A couple comparison points I noticed while briefly investigating shark:
C code is passed to clang+llc as external calls, whereas in BCC clang+llvm are statically linked in.
Both support native (lua/python) bindings to the eBPF maps.
In shark, I don't see that it is easy to dereference kprobe'd function arguments, as it is in `bpf_trace_printk("1 W %s %d %d ?\\n", req->rq_disk->disk_name, ...)` of <bcc>/tools/biosnoop.
This should also answer your last question, which was where is "%s" used. tools/opensnoop also uses string printks.
Comparison points aside, I intentionally made sure that the clang legwork that is being done in BCC is wrapped with a C api, so any language bindings besides python should be trivial to implement. It would be ideal (in my mind) if shark could leverage libbcc and make both tools better in the process.