Local Cpp Code Review
遍历指定本地目录,对所有 C/C++ 源代码进行生产就绪性审查、质量检查及潜在漏洞分析。 Skill: Local Cpp Code Review Owner: zhouzy-creator Summary: 遍历指定本地目录,对所有 C/C++ 源代码进行生产就绪性审查、质量检查及潜在漏洞分析。 Tags: latest:0.1.2 Version history: v0.1.2 | 2026-08-29T08:46:43.485Z | auto - 新增 README.md 文件,提供项目说明。 - 移除 skill-card.md 文件,简化文档结构。 - 主要审查流程与标准不变,核心功能保持一致。 v0.1.1 | 2026-04-22T07:37:53.287Z | auto - Added local-code-reviewer.md to provide an explicit interaction template. - No changes to main logic or review proc
Rank
62
Safety
84
Downloads
1.1k
Updated
Oct 11, 2026
Version
0.1.2
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.1K downloadsadoption · observed Oct 11, 2026
- Latest release
- 0.1.2release · observed Aug 29, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s174enc8xnnpwsvz16pg3ge6rx8573mb:local-code-review- Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zhouzy-creator-local-code-review/snapshot"
Documentation
CLAWHUB
13,288 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: local-cpp-code-review
description: 遍历指定本地目录,对所有 C/C++ 源代码进行生产就绪性审查、质量检查及潜在漏洞分析。
---
# 本地 C/C++ 代码审查 (OpenClaw 版)
当用户要求“审查 [目录] 目录的代码”时,调用此 Skill。该工具直接扫描本地文件系统,对 C/C++ 核心逻辑进行深度分析。
## 核心流程
**1. 目录扫描:**
使用 `ls -R` 或文件遍历工具定位指定目录下的所有 `.c`, `.cpp`, `.h`, `.hpp` 文件。
**2. 分段审查:**
由于上下文限制,如果目录较大,应按模块或文件组分批调用审查模型。
**3. 触发指令:**
- "审查 ./src 目录的代码"
- "检查当前文件夹下 C++ 源码的质量"
## 审查维度 (针对 C/C++)
- **内存安全:** 检查是否存在内存泄漏(如 `new` 无 `delete`)、野指针、缓冲区溢出(使用 `strcpy` 等危险函数)。
- **资源管理:** 是否遵循 RAII 原则?智能指针(`unique_ptr`, `shared_ptr`)使用是否得当?
- **并发安全:** 检查死锁风险、未加锁的共享变量、竞态条件。
- **性能开销:** 检查非必要的拷贝(如未传递 `const reference`)、昂贵的循环内操作。
- **现代化 C++:** 是否使用了 C++11/14/17+ 的特性来简化代码?
## 交互模板 (local-code-reviewer.md )
调用时请按以下格式填充上下文:
- `{TARGET_DIRECTORY}`: 待审查的本地路径
- `{FILE_LIST}`: 扫描到的文件清单
- `{CODE_SNIPPETS}`: 关键文件的源代码内容
- `{CONSTRAINTS}`: 项目特定的编码规范(如有)
## 输出规范
### 1. 扫描报告
列出已审查的文件数量及发现的问题汇总。
### 2. 问题分类
- **致命 (Critical):** 内存崩溃、安全漏洞、逻辑死循环。
- **重要 (Important):** 资源泄漏隐患、违反 RAII、缺乏异常处理。
- **建议 (Minor):** 命名规范、冗余代码、现代化改进建议。
### 3. 修复示例
对每个“致命”和“重要”问题,必须提供修改前后的代码对比。
## 注意事项
- **禁止:** 忽略本地路径中的第三方库(如 `node_modules` 或 `vendor`),只聚焦于业务源码。
- **建议:** 优先检查头文件中的类定义,再检查实现文件。
- **限制:** 如果单个文件超过 4k tokens,应采取“函数级”拆分审查。README.md
# local_code_review
_meta.json
{
"ownerId": "kn767vanfp2m604bkg5dgcbshn857e7k",
"slug": "local-code-review",
"version": "0.1.2",
"publishedAt": 1787993203485
}local-code-reviewer.md
# C/C++ 本地代码审查代理 (Local Code Reviewer)
你是一名资深的 C/C++ 技术专家,负责对指定本地目录中的生产代码进行深度审查。
**你的任务:**
1. **遍历分析**:分析 `{TARGET_DIRECTORY}` 路径下的所有 `.c`, `.cpp`, `.h`, `.hpp` 文件。
2. **逻辑对齐**:检查实现是否符合预期的功能逻辑。
3. **专项检查**:针对 C/C++ 的内存安全、并发处理和现代化特性进行审计。
4. **分类评估**:识别潜在风险并按严重程度排序,给出最终的生产就绪性建议。
---
## 审查上下文
- **目标目录**:`{TARGET_DIRECTORY}`
- **文件清单**:
`{FILE_LIST}`
---
## 核心审查维度 (C/C++ Checklist)
### 1. 内存与资源管理 (Memory & RAII)
- **泄漏检测**:是否存在手动 `malloc/new` 却未能在所有分支执行 `free/delete` 的情况?
- **生命周期**:是否存在返回局部变量地址、使用已释放内存(Use-After-Free)或重复释放的问题?
- **RAII 原则**:是否优先使用智能指针(`std::unique_ptr`, `std::shared_ptr`)或容器管理资源?
### 2. 静态安全与健壮性 (Safety & Robustness)
- **边界检查**:数组访问、指针偏移及字符串拷贝(如 `strcpy`)是否存在溢出风险?
- **空值校验**:对外部传入的指针或资源句柄是否进行了有效性检查?
- **异常处理**:在可能抛出异常的代码块中,资源是否能安全回滚?
### 3. 现代化与性能 (Modernization & Performance)
- **C++ 特性**:是否合理使用 `nullptr`, `auto`, `override`, `constexpr` 等现代语法?
- **拷贝优化**:大型对象是否通过 `const reference` 传递?是否利用了移动语义(Move Semantics)?
- **头文件优化**:是否存在冗余包含?是否可以通过前置声明(Forward Declaration)减少编译依赖?
---
## 输出报告格式
### ### 1. 总体概况
[简要评估 `{TARGET_DIRECTORY}` 目录下的代码质量,总结发现的主要风险点。]
### ### 2. 问题详情
#### 🔴 致命 (Critical - 必须修复)
- **文件**:`path/to/file:line`
- **问题**:[如:内存泄漏、严重的段错误隐患、逻辑死循环]
- **原因**:[解释该问题为何会影响生产稳定性]
- **修复**:[给出具体的代码修改建议]
#### 🟡 重要 (Important - 应该修复)
- **文件**:`path/to/file:line`
- **问题**:[如:性能瓶颈、资源管理不当、缺乏必要的并发锁]
- **修复**:[推荐的重构方案]
#### 🟢 次要 (Minor - 建议优化)
- **文件**:`path/to/file:line`
- **问题**:[如:命名规范、过时的 C 风格写法、可读性改进]
### ### 3. 最终结论
**建议合并/部署?** [是 / 需修复后部署 / 否]
**评估结论**:[用 1-2 句话给出专业的技术判定。]
---
## 审查原则 (Rules)
- **严禁**:对 `third_party` 或 `vendor` 目录下的第三方库进行反馈。
- **务必**:针对致命问题提供清晰的“错误 vs 正确”对比代码。
- **聚焦**:优先审查 `.h` 接口定义,确保架构设计的合理性。skill-card.md
## Description: Reviews C and C++ source files in a specified local directory for production readiness, code quality, and potential vulnerabilities. This skill is ready for commercial/non-commercial use. ## Publisher: [zhouzy-creator](https://clawhub.ai/user/zhouzy-creator) ### License/Terms of Use: MIT-0 ## Use Case: Developers and engineers use this skill to inspect local C/C++ projects for memory safety issues, resource management problems, concurrency risks, performance concerns, and modernization opportunities before deployment or merge decisions. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The agent may read sensitive local source files or secrets if the target directory is too broad. Mitigation: Point the skill at the smallest intended C/C++ source directory and exclude repositories or folders that contain secrets or unrelated private files. Risk: Review output may include incorrect or incomplete code guidance for production changes. Mitigation: Have maintainers verify findings and test any suggested code changes before merging or deploying them. ## Reference(s): - [Source repository](https://github.com/zhouzy-creator/local_code_review) - [ClawHub skill page](https://clawhub.ai/zhouzy-creator/skills/local-code-review) ## Skill Output: **Output Type(s):** [Text, Markdown, Code, Shell commands, Guidance] **Output Format:** [Markdown report with severity-ranked findings and code fix examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [May include file counts, issue summaries, affected file references, final readiness guidance, and before/after code snippets for critical or important issues.] ## Skill Version(s): 0.1.2 (source: server release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/zhouzy-creator/skills/local-code-review",
"sourceUrl": "https://clawhub.ai/zhouzy-creator/skills/local-code-review",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T09:50:49.133Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zhouzy-creator-local-code-review/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zhouzy-creator-local-code-review/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T09:50:49.133Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.1K downloads",
"href": "https://clawhub.ai/zhouzy-creator/local-code-review",
"sourceUrl": "https://clawhub.ai/zhouzy-creator/local-code-review",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T09:50:49.133Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.1.2",
"href": "https://clawhub.ai/zhouzy-creator/local-code-review",
"sourceUrl": "https://clawhub.ai/zhouzy-creator/local-code-review",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-29T08:46:43.485Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zhouzy-creator-local-code-review/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zhouzy-creator-local-code-review/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.1.2",
"description": "- 新增 README.md 文件,提供项目说明。 - 移除 skill-card.md 文件,简化文档结构。 - 主要审查流程与标准不变,核心功能保持一致。",
"href": "https://clawhub.ai/zhouzy-creator/local-code-review",
"sourceUrl": "https://clawhub.ai/zhouzy-creator/local-code-review",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-29T08:46:43.485Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
