Strict Toolchain Audit

Check build and CI configuration for warning-as-error, strict typechecking, and language-specific compiler/linter floors

jmagly Updated

File contents

Strict Toolchain Audit

Inspect build and CI configuration for the strict-toolchain rule. This maps curl Practice 13 into a reusable AIWG security-engineering audit.

Checks

  • C/C++: compiler flags include -Wall, -Wextra, -Werror, -pedantic; recommended hardening flags are reported when absent.
  • Rust: cargo clippy -- -D warnings or equivalent CI gate.
  • Go: go vet ./... and staticcheck ./... fail CI.
  • Python: ruff check and mypy strictness are configured.
  • TypeScript: strict: true and noUncheckedIndexedAccess: true.

Gradual Adoption

Legacy projects may keep a baseline, but the audit must confirm that new warnings fail the build. A baseline without a ratchet is reported as a finding.

References

  • agentic/code/frameworks/security-engineering/rules/strict-toolchain.md
  • agentic/code/frameworks/security-engineering/skills/sanitizer-in-ci/SKILL.md

jmagly/ai-writing-guide/tree/main/agentic/code/plugins/security-engineering/skills/strict-toolchain-audit commit 14352b644a

Frequently asked questions

npx skillmds@latest add jmagly-ai-writing-guide/strict-toolchain-audit