cpp-quality
C++ static analysis and formatting tooling: clang-tidy, clang-format, cppcheck, include-what-you-use (IWYU), and CI integration patterns. USE WHEN: user mentions "clang-tidy", "clang-format", "cppcheck", "iwyu", "include-what-you-use", ".clang-tidy", ".clang-format", "C++ static analysis", "C++ linter" DO NOT USE FOR: SonarQube C++ rules (tool-agnostic), Coverity (commercial), PVS-Studio (commercial)
What this skill does
# C++ Quality Tooling - Quick Reference
> **Deep Knowledge**: Use `mcp__documentation__fetch_docs` with technology: `cpp-quality`.
## clang-format
Reformats source per a style file. Runs in milliseconds; safe to wire into pre-commit and editors.
`.clang-format`:
```yaml
---
BasedOnStyle: LLVM
Language: Cpp
Standard: c++20
ColumnLimit: 100
IndentWidth: 4
AccessModifierOffset: -4
AllowShortFunctionsOnASingleLine: Empty
AlwaysBreakTemplateDeclarations: Yes
BreakBeforeBraces: Attach
NamespaceIndentation: None
PointerAlignment: Left
SortIncludes: CaseInsensitive
IncludeBlocks: Regroup
SpaceAfterTemplateKeyword: false
```
Run:
```bash
clang-format -i src/**/*.cpp include/**/*.hpp
clang-format --dry-run --Werror src/foo.cpp # CI: fail if not formatted
git ls-files '*.cpp' '*.hpp' | xargs clang-format -i
```
Choose a base (`LLVM`, `Google`, `Mozilla`, `Chromium`, `Microsoft`) and tweak — don't bikeshed style from scratch.
## clang-tidy
Linter + simple refactor tool driven by `compile_commands.json` (enable with `set(CMAKE_EXPORT_COMPILE_COMMANDS ON)`).
`.clang-tidy`:
```yaml
---
Checks: >
-*,
bugprone-*,
cert-*,
clang-analyzer-*,
concurrency-*,
cppcoreguidelines-*,
modernize-*,
performance-*,
portability-*,
readability-*,
-modernize-use-trailing-return-type,
-readability-magic-numbers,
-readability-identifier-length,
-cppcoreguidelines-avoid-magic-numbers
WarningsAsErrors: '*'
HeaderFilterRegex: '^.*/(include|src)/.*\.(h|hpp)$'
FormatStyle: file
CheckOptions:
- { key: readability-function-cognitive-complexity.Threshold, value: '25' }
- { key: cppcoreguidelines-avoid-non-const-global-variables.AllowInternalLinkage, value: 'true' }
```
Run:
```bash
# Single file
clang-tidy -p build src/foo.cpp
# Whole project (parallelized)
run-clang-tidy -p build -quiet -header-filter='^.*/(include|src)/.*'
# Auto-apply fixes
run-clang-tidy -p build -fix -fix-errors
# CMake target
add_custom_target(tidy COMMAND run-clang-tidy -p ${CMAKE_BINARY_DIR})
```
### High-value check categories
| Category | What it catches |
|----------|-----------------|
| `bugprone-*` | Real defect patterns (use-after-move, sizeof on pointer, infinite loop) |
| `clang-analyzer-*` | Path-sensitive: null deref, leak, UB |
| `cppcoreguidelines-*` | Per the C++ Core Guidelines (ownership, narrowing, slicing) |
| `modernize-*` | Suggests modern equivalents (`nullptr`, `auto`, `make_unique`) |
| `performance-*` | Unnecessary copies, std::move misuse, string concat in loops |
| `concurrency-*` | Misuse of `std::thread`, `std::condition_variable` |
| `readability-*` | Naming, identifier conventions, redundant code |
### Suppressing
```cpp
// One line
int* p = (int*)x; // NOLINT(cppcoreguidelines-pro-type-cstyle-cast)
// Block
// NOLINTBEGIN(modernize-use-nodiscard)
int legacy_api();
// NOLINTEND(modernize-use-nodiscard)
```
Prefer fixing or disabling at config level for whole categories you don't want.
## cppcheck (complementary, not a replacement)
```bash
cppcheck --enable=warning,style,performance,portability \
--inline-suppr --error-exitcode=2 \
--project=build/compile_commands.json \
--suppress=missingIncludeSystem \
-i tests
```
Catches different patterns than clang-tidy (less path-sensitive but quicker; flags some uninitialized-member and dangling-reference issues clang-tidy misses).
## include-what-you-use (IWYU)
Reduces include bloat → faster builds + fewer accidental dependencies.
```bash
iwyu_tool.py -p build src/foo.cpp
fix_includes.py < iwyu.out # auto-apply suggestions
```
Annotate to override:
```cpp
#include <vector> // IWYU pragma: keep
class Foo; // IWYU pragma: forward_declare
```
## Compiler warnings (the cheap layer underneath)
```cmake
target_compile_options(mylib PRIVATE
$<$<CXX_COMPILER_ID:MSVC>:/W4 /WX /permissive- /w14640>
$<$<NOT:$<CXX_COMPILER_ID:MSVC>>:
-Wall -Wextra -Wpedantic -Werror
-Wshadow -Wnon-virtual-dtor -Wold-style-cast
-Wcast-align -Woverloaded-virtual -Wconversion -Wsign-conversion
-Wnull-dereference -Wdouble-promotion -Wformat=2
>
)
```
Don't skip this in favor of clang-tidy — compiler warnings are free and faster than any external tool.
## CI pipeline (GitHub Actions sketch)
```yaml
- name: Configure
run: cmake --preset debug
- name: Format check
run: |
git ls-files '*.cpp' '*.hpp' | xargs clang-format --dry-run --Werror
- name: Build
run: cmake --build --preset debug -j
- name: clang-tidy
run: run-clang-tidy -p build/debug -quiet
- name: Test
run: ctest --preset debug
```
## Anti-Patterns
| Anti-Pattern | Why It's Bad | Correct Approach |
|--------------|--------------|------------------|
| `WarningsAsErrors: '*'` then `// NOLINT` everywhere | Hides real issues | Disable check at config level instead |
| Running clang-tidy without `compile_commands.json` | Wrong include paths, false positives | Always pass `-p build/` |
| Reformatting whole repo in one PR | Murders `git blame` | One reformat commit, mark in `.git-blame-ignore-revs` |
| `-Wno-error=...` to ship faster | Tech debt that never returns | Fix the warning or `// NOLINT` with reason |
| Skipping warnings when adopting a third-party header | Future you will pay | Wrap with `#pragma GCC diagnostic push/ignored/pop` |
| Tidying generated code | Fights the generator | Exclude with `HeaderFilterRegex` or path globs |
Related in Cloud & DevOps
appbuilder-action-scaffolder
IncludedCreate, implement, deploy, and debug Adobe Runtime actions with consistent layout, validation, and error handling. Use this skill whenever the user needs to add actions to an App Builder project, understand action structure (params, response format, web/raw actions), configure actions in the manifest, use App Builder SDKs (State, Files, Events, database), deploy and invoke actions via CLI, debug action issues, or implement patterns such as webhook receivers, custom event providers, journaling consumers, large payload redirects, action sequence pipelines, and Asset Compute workers. Also trigger when users mention serverless functions in Adobe context, action logging, IMS authentication for actions, or cron-style scheduled actions.
orchestrating-datacloud
IncludedSalesforce Data Cloud product orchestrator for connect→prepare→harmonize→segment→act workflows. Use this skill when the user needs a multi-step Data Cloud pipeline, cross-phase troubleshooting, or data space and data kit management. TRIGGER when: user needs a multi-step Data Cloud pipeline, asks to set up or troubleshoot Data Cloud across phases, manages data spaces or data kits, or wants a cross-phase sf data360 workflow. DO NOT TRIGGER when: work is isolated to a single phase (use the matching phase-specific skill), the task is STDM/session tracing/parquet telemetry (use observing-agentforce), standard CRM SOQL (use querying-soql), or Apex implementation (use generating-apex).
github-project-automation
IncludedAutomate GitHub repository setup with CI/CD workflows, issue templates, Dependabot, and CodeQL security scanning. Includes 12 production-tested workflows and prevents 18 errors: YAML syntax, action pinning, and configuration. Use when: setting up GitHub Actions CI/CD, creating issue/PR templates, enabling Dependabot or CodeQL scanning, deploying to Cloudflare Workers, implementing matrix testing, or troubleshooting YAML indentation, action version pinning, secrets syntax, runner versions, or CodeQL configuration. Keywords: github actions, github workflow, ci/cd, issue templates, pull request templates, dependabot, codeql, security scanning, yaml syntax, github automation, repository setup, workflow templates, github actions matrix, secrets management, branch protection, codeowners, github projects, continuous integration, continuous deployment, workflow syntax error, action version pinning, runner version, github context, yaml indentation error
sf-datacloud
IncludedSalesforce Data Cloud product orchestrator for connect→prepare→harmonize→segment→act workflows. TRIGGER when: user needs a multi-step Data Cloud pipeline, asks to set up or troubleshoot Data Cloud across phases, manages data spaces or data kits, or wants a cross-phase `sf data360` workflow. DO NOT TRIGGER when: work is isolated to a single phase (use the matching sf-datacloud-* skill), the task is STDM/session tracing/parquet telemetry (use sf-ai-agentforce-observability), standard CRM SOQL (use sf-soql), or Apex implementation (use sf-apex).
fabric-cli
IncludedUse this skill for Fabric.so CLI workflows with the `fabric` terminal command: diagnose/install/login, search or browse a Fabric library, save notes/links/files, create folders, ask the Fabric AI assistant, manage tasks/workspaces, generate shell completion, check subscription usage, produce JSON output, and use Fabric as persistent agent memory. Do not use for Microsoft Fabric/Azure/Power BI `fab`, Daniel Miessler's Fabric framework, Python Fabric SSH, Fabric.js, or textile/fashion fabric.
lark
IncludedLark/Feishu CLI skills: lark-cli operations for docs, markdown, sheets, base, calendar, im, mail, task, okr, drive, wiki, slides, whiteboard, apps, approval, attendance, contact, vc, minutes, event. Use when the user needs to operate Lark/Feishu resources via lark-cli, send messages, manage documents, spreadsheets, calendars, tasks, OKRs, deploy web pages, or any Feishu/Lark workspace operations.