modern-cpp
Acerca de
Esta habilidad guía el desarrollo en C++ hacia prácticas modernas y seguras de C++20/23/26, reemplazando patrones heredados como punteros crudos y códigos de error con punteros inteligentes y `std::expected`. Es ideal para escribir código nuevo, modernizar sistemas existentes o trabajar en proyectos críticos para la seguridad. Úsala cuando necesites adoptar prácticas contemporáneas de C++ que reduzcan vulnerabilidades y código repetitivo.
Instalación rápida
Claude Code
Recomendadonpx skills add trailofbits/skills -a claude-code/plugin add https://github.com/trailofbits/skillsgit clone https://github.com/trailofbits/skills.git ~/.claude/skills/modern-cppCopia y pega este comando en Claude Code para instalar esta habilidad
Documentación
Modern C++
Guide for writing modern C++ using C++20, C++23, and C++26 idioms. Focuses on patterns that eliminate vulnerability classes and reduce boilerplate, with a security emphasis from Trail of Bits.
When to Use This Skill
- Writing new C++ functions, classes, or libraries
- Modernizing existing C++ code (pre-C++20 patterns)
- Choosing between legacy and modern approaches
- Working on security-critical or safety-sensitive C++
- Reviewing C++ code for modern idiom adoption
When NOT to Use This Skill
- User explicitly requires older standard: Respect constraints (embedded, legacy ABI)
- Pure C code: This skill is C++-specific
- Build system questions: CMake, Meson, Bazel configuration is out of scope
- Non-C++ projects: Mixed codebases where C++ isn't primary
Anti-Patterns to Avoid
| Avoid | Use Instead | Why |
|---|---|---|
new/delete | std::make_unique, std::make_shared | Eliminates leaks, double-free |
| Raw owning pointers | std::unique_ptr, std::shared_ptr | RAII ownership semantics |
C arrays (int arr[N]) | std::array<int, N> | Bounds-aware, value semantics |
| Pointer + length params | std::span<T> | Non-owning, bounds-checkable |
printf / sprintf | std::format, std::print | Type-safe, no buffer overflow |
C-style casts (int)x | static_cast<int>(x) | Explicit intent, auditable |
#define constants | constexpr variables | Scoped, typed, debuggable |
SFINAE / enable_if | Concepts + requires | Readable constraints and errors |
| Error codes + out params | std::expected<T, E> | Composable, type-safe errors |
union | std::variant | Type-safe, no silent UB |
Raw mutex.lock()/unlock() | std::scoped_lock | Exception-safe, no deadlocks |
std::thread | std::jthread | Auto-join, stop token support |
assert() macro | contract_assert (C++26) | Visible to tooling, configurable |
| Manual CRTP | Deducing this (C++23) | Simpler, no template boilerplate |
| Macro code generation | Reflection (C++26) | Zero-overhead, composable |
See anti-patterns.md for the full table (30+ patterns).
Decision Tree
What are you doing?
|
+-- Writing new C++ code?
| +-- Use modern idioms by default (C++20/23)
| +-- Choose the newest standard your compiler supports
| +-- See Feature Tiers below
|
+-- Modernizing existing code?
| +-- Start with Tier 1 (C++20/23) replacements
| +-- Prioritize by security impact (memory > types > style)
| +-- See anti-patterns.md for the migration table
|
+-- Security-critical code?
| +-- Enable compiler hardening flags (see below)
| +-- Enable hardened libc++ mode
| +-- Run sanitizers in CI
| +-- See safe-idioms.md and compiler-hardening.md
|
+-- Using C++26 features?
+-- Reflection: YES, plan for it (GCC 16+)
+-- Contracts: cautiously, for new API boundaries
+-- std::execution: wait for ecosystem maturity
+-- See cpp26-features.md
Feature Tiers
Features are ranked by practical usability today, not by standard version.
Tier 1: Use Today (C++20/23, solid compiler support)
| Feature | Replaces | Standard |
|---|---|---|
Concepts + requires | SFINAE, enable_if | C++20 |
| Ranges + views | Raw iterator loops | C++20 |
std::span<T> | Pointer + length | C++20 |
std::format | sprintf, iostream chains | C++20 |
Three-way comparison <=> | Manual comparison operators | C++20 |
std::jthread | std::thread + manual join | C++20 |
| Designated initializers | Positional struct init | C++20 |
std::expected<T,E> | Error codes, exceptions at boundaries | C++23 |
std::print / std::println | printf, std::cout << | C++23 |
Deducing this | CRTP, const/non-const duplication | C++23 |
std::flat_map | std::map for read-heavy use | C++23 |
Monadic std::optional | Nested if-checks on optionals | C++23 |
See cpp20-features.md and cpp23-features.md.
Tier 2: Deploy Now (no standard bump needed)
These improve safety without changing your C++ standard version:
- Compiler hardening flags —
-D_FORTIFY_SOURCE=3,-fstack-protector-strong,-ftrivial-auto-var-init=zero - Hardened libc++ —
-D_LIBCPP_HARDENING_MODE=_LIBCPP_HARDENING_MODE_FASTfor ~0.3% overhead bounds-checking - Sanitizers in CI — ASan + UBSan as minimum; TSan for concurrent code
- Warning flags —
-Wall -Wextra -Wpedantic -Werror
Tier 3: Plan For (C++26, worth restructuring around)
Reflection is the single most transformative C++26 feature. It eliminates:
- Serialization boilerplate (one generic function replaces per-struct
to_json) - Code generators (protobuf codegen, Qt MOC)
- Macro-based registration and enum-to-string hacks
GCC 16 (April 2026) has reflection merged. Plan new code to benefit from it.
Tier 4: Watch (C++26, needs maturation)
- Contracts (
pre/post/contract_assert) — Better thanassert(), but no virtual function support and limited compiler support. Adopt cautiously for new API boundaries. - std::execution (senders/receivers) — Powerful async framework, but steep learning curve, no scheduler ships with it, and poor documentation. Wait for ecosystem maturity.
See cpp26-features.md.
Compiler Hardening Quick Reference
Essential Flags (GCC + Clang)
-Wall -Wextra -Wpedantic -Werror
-D_FORTIFY_SOURCE=3
-fstack-protector-strong
-fstack-clash-protection
-ftrivial-auto-var-init=zero
-fPIE -pie
-Wl,-z,relro,-z,now
Clang-Specific
-Wunsafe-buffer-usage
Hardened libc++ (Clang/libc++ only)
-D_LIBCPP_HARDENING_MODE=_LIBCPP_HARDENING_MODE_FAST
Google deployed this across Chrome and their server fleet: ~0.3% overhead, 1000+ bugs found, 30% reduction in production segfaults.
See compiler-hardening.md for the full guide.
Rationalizations to Reject
| Rationalization | Why It's Wrong |
|---|---|
| "It compiles without warnings" | Warnings depend on which flags you enable. Add -Wall -Wextra -Wpedantic. |
| "ASan is too slow for production" | Use GWP-ASan for sampling-based production detection (~0% overhead). |
| "We only use safe containers" | Iterator invalidation and unchecked optional access are still exploitable. |
| "Smart pointers are slower" | std::unique_ptr has zero overhead vs raw pointers. Measure before claiming. |
| "Our code doesn't have memory bugs" | Google found 1000+ bugs when enabling hardened libc++. So did everyone else. |
| "C++26 features aren't available yet" | C++20/23 features are. Hardening flags work on any standard. Start there. |
| "Modern C++ is harder to read" | std::expected is more readable than checking error codes across 5 out-params. |
Best Practices Checklist
- Use smart pointers for ownership, raw pointers only for non-owning observation
- Prefer
std::spanover pointer + length for function parameters - Use
std::expectedfor functions that can fail with typed errors - Constrain templates with concepts, not SFINAE
- Enable compiler hardening flags and hardened libc++ in all builds
- Run ASan + UBSan in CI; add TSan for concurrent code
- Use
constexpr/constevalwhere possible (UB-free by design) - Mark functions
[[nodiscard]]when ignoring the return value is likely a bug - Prefer value semantics; use
std::variantoverunion,enum classoverenum - Initialize all variables at declaration
Read Next
- anti-patterns.md — Full legacy-to-modern migration table (30+ patterns)
- cpp20-features.md — Concepts, ranges, span, format, coroutines
- cpp23-features.md — expected, print, deducing this, flat_map
- cpp26-features.md — Reflection, contracts, memory safety improvements
- compiler-hardening.md — Flags, sanitizers, hardened libc++
- safe-idioms.md — Security patterns by vulnerability class
Repositorio GitHub
Preguntas frecuentes
¿Qué es el Skill modern-cpp?
modern-cpp es un Skill de Claude creado por trailofbits. Los Skills agrupan instrucciones y recursos que Claude carga cuando los necesita para realizar tareas relacionadas con modern-cpp sin indicaciones adicionales.
¿Cómo instalo modern-cpp?
Usa los comandos de instalación de esta página: añade modern-cpp a Claude Code como plugin o clona su repositorio en tu directorio de skills y reinicia Claude para cargarlo.
¿A qué categoría pertenece modern-cpp?
modern-cpp pertenece a la categoría Diseño.
¿Se puede usar modern-cpp gratis?
Sí. modern-cpp aparece en AIMCP y se puede instalar gratis.
Habilidades relacionadas
Utilice la habilidad executing-plans cuando tenga un plan de implementación completo para ejecutar en lotes controlados con puntos de revisión. Esta habilidad carga y revisa críticamente el plan, luego ejecuta tareas en pequeños lotes (por defecto 3 tareas) mientras reporta el progreso entre cada lote para la revisión del arquitecto. Esto asegura una implementación sistemática con puntos de control de calidad integrados.
Esta habilidad despacha un subagente revisor de código para analizar los cambios en el código frente a los requisitos antes de proceder. Debe usarse después de completar tareas, implementar funciones principales o antes de fusionar con la rama principal. La revisión ayuda a detectar problemas de forma temprana al comparar la implementación actual con el plan original.
Esta habilidad proporciona una guía integral para que los desarrolladores conecten servidores MCP a Claude Code mediante transportes HTTP, stdio o SSE. Cubre la instalación, configuración, autenticación y seguridad para integrar servicios externos como GitHub, Notion y APIs personalizadas. Úsala al configurar integraciones MCP, al configurar herramientas externas o al trabajar con el Protocolo de Contexto del Modelo de Claude.
Esta habilidad ayuda a los desarrolladores a elegir entre las interfaces web y CLI de Claude Code mediante el análisis de tareas, y luego permite la teletransportación fluida de sesiones entre estos entornos. Optimiza el flujo de trabajo gestionando el estado y el contexto de la sesión al cambiar entre web, CLI o móvil. Úsala para proyectos complejos que requieren diferentes herramientas en varias etapas.
