Skip to content
Back to skills

C

ASecurity

Write safe C avoiding memory corruption, buffer overflows, and undefined behavior traps.

  • 17 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 6, 2026
documentationc++

Works with

  • mcp

Security analysis

A100/100

Pro scans all 8 files and shows the line behind each finding

Scanned September 6, 2026

npx -y skills add clawic/skills --skill c --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of C?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for C
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/clawic-skills/badge)](https://www.skillsdirectory.com/skills/clawic-skills)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: C
slug: c
version: 1.0.1
description: Write safe C avoiding memory corruption, buffer overflows, and undefined behavior traps.
homepage: https://clawic.com/skills/c
metadata:
  clawdbot:
    emoji: ⚙️
    requires:
      bins:
      - gcc
      - clang
    os:
    - linux
    - darwin
    - win32
    displayName: C
---

## Quick Reference

| Topic | File |
|-------|------|
| malloc/free, leaks, double free | `memory.md` |
| Null, dangling, pointer arithmetic | `pointers.md` |
| Null terminator, buffer overflow | `strings.md` |
| Integer overflow, signed/unsigned | `types.md` |
| Macro traps, include guards | `preprocessor.md` |
| Common undefined behavior | `undefined.md` |

## Critical Rules

- `malloc` returns `void*` — cast required in C++, optional in C but check for NULL
- `free(ptr); ptr = NULL;` — always null after free to prevent double-free
- `sizeof(array)` in function gives pointer size, not array size — pass length separately
- `char str[5] = "hello";` — no room for null terminator, UB when used as string
- `strcpy` doesn't check bounds — use `strncpy` and manually null-terminate
- Signed overflow is UB — compiler can optimize assuming it never happens
- `i++ + i++` is UB — no sequence point between modifications
- Returning pointer to local variable — dangling pointer, UB on use
- `#define SQUARE(x) x*x` — `SQUARE(1+2)` = `1+2*1+2` = 5, not 9
- `memcpy` with overlapping regions — use `memmove` instead
- Uninitialized variables — contain garbage, UB if used
- Array out of bounds — no runtime check, silent corruption or crash

Files in this skill

  • SKILL.md1.6 KB
  • _meta.json230 B
  • memory.md670 B
  • pointers.md522 B
  • preprocessor.md509 B
  • strings.md552 B
  • types.md556 B
  • undefined.md663 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…