     -- use an intermediate dir per target

Sanitizers (GCC/Clang)

set_policy("build.sanitizer.address",   true)        -- -fsanitize=address
set_policy("build.sanitizer.thread",    true)        -- -fsanitize=thread
set_policy("build.sanitizer.memory",    true)        -- -fsanitize=memory
set_policy("build.sanitizer.leak",      true)        -- -fsanitize=leak
set_policy("build.sanitizer.undefined", true)        -- -fsanitize=undefined

Read the full file on GitHub · 233 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 233 lines · 85 tokens per session scan A 8af86140e13c

Subscribe to this mod's changes

xmake-policy is a skill published in the GitHub repository xmake-io/xmake-skills (24 stars, last pushed 19d ago), licensed Apache-2.0. It adds 85 tokens to every session and 2,054 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

zoom-meeting-sdk-unreal

Zoom Meeting SDK for Unreal Engine wrapper integrations. Use when building Unreal projects that embed Zoom meetings with C++ and Blueprint wrappers, including wrapper-to-SDK mapping concerns.

anthropics/knowledge-work-plugins · 41 tokens

ax-cpp-gen

Use when writing C++ code with axllm for AxGen programs, forward calls, indexed multi-sampling, result pickers, streaming, tools, assertions, traces, usage, and output parsing.

ax-llm/ax · 48 tokens

doca-argp

Use this skill for hands-on DOCA Arg Parser CLI work on a shipped sample or new DOCA-using app — adding / removing / renaming flags; wiring docaargpinit → register params → docaargpstart → docaargpdestroy in order; picking a parameter type from the full public enum (DOCAARGPTYPESTRING, INT, BOOLEAN, DEVICE, DEVICEREP…

NVIDIA/skills · 267 tokens

cpu-kernels

Provides guidance for writing, optimizing, and benchmarking C++ CPU kernels with SIMD intrinsics (AVX2/AVX512) for the Hugging Face kernels ecosystem. Includes a two-phase workflow: Phase 1 correctness (generic → AVX2) and Phase 2 performance exploration (AVX512 with branching trial loop), runtime CPU dispatch, OpenMP…

huggingface/kernels · 89 tokens

cudaq-importing

Use when porting circuits from another framework (e.g. Qiskit) into CUDA-Q kernels while preserving the source algorithm and validation fidelity.

NVIDIA/cuda-quantum · 34 tokens

llvm-learning

Comprehensive learning resources and tutorials for LLVM, Clang, and compiler development. Use this skill when helping users learn LLVM internals, find educational resources, or understand compiler concepts.

gmh5225/awesome-llvm-security · 39 tokens