Official agent skill

Analyzing .NET Performance

by dotnet in dotnet/skills

Scans C# and .NET code for about 50 performance anti-patterns and reports prioritized findings with concrete fixes, at a scan depth you choose.

OfficialMITAuto-check passedDevelopment

Install Analyzing .NET Performance

skills CLI
$ npx skills add dotnet/skills --skill analyzing-dotnet-performance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dotnet/skills analyzing-dotnet-performance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dotnet-diag/skills/analyzing-dotnet-performance .claude/skills/analyzing-dotnet-performance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyzing-dotnet-performance
GitHub stars
5.6k
Used in
3 other repos
Token cost
~3.1k tokens
SKILL.md length
1,283 words
Files
8 (incl. references)
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Scans C# and .NET code for about 50 performance anti-patterns and reports prioritized findings with concrete fixes, at a scan depth you choose.

  • Works in 5 steps: Load Critical Reference → Detect Code Signals and Select Topic… → Scan and Report → …
  • Reviewing C# code for performance optimization opportunities
  • SKILL.md covers When to Use, When Not to Use, Inputs and Workflow, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

The skill reads C# files, code blocks or repository paths and checks them against around 50 anti-patterns in async code, memory and strings, collections and LINQ, regex, serialization and I/O. Findings are classified by severity, ordered by priority and paired with specific fixes. The patterns come from the official .NET performance blog series, reduced to guidance a developer can act on.

You can pass hot-path context and the target framework, since some patterns require .NET 8 or later, and pick a scan depth: critical-only, standard (the default) or comprehensive. The agent always loads `references/critical-patterns.md` first, then in standard mode loads only the topic references whose signals appear in the code, such as async, memory and strings, regex, collections and LINQ, or JSON, HttpClient and streams. It does not analyze algorithmic complexity, and code off the hot path is left alone.

When your agent uses it

  • Reviewing C# code for performance optimization opportunities
  • Auditing hot paths for allocation-heavy or inefficient patterns
  • Running a systematic anti-pattern scan before a release
  • Getting a second opinion after a manual performance review

Example prompts

  • “Scan src/Orders for performance anti-patterns and rank them by severity.”
  • “Review this request handler for allocation problems; we target .NET 8.”
  • “Run a critical-only scan over the whole solution before the release.”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Load Critical Reference
  2. Detect Code Signals and Select Topic Recipes
  3. Scan and Report
  4. Classify and Prioritize Findings
  5. Generate Findings

What it can do on your machine

Read from SKILL.md and the folder at commit 8d670fa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Analyzing .NET Performance loads about 3.1k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 79 tokens; SKILL.md has 1,283 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~11k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dotnet/skills at commit 8d670fa, republished under its MIT licence (© dotnet). 1,283 words, ~3,145 tokens.

Download SKILL.mdSave it as .claude/skills/analyzing-dotnet-performance/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
analyzing-dotnet-performance
description
Scans .NET code for ~50 performance anti-patterns across async, memory, strings, collections, LINQ, regex, serialization, and I/O with tiered severity classification. Use when analyzing .NET code for optimization opportunities, reviewing hot paths, or auditing allocation-heavy patterns.
license
MIT

.NET Performance Patterns

Scan C#/.NET code for performance anti-patterns and produce prioritized findings with concrete fixes. Patterns sourced from the official .NET performance blog series, distilled to customer-actionable guidance.

When to Use

  • Reviewing C#/.NET code for performance optimization opportunities
  • Auditing hot paths for allocation-heavy or inefficient patterns
  • Systematic scan of a codebase for known anti-patterns before release
  • Second-opinion analysis after manual performance review

When Not to Use

  • Algorithmic complexity analysis — this skill targets API usage patterns, not algorithm design
  • Code not on a hot path with no performance requirements — avoid premature optimization

Inputs

InputRequiredDescription
Source codeYesC# files, code blocks, or repository paths to scan
Hot-path contextRecommendedWhich code paths are performance-critical
Target frameworkRecommended.NET version (some patterns require .NET 8+)
Scan depthOptionalcritical-only, standard (default), or comprehensive

Workflow

Step 1: Load Critical Reference

Resolve bundled paths from the directory that contains this SKILL.md, not from the user's workspace. Load this reference file first:

  • references/critical-patterns.md

If a direct read fails, list this skill's references/ directory once and retry only when the listing shows the expected file. Do not use workspace file or text search to locate the skill installation.

Step 2: Detect Code Signals and Select Topic Recipes

Scan the code for signals that indicate which pattern categories to check. Use the ## Detection section from the critical reference when available and the inline recipes in Step 3 for initial signal detection.

After detecting signals, load only the topic-specific references selected by scan depth:

  • critical-only: No additional references (use only critical-patterns.md)
  • standard (default): Load references matching detected signals from this list:
    • references/async-patterns.md — async/Task/ValueTask signals
    • references/memory-and-strings.md — Span/Memory/string allocation signals
    • references/regex-patterns.md — Regex signals
    • references/collections-and-linq.md — Dictionary/List/LINQ signals
    • references/io-and-serialization.md — JsonSerializer/HttpClient/Stream signals
    • references/structural-patterns.md — always loaded (unsealed classes checked regardless)
  • comprehensive: Load all six topic-specific references above

For coverage reporting, the selected references are references/critical-patterns.md plus only the topic-specific references selected above. If any selected reference remains unavailable after retry, use the inline recipes in Step 3 for the missing coverage. Include Reference coverage: reduced; unavailable: <paths>; used inline recipes for missing references. in the final report, with <paths> replaced by the missing relative paths of the selected references only.

Use the ## Detection sections from loaded reference files and the inline recipes in Step 3 for categories whose reference files are unavailable.

Signal in CodeTopic
async, await, Task, ValueTaskAsync patterns
Span<, Memory<, stackalloc, ArrayPool, string.Substring, .Replace(, .ToLower(), += in loops, paramsMemory & strings
Regex, [GeneratedRegex], Regex.Match, RegexOptions.CompiledRegex patterns
Dictionary<, List<, .ToList(), .Where(, .Select(, LINQ methods, static readonly Dictionary<Collections & LINQ
JsonSerializer, HttpClient, Stream, FileStreamI/O & serialization

Always check structural patterns (unsealed classes) regardless of signals.

Scan depth controls scope:

  • critical-only: Only critical patterns (deadlocks, >10x regressions)
  • standard (default): Critical + detected topic patterns
  • comprehensive: All pattern categories
Step 3: Scan and Report

For files under 500 lines, read the entire file first — you'll spot most patterns faster than running individual grep recipes. Use grep to confirm counts and catch patterns you might miss visually.

For each relevant pattern category, run the detection recipes below. Report exact counts, not estimates.

Core scan recipes (run these when reference files aren't available):

# Strings & memory
grep -n '\.IndexOf(\"' FILE                    # Missing StringComparison
grep -n '\.Substring(' FILE                    # Substring allocations
grep -En '\.(StartsWith|EndsWith|Contains)\s*\(' FILE  # Missing StringComparison
grep -n '\.ToLower()\|\.ToUpper()' FILE        # Culture-sensitive + allocation
grep -n '\.Replace(' FILE                      # Chained Replace allocations
grep -n 'params ' FILE                         # params array allocation

# Collections & LINQ
grep -n '\.Select\|\.Where\|\.OrderBy\|\.GroupBy' FILE  # LINQ on hot path
grep -n '\.All\|\.Any' FILE                    # LINQ on string/char
grep -n 'new Dictionary<\|new List<' FILE      # Per-call allocation
grep -n 'static readonly Dictionary<' FILE     # FrozenDictionary candidate

# Regex
grep -n 'RegexOptions.Compiled' FILE           # Compiled regex budget
grep -n 'new Regex(' FILE                      # Per-call regex
grep -n 'GeneratedRegex' FILE                  # Positive: source-gen regex

# Structural
grep -n 'public class \|internal class ' FILE  # Unsealed classes
grep -n 'sealed class' FILE                    # Already sealed
grep -n ': IEquatable' FILE                    # Positive: struct equality

Rules:

  • Run every relevant recipe for the detected pattern categories
  • Emit a scan execution checklist before classifying findings — list each recipe and the hit count
  • A result of 0 hits is valid and valuable (confirms good practice)
  • If reference files were loaded, also run their ## Detection recipes

Verify-the-Inverse Rule: For absence patterns, always count both sides and report the ratio (e.g., "N of M classes are sealed"). The ratio determines severity — 0/185 is systematic, 12/15 is a consistency fix.

Step 3b: Cross-File Consistency Check

If an optimized pattern is found in one file, check whether sibling files (same directory, same interface, same base class) use the un-optimized equivalent. Flag as 🟡 Moderate with the optimized file as evidence.

Step 3c: Compound Allocation Check

After running scan recipes, look for these multi-allocation patterns that single-line recipes miss:

  1. Branched .Replace() chains: Methods that call .Replace() across multiple if/else branches — report total allocation count across all branches, not just per-line.
  2. Cross-method chaining: When a public method delegates to another method that itself allocates intermediates (e.g., A calls B which does 3 regex replaces, then A calls C), report the total chain cost as one finding.
  3. Compound += with embedded allocating calls: Lines like result += $"...{Foo().ToLower()}" are 2+ allocations (interpolation + ToLower + concatenation) — flag the compound cost, not just the .ToLower().
  4. string.Format specificity: Distinguish resource-loaded format strings (not fixable) from compile-time literal format strings (fixable with interpolation). Enumerate the actionable sites.
Show full SKILL.md (526 more words)Show less
Step 4: Classify and Prioritize Findings

Assign each finding a severity:

SeverityCriteriaAction
🔴 CriticalDeadlocks, crashes, security vulnerabilities, >10x regressionMust fix
🟡 Moderate2-10x improvement opportunity, best practice for hot pathsShould fix on hot paths
ℹ️ InfoPattern applies but code may not be on a hot pathConsider if profiling shows impact

Prioritization rules:

  1. If the user identified hot-path code, elevate all findings in that code to their maximum severity
  2. If hot-path context is unknown, report 🔴 Critical findings unconditionally; report 🟡 Moderate findings with a note: "Impactful if this code is on a hot path"
  3. Never suggest micro-optimizations on code that is clearly not performance-sensitive

Scale-based severity escalation: When the same pattern appears across many instances, escalate severity:

  • 1-10 instances of the same anti-pattern → report at the pattern's base severity
  • 11-50 instances → escalate ℹ️ Info patterns to 🟡 Moderate
  • 50+ instances → escalate to 🟡 Moderate with elevated priority; flag as a codebase-wide systematic issue

Always report exact counts (from scan recipes), not estimates or agent summaries.

Step 5: Generate Findings

Keep findings compact. Each finding is one short block — not an essay. Group by severity (🔴 → 🟡 → ℹ️), not by file.

Format per finding:

#### ID. Title (N instances)
**Impact:** one-line impact statement
**Files:** file1.cs:L1, file2.cs:L2, ... (list locations, don't build tables)
**Fix:** one-line description of the change (e.g., "Add `StringComparison.Ordinal` parameter")
**Caveat:** only if non-obvious (version requirement, correctness risk)

Rules for compact output:

  • No ❌/✅ code blocks for trivial fixes (adding a keyword, parameter, or type change). A one-line fix description suffices.
  • Only include code blocks for non-obvious transformations (e.g., replacing a LINQ chain with a foreach loop, or hoisting a closure).
  • File locations as inline comma-separated list, not a table. Use File.cs:L42 format.
  • No explanatory prose beyond the Impact line — the severity icon already conveys urgency.
  • Merge related findings that share the same fix (e.g., all .ToLower() calls go in one finding, not split by file).
  • Positive findings in a bullet list, not a table. One line per pattern: ✅ Pattern — evidence.

End with a summary table and disclaimer:

markdown
| Severity | Count | Top Issue |
|----------|-------|-----------|
| 🔴 Critical | N | ... |
| 🟡 Moderate | N | ... |
| ℹ️ Info | N | ... |

> ⚠️ **Disclaimer:** These results are generated by an AI assistant and are non-deterministic. Findings may include false positives, miss real issues, or suggest changes that are incorrect for your specific context. Always verify recommendations with benchmarks and human review before applying changes to production code.

Validation

Before delivering results, verify:

  • All critical patterns were checked (from reference files or inline recipes)
  • Topic-specific recipes run only when matching signals detected
  • Each finding includes a concrete code fix
  • Scan execution checklist is complete (all recipes run)
  • Summary table included at end

Common Pitfalls

PitfallCorrect Approach
Flagging every Dictionary as needing FrozenDictionaryOnly flag if the dictionary is never mutated after construction
Suggesting Span<T> in async methodsUse Memory<T> in async code; Span<T> only in sync hot paths
Reporting LINQ outside hot pathsOnly flag LINQ in identified hot paths or tight loops; LINQ is acceptable in code that runs infrequently. Since .NET 7, LINQ Min/Max/Sum/Average are vectorized — blanket bans on LINQ are misguided
Suggesting ConfigureAwait(false) in app codeOnly applicable in library code; not primarily a performance concern
Recommending ValueTask everywhereOnly for hot paths with frequent synchronous completion
Flagging new HttpClient() in DI servicesCheck if IHttpClientFactory is already in use
Suggesting [GeneratedRegex] for dynamic patternsOnly flag when the pattern string is a compile-time literal
Suggesting CollectionsMarshal.AsSpan broadlyOnly for ultra-hot paths with benchmarked evidence; adds complexity and fragility
Suggesting unsafe code for micro-optimizationsAvoid unsafe except where absolutely necessary — do not recommend it for micro-optimizations that don't matter. Safe alternatives like Span<T>, stackalloc in safe context, and ArrayPool cover the vast majority of performance needs

© dotnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in plugins/dotnet-diag/skills/analyzing-dotnet-performance of dotnet/skills.

  • SKILL.md
  • references/async-patterns.md
  • references/collections-and-linq.md
  • references/critical-patterns.md
  • references/io-and-serialization.md
  • references/memory-and-strings.md
  • references/regex-patterns.md
  • references/structural-patterns.md

Open the folder on GitHubat commit 8d670fa

Used in 3 other repositories

We found 4 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in dotnet/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Analyzing .NET Performance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Analyzing .NET Performance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Analyzing .NET Performance this skilldotnet/skills5.6k3 repos~3.1kAutomated safety check: PassMIT
Code Reviewdotnet/macios2.9k—~1.7kAutomated safety check: PassCustom licence
MAUI PR Performance Analysisdotnet/maui23k—~2.4kAutomated safety check: PassMIT
Code Reviewjonathanpeppers/dotnes780—~2.1kAutomated safety check: PassMIT
PR Code ReviewSamsung/TizenFX214—~3.3kAutomated safety check: PassApache-2.0
Dotnet Copfmflurry/settings-opencode171—~2kAutomated safety check: PassMIT

Similar skills

  • Code Review

    dotnet/macios

    Official

    Review dotnet/macios PRs against established rules. An agent skill from dotnet/macios.

    2.9k GitHub stars~1.7k tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Interprets pinned managed benchmark evidence for a dotnet/maui pull request and writes a narrative for the performance review workflow, without running or publishing anything.

    23k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review

    jonathanpeppers/dotnes

    Review dotnes pull requests against established repository rules.

    780 GitHub stars~2.1k tokensUpdated 13 days ago
    DevelopmentAuto-check passed
  • PR Code Review

    Samsung/TizenFX

    Performs code review on every open PR of TizenFX and replies with technical responses to new comments left by other reviewers.

    214 GitHub stars~3.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Dotnet Cop

    fmflurry/settings-opencode

    Pre-merge code review for .NET 10 pull requests. An agent skill from fmflurry/settings-opencode.

    171 GitHub stars~2k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed

More from dotnet/skills

All 91 skills in this repo
  • Official

    Resolves .NET runtime frames in Apple .ips crash logs to function names, source files and line numbers using dSYM symbols, atos and the Microsoft symbol server.

    5.6k GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Official

    Resolves native crash frames from .NET Android tombstones to function names, source files and line numbers using BuildIds, Microsoft's symbol server and llvm-symbolizer.

    5.6k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Official

    Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.

    5.6k GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Microbenchmarking

    dotnet/skills

    Official

    Activate this skill when BenchmarkDotNet (BDN) is involved in the task — creating, running, configuring, or reviewing BDN benchmarks.

    5.6k GitHub starsUsed in 3 repos~3.3k tokens
    Auto-check passed
  • Official

    Makes .NET projects compatible with Native AOT and trimming by resolving IL trim and AOT analyzer warnings through annotations rather than suppressions.

    5.6k GitHub starsUsed in 2 repos~4.2k tokens
    Auto-check passed
  • Official

    Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.

    5.6k GitHub starsUsed in 2 repos~1.1k tokens
    Auto-check passed

Works with

Categories

Questions about Analyzing .NET Performance

What does Analyzing .NET Performance do?

Scans C# and .NET code for about 50 performance anti-patterns and reports prioritized findings with concrete fixes, at a scan depth you choose. The skill reads C# files, code blocks or repository paths and checks them against around 50 anti-patterns in async code, memory and strings, collections and LINQ, regex, serialization and I/O. Findings are classified by severity, ordered by priority and paired with specific fixes.

When should I use Analyzing .NET Performance?

Analyzing .NET Performance fits situations like: reviewing C# code for performance optimization opportunities; auditing hot paths for allocation-heavy or inefficient patterns; running a systematic anti-pattern scan before a release; getting a second opinion after a manual performance review.

How do I install Analyzing .NET Performance in Claude Code?

Run `npx skills add dotnet/skills --skill analyzing-dotnet-performance -a claude-code`. Or copy the skill folder (plugins/dotnet-diag/skills/analyzing-dotnet-performance in dotnet/skills) into .claude/skills/analyzing-dotnet-performance in your project. Claude Code loads it when a task matches its description.

How do I install Analyzing .NET Performance in Codex?

Run `npx skills add dotnet/skills --skill analyzing-dotnet-performance -a codex`. Or copy the skill folder (plugins/dotnet-diag/skills/analyzing-dotnet-performance in dotnet/skills) into .agents/skills/analyzing-dotnet-performance in your project. Codex loads it when a task matches its description.

Can I use Analyzing .NET Performance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dotnet/skills --skill analyzing-dotnet-performance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-dotnet-performance, .gemini/skills/analyzing-dotnet-performance, .github/skills/analyzing-dotnet-performance and .opencode/skills/analyzing-dotnet-performance in your project.

What does Analyzing .NET Performance need to run?

SKILL.md names no scripts, command-line tools or credentials: Analyzing .NET Performance is instructions for the agent only.

Does Analyzing .NET Performance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Analyzing .NET Performance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Analyzing .NET Performance use?

Analyzing .NET Performance is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Analyzing .NET Performance use?

About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8k tokens, read only when the agent opens those files.

What are the alternatives to Analyzing .NET Performance?

Skills that share tags, products or a category with Analyzing .NET Performance: Code Review (dotnet/macios, 2.9k stars), MAUI PR Performance Analysis (dotnet/maui, 23k stars), Code Review (jonathanpeppers/dotnes, 780 stars) and PR Code Review (Samsung/TizenFX, 214 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Analyzing .NET Performance?

dotnet (a GitHub organization, an official publisher) maintains it in dotnet/skills, which has 5,568 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 7, 2026.

Source: dotnet/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.