Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Audit code for memory leaks and disposable issues. An agent skill from diodeme/Gold-Band.
$ npx skills add diodeme/Gold-Band --skill memory-leak-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install diodeme/Gold-Band memory-leak-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/diodeme/Gold-Band.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/memory-leak-audit .claude/skills/memory-leak-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "memory-leak-audit" agent skill from https://github.com/diodeme/Gold-Band/tree/main/.agents/skills/memory-leak-audit into .claude/skills/memory-leak-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memory-leak-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/diodeme/Gold-Band/tree/main/.agents/skills/memory-leak-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add diodeme/Gold-Band --skill memory-leak-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install diodeme/Gold-Band memory-leak-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/diodeme/Gold-Band.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/memory-leak-audit .agents/skills/memory-leak-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "memory-leak-audit" agent skill from https://github.com/diodeme/Gold-Band/tree/main/.agents/skills/memory-leak-audit into .agents/skills/memory-leak-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memory-leak-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add diodeme/Gold-Band --skill memory-leak-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install diodeme/Gold-Band memory-leak-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/diodeme/Gold-Band.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/memory-leak-audit .cursor/skills/memory-leak-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "memory-leak-audit" agent skill from https://github.com/diodeme/Gold-Band/tree/main/.agents/skills/memory-leak-audit into .cursor/skills/memory-leak-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memory-leak-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/diodeme/Gold-Band.git --path .agents/skills/memory-leak-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add diodeme/Gold-Band --skill memory-leak-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install diodeme/Gold-Band memory-leak-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/diodeme/Gold-Band.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/memory-leak-audit .gemini/skills/memory-leak-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "memory-leak-audit" agent skill from https://github.com/diodeme/Gold-Band/tree/main/.agents/skills/memory-leak-audit into .gemini/skills/memory-leak-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memory-leak-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install diodeme/Gold-Band memory-leak-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add diodeme/Gold-Band --skill memory-leak-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/diodeme/Gold-Band.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/memory-leak-audit .github/skills/memory-leak-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "memory-leak-audit" agent skill from https://github.com/diodeme/Gold-Band/tree/main/.agents/skills/memory-leak-audit into .github/skills/memory-leak-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memory-leak-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add diodeme/Gold-Band --skill memory-leak-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install diodeme/Gold-Band memory-leak-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/diodeme/Gold-Band.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/memory-leak-audit .opencode/skills/memory-leak-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "memory-leak-audit" agent skill from https://github.com/diodeme/Gold-Band/tree/main/.agents/skills/memory-leak-audit into .opencode/skills/memory-leak-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "memory-leak-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
memory-leak-auditAudit code for memory leaks and disposable issues. An agent skill from diodeme/Gold-Band.
Memory Leak Audit is an agent skill from diodeme/Gold-Band. Audit code for memory leaks and disposable issues. Use when reviewing event listeners, DOM handlers, lifecycle callbacks, or fixing leak reports. Covers addDisposableListener, Event.once, MutableDisposable, DisposableStore, and onWillDispose patterns.
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Performance optimization. The repository describes itself as: Desktop app for harness engineering, loop engineering, graph engineering—and whatever comes next in local AI-agent workflows. The licence is AGPL-3.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 75622ac. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Memory Leak Audit loads about 1.3k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 365 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from diodeme/Gold-Band at commit 75622ac, republished under its AGPL-3.0 licence (© diodeme). 365 words, ~1,337 tokens.
.claude/skills/memory-leak-audit/SKILL.md (or your agent's skills folder).The #1 bug category in VS Code. This skill encodes the patterns that prevent and fix leaks.
Work through each check in order. A single missed pattern can cause thousands of leaked objects.
Rule: Never use raw .onload, .onclick, or addEventListener() directly. Always use addDisposableListener().
// BAD — leaks a listener every call
this.iconElement.onload = () => { ... };
// GOOD — tracked and disposable
this._register(addDisposableListener(this.iconElement, 'load', () => { ... }));Validated by: PR #280566 — Extension icon widget leaked 185 listeners after 37 toggles.
Rule: Use Event.once() for events that should only fire once (lifecycle events, close events, first-change events).
// BAD — listener stays registered forever after first fire
model.onDidDispose(() => store.dispose());
// GOOD — auto-removes after first invocation
Event.once(model.onDidDispose)(() => store.dispose());Validated by: PRs #285657, #285661 — Terminal lifecycle hacks replaced with Event.once().
Rule: Objects created in methods called multiple times must NOT be registered to the class this._register(). Use MutableDisposable or return IDisposable to the caller.
// BAD — every call adds another listener to the class store
startSearch() {
this._register(this.model.onResults(() => { ... }));
}
// GOOD — MutableDisposable ensures max 1 listener
private readonly _searchListener = this._register(new MutableDisposable());
startSearch() {
this._searchListener.value = this.model.onResults(() => { ... });
}When the event should only fire once per method call, combine Event.once() with MutableDisposable — this auto-removes the listener after the first invocation while still guarding against repeated calls:
private readonly _searchListener = this._register(new MutableDisposable());
startSearch() {
this._searchListener.value = Event.once(this.model.onResults)(() => { ... });
}Validated by: PR #283466 — Terminal find widget leaked 1 listener per search.
Rule: When creating a DisposableStore tied to a model's lifetime, register model.onWillDispose(() => store.dispose()) to the store itself.
const store = new DisposableStore();
store.add(model.onWillDispose(() => store.dispose()));
store.add(model.onDidChange(() => { ... }));Validated by: Pattern used in chatEditingSession.ts, fileBasedRecommendations.ts, testingContentProvider.ts.
Rule: When using factory methods that create pooled objects (lists, trees), disposables must be registered to the individual item, not the pool class.
// BAD — registers to pool, never cleaned per item
createItem() {
const item = new Item();
this._register(item.onEvent(() => { ... }));
return item;
}
// GOOD — wrap with item-scoped disposal
createItem(): IDisposable & Item {
const store = new DisposableStore();
const item = new Item();
store.add(item.onEvent(() => { ... }));
return { ...item, dispose: () => store.dispose() };
}Validated by: PR #290505 — Chat content parts CollapsibleListPool and TreePool leaked disposables.
Rule: Every test suite that creates disposable objects must call ensureNoDisposablesAreLeakedInTestSuite().
import { ensureNoDisposablesAreLeakedInTestSuite } from '../../../../base/test/common/utils.js';
suite('MyFeature', () => {
ensureNoDisposablesAreLeakedInTestSuite();
test('does something', () => {
// test disposables are tracked automatically
});
});| Scenario | Pattern | Anti-Pattern |
|---|---|---|
| DOM events | addDisposableListener() | .onclick =, addEventListener() |
| One-time events | Event.once(event)(handler) | event(handler) for lifecycle |
| Repeated methods | MutableDisposable or return IDisposable | this._register() in non-constructor |
| Model lifecycle | store.add(model.onWillDispose(...)) | Forgetting cleanup |
| Pooled objects | Item-scoped DisposableStore | Pool-scoped this._register() |
| Tests | ensureNoDisposablesAreLeakedInTestSuite() | No leak checking |
After fixing leaks, verify by:
ensureNoDisposablesAreLeakedInTestSuite() in tests© diodeme, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/memory-leak-audit of diodeme/Gold-Band.
Open the folder on GitHubat commit 75622ac
Memory Leak Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Memory Leak Audit this skilldiodeme/Gold-Band | 143 | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| LLM Torch Profiler Analysissgl-project/sglang | 37k | 2 repos | ~6.4k | Automated safety check: Pass | Apache-2.0 | |
| Pycrazyguitar/pysheeet | 8.2k | — | ~886 | Automated safety check: Pass | MIT | |
| Cmux Debugging Guidemanaflow-ai/cmux | 28k | 1 repos | ~1.1k | Automated safety check: Pass | Custom licence | |
| Electron Heap Snapshot Analysiskeybase/client | 9.3k | — | ~875 | Automated safety check: Pass | BSD-3-Clause |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
sgl-project/sglang
Unified LLM torch-profiler triage skill for sglang, vllm, TensorRT-LLM, and TokenSpeed.
crazyguitar/pysheeet
Comprehensive Python programming reference covering syntax, concurrency, networking, databases, ML/LLM development, and HPC.
manaflow-ai/cmux
Covers debug logging, the Debug menu, profiling rules and runtime pitfalls for working on the cmux macOS terminal app.
keybase/client
Analyzes V8, Chrome and Electron .heapsnapshot files with Node scripts to find memory leaks, detached DOM nodes and the retainer paths that keep objects alive.
ben-manes/caffeine
Runs controlled JMH experiments on the Caffeine cache to find shared contention and hot-path waste, then reviews correctness and returns a reviewable patch.
diodeme/Gold-Band
Master Rust async programming with Tokio, async traits, error handling, and concurrent patterns.
diodeme/Gold-Band
Rust profiling skill for performance analysis. An agent skill from diodeme/Gold-Band.
diodeme/Gold-Band
Diagnoses and resolves memory leaks in JavaScript/Node.js applications.
diodeme/Gold-Band
Create and localize user-facing release notes from an explicit Git change range.
diodeme/Gold-Band
Prepare, review, publish, or update a complete GitHub pull request for the current repository, including local commit readiness, safe push strategy, semantic title validation, repository-native PR…
diodeme/Gold-Band
Unified entry point for Stitch design work. An agent skill from diodeme/Gold-Band.
Categories
Audit code for memory leaks and disposable issues. An agent skill from diodeme/Gold-Band. Memory Leak Audit is an agent skill from diodeme/Gold-Band. Audit code for memory leaks and disposable issues.
Memory Leak Audit fits situations like: reviewing event listeners; lifecycle callbacks; fixing leak reports.
Run `npx skills add diodeme/Gold-Band --skill memory-leak-audit -a claude-code`. Or copy the skill folder (.agents/skills/memory-leak-audit in diodeme/Gold-Band) into .claude/skills/memory-leak-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add diodeme/Gold-Band --skill memory-leak-audit -a codex`. Or copy the skill folder (.agents/skills/memory-leak-audit in diodeme/Gold-Band) into .agents/skills/memory-leak-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add diodeme/Gold-Band --skill memory-leak-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/memory-leak-audit, .gemini/skills/memory-leak-audit, .github/skills/memory-leak-audit and .opencode/skills/memory-leak-audit in your project.
SKILL.md names no scripts, command-line tools or credentials: Memory Leak Audit is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Memory Leak Audit is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Memory Leak Audit: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), LLM Torch Profiler Analysis (sgl-project/sglang, 37k stars), Py (crazyguitar/pysheeet, 8.2k stars) and Cmux Debugging Guide (manaflow-ai/cmux, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
diodeme (a GitHub user) maintains it in diodeme/Gold-Band, which has 143 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on September 30, 2026.
Source: diodeme/Gold-Band on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.