Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Guides performance optimization, profiling techniques, and bottleneck identification.
$ npx skills add CloudAI-X/opencode-workflow --skill optimizing-performance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install CloudAI-X/opencode-workflow optimizing-performance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/CloudAI-X/opencode-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/optimizing-performance .claude/skills/optimizing-performance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "optimizing-performance" agent skill from https://github.com/CloudAI-X/opencode-workflow/tree/main/skills/optimizing-performance into .claude/skills/optimizing-performance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "optimizing-performance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/CloudAI-X/opencode-workflow/tree/main/skills/optimizing-performanceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add CloudAI-X/opencode-workflow --skill optimizing-performance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install CloudAI-X/opencode-workflow optimizing-performance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/CloudAI-X/opencode-workflow.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/optimizing-performance .agents/skills/optimizing-performance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "optimizing-performance" agent skill from https://github.com/CloudAI-X/opencode-workflow/tree/main/skills/optimizing-performance into .agents/skills/optimizing-performance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "optimizing-performance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add CloudAI-X/opencode-workflow --skill optimizing-performance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install CloudAI-X/opencode-workflow optimizing-performance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/CloudAI-X/opencode-workflow.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/optimizing-performance .cursor/skills/optimizing-performance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "optimizing-performance" agent skill from https://github.com/CloudAI-X/opencode-workflow/tree/main/skills/optimizing-performance into .cursor/skills/optimizing-performance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "optimizing-performance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/CloudAI-X/opencode-workflow.git --path skills/optimizing-performance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add CloudAI-X/opencode-workflow --skill optimizing-performance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install CloudAI-X/opencode-workflow optimizing-performance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/CloudAI-X/opencode-workflow.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/optimizing-performance .gemini/skills/optimizing-performance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "optimizing-performance" agent skill from https://github.com/CloudAI-X/opencode-workflow/tree/main/skills/optimizing-performance into .gemini/skills/optimizing-performance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "optimizing-performance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install CloudAI-X/opencode-workflow optimizing-performanceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add CloudAI-X/opencode-workflow --skill optimizing-performance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/CloudAI-X/opencode-workflow.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/optimizing-performance .github/skills/optimizing-performance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "optimizing-performance" agent skill from https://github.com/CloudAI-X/opencode-workflow/tree/main/skills/optimizing-performance into .github/skills/optimizing-performance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "optimizing-performance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add CloudAI-X/opencode-workflow --skill optimizing-performance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install CloudAI-X/opencode-workflow optimizing-performance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/CloudAI-X/opencode-workflow.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/optimizing-performance .opencode/skills/optimizing-performance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "optimizing-performance" agent skill from https://github.com/CloudAI-X/opencode-workflow/tree/main/skills/optimizing-performance into .opencode/skills/optimizing-performance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "optimizing-performance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
optimizing-performanceGuides performance optimization, profiling techniques, and bottleneck identification.
Optimizing Performance is an agent skill from CloudAI-X/opencode-workflow. Guides performance optimization, profiling techniques, and bottleneck identification. Use when improving application speed, reducing resource usage, or diagnosing performance issues.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: opencode
It sits in Development, covering Performance optimization. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 0128ca6. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxnodegopythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
opencode
From compatibility in the SKILL.md frontmatter.
Optimizing Performance loads about 2.6k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 515 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from CloudAI-X/opencode-workflow at commit 0128ca6, republished under its MIT licence (© CloudAI-X). 515 words, ~2,565 tokens.
.claude/skills/optimizing-performance/SKILL.md (or your agent's skills folder).Strategies for identifying, analyzing, and resolving performance bottlenecks.
80% of performance problems come from 20% of the code.
Focus on:
├── Hot paths (frequently executed code)
├── I/O operations (database, network, disk)
├── Memory allocation patterns
└── Algorithm complexity| Type | What It Measures | Tools |
|---|---|---|
| CPU Profiling | Time spent in functions | pprof, py-spy, Chrome DevTools |
| Memory Profiling | Allocation patterns, leaks | Valgrind, memory_profiler, Chrome |
| I/O Profiling | Disk/network operations | strace, perf, Wireshark |
| Database Profiling | Query performance | EXPLAIN, slow query log, APM |
1. Establish baseline
└─ Measure current performance with realistic load
2. Identify hotspots
└─ Profile to find where time/resources are spent
3. Form hypothesis
└─ Why is this slow? What would make it faster?
4. Implement fix
└─ Make ONE change at a time
5. Measure again
└─ Did it help? By how much?
6. Repeat
└─ Until performance goals are met# Node.js
node --prof app.js
node --prof-process isolate-*.log > profile.txt
# Python
python -m cProfile -s cumtime app.py
py-spy record -o profile.svg -- python app.py
# Go
go test -cpuprofile cpu.prof -memprofile mem.prof -bench .
go tool pprof cpu.prof
# Database (PostgreSQL)
EXPLAIN ANALYZE SELECT * FROM users WHERE email = 'test@example.com';BAD (N+1 queries):
SELECT * FROM posts; -- 1 query
SELECT * FROM users WHERE id=1; -- N queries
SELECT * FROM users WHERE id=2;
...
GOOD (2 queries):
SELECT * FROM posts;
SELECT * FROM users WHERE id IN (1, 2, 3, ...);Detection: High query count relative to data returned Fix: Eager loading, batch fetching, JOINs
BAD:
SELECT * FROM logs; -- Returns millions of rows
GOOD:
SELECT * FROM logs
WHERE created_at > NOW() - INTERVAL '1 day'
LIMIT 100;Detection: Memory spikes, timeouts Fix: Pagination, limits, streaming
BAD (blocking):
result1 = fetch_api_1() -- Wait 200ms
result2 = fetch_api_2() -- Wait 200ms
return combine(result1, result2) -- Total: 400ms
GOOD (parallel):
[result1, result2] = await Promise.all([
fetch_api_1(),
fetch_api_2()
]) -- Total: ~200msDetection: Sequential I/O in traces Fix: Parallel execution, async/await
BAD (allocates in loop):
for item in large_list:
result = [] # Allocates each iteration
result.append(transform(item))
GOOD (pre-allocate):
result = []
for item in large_list:
result.append(transform(item))
BEST (generator):
def transform_all(items):
for item in items:
yield transform(item)Detection: GC pressure, memory profiling Fix: Object pooling, pre-allocation, generators
| Technique | When to Use | Impact |
|---|---|---|
| Indexing | Slow WHERE/JOIN queries | High |
| Query optimization | Complex queries | High |
| Connection pooling | Many short connections | Medium |
| Read replicas | Read-heavy workloads | High |
| Caching | Repeated queries | Very High |
| Denormalization | Complex JOINs | Medium |
-- Create index for frequently queried columns
CREATE INDEX idx_users_email ON users(email);
-- Composite index for multiple column queries
CREATE INDEX idx_orders_user_date ON orders(user_id, created_at);
-- Check if index is used
EXPLAIN ANALYZE SELECT * FROM users WHERE email = 'test@example.com';| Strategy | Use Case | Invalidation |
|---|---|---|
| Cache-aside | General purpose | Manual or TTL |
| Write-through | Strong consistency | On write |
| Write-behind | Write-heavy | Async batched |
| Read-through | Read-heavy | On miss |
Cache-aside pattern:
1. Check cache
2. If miss, query database
3. Store in cache
4. Return result| Technique | When to Use |
|---|---|
| Object pooling | Frequent allocation of same type |
| Lazy loading | Large objects not always needed |
| Streaming | Processing large datasets |
| Weak references | Cache that can be evicted |
| Data structure choice | Right structure for access pattern |
| Metric | Target | What It Measures |
|---|---|---|
| LCP (Largest Contentful Paint) | < 2.5s | Load performance |
| INP (Interaction to Next Paint) | < 200ms | Interactivity |
| CLS (Cumulative Layout Shift) | < 0.1 | Visual stability |
Loading Performance:
☐ Code splitting (lazy load routes/components)
☐ Tree shaking (remove unused code)
☐ Minification (JS, CSS)
☐ Compression (gzip, brotli)
☐ Image optimization (WebP, srcset, lazy loading)
☐ CDN for static assets
Runtime Performance:
☐ Virtualized lists for large data
☐ Debounce/throttle event handlers
☐ Memoization of expensive computations
☐ Avoid layout thrashing (batch DOM reads/writes)
☐ Use CSS transforms for animations
☐ Web Workers for heavy computation# Analyze bundle size
npx webpack-bundle-analyzer stats.json
npx source-map-explorer bundle.js
# Identify large dependencies
npx depcheck| Percentile | Target | User Experience |
|---|---|---|
| p50 | < 100ms | Fast |
| p95 | < 500ms | Acceptable |
| p99 | < 1s | Tolerable |
| Technique | Benefit |
|---|---|
| Response compression | Reduce transfer size |
| Pagination | Limit response size |
| Field selection | Return only needed data |
| ETags/Caching headers | Reduce redundant requests |
| Connection keep-alive | Reduce handshake overhead |
| HTTP/2 | Multiplexing, header compression |
BAD (multiple requests):
GET /users/1
GET /users/2
GET /users/3
GOOD (batch):
POST /users/batch
{ "ids": [1, 2, 3] }| Category | Metrics |
|---|---|
| Latency | p50, p95, p99 response times |
| Throughput | Requests per second |
| Errors | Error rate, error types |
| Saturation | CPU, memory, connections |
Critical (page immediately):
- Error rate > 5%
- p99 latency > 5s
- Service down
Warning (notify during hours):
- Error rate > 1%
- p95 latency > 2s
- Resource utilization > 80%# Log slow operations
import time
import logging
def timed_operation(func):
def wrapper(*args, **kwargs):
start = time.time()
result = func(*args, **kwargs)
duration = time.time() - start
if duration > 1.0: # Log if > 1 second
logging.warning(f"{func.__name__} took {duration:.2f}s")
return result
return wrapper| Tool | Use Case |
|---|---|
| k6 | Modern, scriptable load testing |
| JMeter | Complex scenarios, GUI |
| Locust | Python-based, distributed |
| Artillery | YAML config, easy to start |
| wrk | Simple HTTP benchmarking |
import http from 'k6/http';
import { check, sleep } from 'k6';
export const options = {
stages: [
{ duration: '1m', target: 50 }, // Ramp up
{ duration: '5m', target: 50 }, // Stay at 50 users
{ duration: '1m', target: 0 }, // Ramp down
],
thresholds: {
http_req_duration: ['p(95)<500'], // 95% under 500ms
http_req_failed: ['rate<0.01'], // Error rate < 1%
},
};
export default function () {
const res = http.get('https://api.example.com/users');
check(res, { 'status is 200': (r) => r.status === 200 });
sleep(1);
}PROFILING FLOW:
Measure → Identify → Hypothesize → Fix → Measure → Repeat
COMMON BOTTLENECKS:
N+1 queries → Eager loading
Unbounded data → Pagination
Blocking I/O → Parallelization
Excessive allocation → Object pooling
DATABASE:
Index frequently queried columns
Use EXPLAIN ANALYZE
Add caching layer
CACHING:
Cache-aside for general use
TTL for time-based invalidation
Invalidate on write for consistency
TARGETS:
p50 < 100ms
p95 < 500ms
p99 < 1s
TOOLS:
CPU: pprof, py-spy
Memory: valgrind, memory_profiler
Load: k6, locust
DB: EXPLAIN, slow query log© CloudAI-X, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/optimizing-performance of CloudAI-X/opencode-workflow.
Open the folder on GitHubat commit 0128ca6
Optimizing Performance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Optimizing Performance this skillCloudAI-X/opencode-workflow | 275 | — | ~2.6k | Automated safety check: Pass | MIT | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| LLM Torch Profiler Analysissgl-project/sglang | 37k | 2 repos | ~6.4k | Automated safety check: Pass | Apache-2.0 | |
| Pycrazyguitar/pysheeet | 8.2k | — | ~886 | Automated safety check: Pass | MIT | |
| Cmux Debugging Guidemanaflow-ai/cmux | 28k | 1 repos | ~1.1k | Automated safety check: Pass | Custom licence | |
| Electron Heap Snapshot Analysiskeybase/client | 9.3k | — | ~875 | Automated safety check: Pass | BSD-3-Clause |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
sgl-project/sglang
Unified LLM torch-profiler triage skill for sglang, vllm, TensorRT-LLM, and TokenSpeed.
crazyguitar/pysheeet
Comprehensive Python programming reference covering syntax, concurrency, networking, databases, ML/LLM development, and HPC.
manaflow-ai/cmux
Covers debug logging, the Debug menu, profiling rules and runtime pitfalls for working on the cmux macOS terminal app.
keybase/client
Analyzes V8, Chrome and Electron .heapsnapshot files with Node scripts to find memory leaks, detached DOM nodes and the retainer paths that keep objects alive.
ben-manes/caffeine
Runs controlled JMH experiments on the Caffeine cache to find shared contention and hot-path waste, then reviews correctness and returns a reviewable patch.
CloudAI-X/opencode-workflow
Guides systematic project analysis, codebase exploration, and architecture pattern recognition.
CloudAI-X/opencode-workflow
Guides REST and GraphQL API design, endpoint patterns, request/response schemas, versioning, and API best practices.
CloudAI-X/opencode-workflow
Guides software architecture decisions, design patterns, and system design principles.
CloudAI-X/opencode-workflow
Guides test strategy, TDD/BDD approaches, test coverage planning, and testing best practices.
CloudAI-X/opencode-workflow
Guides git workflows, branching strategies, commit conventions, and version control best practices.
CloudAI-X/opencode-workflow
CRITICAL skill for executing multiple Task tool calls in a SINGLE message for true parallelism.
Categories
Guides performance optimization, profiling techniques, and bottleneck identification. Optimizing Performance is an agent skill from CloudAI-X/opencode-workflow. Guides performance optimization, profiling techniques, and bottleneck identification.
Optimizing Performance fits situations like: improving application speed; reducing resource usage; diagnosing performance issues.
Run `npx skills add CloudAI-X/opencode-workflow --skill optimizing-performance -a claude-code`. Or copy the skill folder (skills/optimizing-performance in CloudAI-X/opencode-workflow) into .claude/skills/optimizing-performance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add CloudAI-X/opencode-workflow --skill optimizing-performance -a codex`. Or copy the skill folder (skills/optimizing-performance in CloudAI-X/opencode-workflow) into .agents/skills/optimizing-performance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CloudAI-X/opencode-workflow --skill optimizing-performance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/optimizing-performance, .gemini/skills/optimizing-performance, .github/skills/optimizing-performance and .opencode/skills/optimizing-performance in your project.
Going by SKILL.md and its folder, Optimizing Performance needs the command-line tools its instructions call (npx, node, go and python). Our summary lists: Python 3; Node.js. Compatibility (from SKILL.md): opencode.
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Optimizing Performance is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Optimizing Performance: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), LLM Torch Profiler Analysis (sgl-project/sglang, 37k stars), Py (crazyguitar/pysheeet, 8.2k stars) and Cmux Debugging Guide (manaflow-ai/cmux, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
CloudAI-X (a GitHub user) maintains it in CloudAI-X/opencode-workflow, which has 275 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on January 10, 2026.
Source: CloudAI-X/opencode-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.