Code Review
dotnet/macios
Review dotnet/macios PRs against established rules. An agent skill from dotnet/macios.
Scans C# and .NET code for about 50 performance anti-patterns and reports prioritized findings with concrete fixes, at a scan depth you choose.
$ npx skills add dotnet/skills --skill analyzing-dotnet-performance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dotnet/skills analyzing-dotnet-performance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dotnet-diag/skills/analyzing-dotnet-performance .claude/skills/analyzing-dotnet-performance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "analyzing-dotnet-performance" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-diag/skills/analyzing-dotnet-performance into .claude/skills/analyzing-dotnet-performance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-dotnet-performance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dotnet/skills/tree/main/plugins/dotnet-diag/skills/analyzing-dotnet-performanceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dotnet/skills --skill analyzing-dotnet-performance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dotnet/skills analyzing-dotnet-performance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/dotnet-diag/skills/analyzing-dotnet-performance .agents/skills/analyzing-dotnet-performance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "analyzing-dotnet-performance" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-diag/skills/analyzing-dotnet-performance into .agents/skills/analyzing-dotnet-performance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-dotnet-performance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dotnet/skills --skill analyzing-dotnet-performance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dotnet/skills analyzing-dotnet-performance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/dotnet-diag/skills/analyzing-dotnet-performance .cursor/skills/analyzing-dotnet-performance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "analyzing-dotnet-performance" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-diag/skills/analyzing-dotnet-performance into .cursor/skills/analyzing-dotnet-performance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-dotnet-performance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dotnet/skills.git --path plugins/dotnet-diag/skills/analyzing-dotnet-performance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dotnet/skills --skill analyzing-dotnet-performance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dotnet/skills analyzing-dotnet-performance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/dotnet-diag/skills/analyzing-dotnet-performance .gemini/skills/analyzing-dotnet-performance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "analyzing-dotnet-performance" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-diag/skills/analyzing-dotnet-performance into .gemini/skills/analyzing-dotnet-performance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-dotnet-performance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dotnet/skills analyzing-dotnet-performanceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dotnet/skills --skill analyzing-dotnet-performance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/dotnet-diag/skills/analyzing-dotnet-performance .github/skills/analyzing-dotnet-performance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "analyzing-dotnet-performance" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-diag/skills/analyzing-dotnet-performance into .github/skills/analyzing-dotnet-performance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-dotnet-performance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dotnet/skills --skill analyzing-dotnet-performance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dotnet/skills analyzing-dotnet-performance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/dotnet-diag/skills/analyzing-dotnet-performance .opencode/skills/analyzing-dotnet-performance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "analyzing-dotnet-performance" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-diag/skills/analyzing-dotnet-performance into .opencode/skills/analyzing-dotnet-performance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-dotnet-performance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
analyzing-dotnet-performanceScans C# and .NET code for about 50 performance anti-patterns and reports prioritized findings with concrete fixes, at a scan depth you choose.
The skill reads C# files, code blocks or repository paths and checks them against around 50 anti-patterns in async code, memory and strings, collections and LINQ, regex, serialization and I/O. Findings are classified by severity, ordered by priority and paired with specific fixes. The patterns come from the official .NET performance blog series, reduced to guidance a developer can act on.
You can pass hot-path context and the target framework, since some patterns require .NET 8 or later, and pick a scan depth: critical-only, standard (the default) or comprehensive. The agent always loads `references/critical-patterns.md` first, then in standard mode loads only the topic references whose signals appear in the code, such as async, memory and strings, regex, collections and LINQ, or JSON, HttpClient and streams. It does not analyze algorithmic complexity, and code off the hot path is left alone.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8d670fa. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Analyzing .NET Performance loads about 3.1k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 79 tokens; SKILL.md has 1,283 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dotnet/skills at commit 8d670fa, republished under its MIT licence (© dotnet). 1,283 words, ~3,145 tokens.
.claude/skills/analyzing-dotnet-performance/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.Scan C#/.NET code for performance anti-patterns and produce prioritized findings with concrete fixes. Patterns sourced from the official .NET performance blog series, distilled to customer-actionable guidance.
| Input | Required | Description |
|---|---|---|
| Source code | Yes | C# files, code blocks, or repository paths to scan |
| Hot-path context | Recommended | Which code paths are performance-critical |
| Target framework | Recommended | .NET version (some patterns require .NET 8+) |
| Scan depth | Optional | critical-only, standard (default), or comprehensive |
Resolve bundled paths from the directory that contains this SKILL.md, not from the user's workspace. Load this reference file first:
references/critical-patterns.mdIf a direct read fails, list this skill's references/ directory once and retry only when the listing shows the expected file. Do not use workspace file or text search to locate the skill installation.
Scan the code for signals that indicate which pattern categories to check. Use the ## Detection section from the critical reference when available and the inline recipes in Step 3 for initial signal detection.
After detecting signals, load only the topic-specific references selected by scan depth:
critical-only: No additional references (use only critical-patterns.md)standard (default): Load references matching detected signals from this list:references/async-patterns.md — async/Task/ValueTask signalsreferences/memory-and-strings.md — Span/Memory/string allocation signalsreferences/regex-patterns.md — Regex signalsreferences/collections-and-linq.md — Dictionary/List/LINQ signalsreferences/io-and-serialization.md — JsonSerializer/HttpClient/Stream signalsreferences/structural-patterns.md — always loaded (unsealed classes checked regardless)comprehensive: Load all six topic-specific references aboveFor coverage reporting, the selected references are references/critical-patterns.md plus only the topic-specific references selected above. If any selected reference remains unavailable after retry, use the inline recipes in Step 3 for the missing coverage. Include Reference coverage: reduced; unavailable: <paths>; used inline recipes for missing references. in the final report, with <paths> replaced by the missing relative paths of the selected references only.
Use the ## Detection sections from loaded reference files and the inline recipes in Step 3 for categories whose reference files are unavailable.
| Signal in Code | Topic |
|---|---|
async, await, Task, ValueTask | Async patterns |
Span<, Memory<, stackalloc, ArrayPool, string.Substring, .Replace(, .ToLower(), += in loops, params | Memory & strings |
Regex, [GeneratedRegex], Regex.Match, RegexOptions.Compiled | Regex patterns |
Dictionary<, List<, .ToList(), .Where(, .Select(, LINQ methods, static readonly Dictionary< | Collections & LINQ |
JsonSerializer, HttpClient, Stream, FileStream | I/O & serialization |
Always check structural patterns (unsealed classes) regardless of signals.
Scan depth controls scope:
critical-only: Only critical patterns (deadlocks, >10x regressions)standard (default): Critical + detected topic patternscomprehensive: All pattern categoriesFor files under 500 lines, read the entire file first — you'll spot most patterns faster than running individual grep recipes. Use grep to confirm counts and catch patterns you might miss visually.
For each relevant pattern category, run the detection recipes below. Report exact counts, not estimates.
Core scan recipes (run these when reference files aren't available):
# Strings & memory
grep -n '\.IndexOf(\"' FILE # Missing StringComparison
grep -n '\.Substring(' FILE # Substring allocations
grep -En '\.(StartsWith|EndsWith|Contains)\s*\(' FILE # Missing StringComparison
grep -n '\.ToLower()\|\.ToUpper()' FILE # Culture-sensitive + allocation
grep -n '\.Replace(' FILE # Chained Replace allocations
grep -n 'params ' FILE # params array allocation
# Collections & LINQ
grep -n '\.Select\|\.Where\|\.OrderBy\|\.GroupBy' FILE # LINQ on hot path
grep -n '\.All\|\.Any' FILE # LINQ on string/char
grep -n 'new Dictionary<\|new List<' FILE # Per-call allocation
grep -n 'static readonly Dictionary<' FILE # FrozenDictionary candidate
# Regex
grep -n 'RegexOptions.Compiled' FILE # Compiled regex budget
grep -n 'new Regex(' FILE # Per-call regex
grep -n 'GeneratedRegex' FILE # Positive: source-gen regex
# Structural
grep -n 'public class \|internal class ' FILE # Unsealed classes
grep -n 'sealed class' FILE # Already sealed
grep -n ': IEquatable' FILE # Positive: struct equalityRules:
## Detection recipesVerify-the-Inverse Rule: For absence patterns, always count both sides and report the ratio (e.g., "N of M classes are sealed"). The ratio determines severity — 0/185 is systematic, 12/15 is a consistency fix.
If an optimized pattern is found in one file, check whether sibling files (same directory, same interface, same base class) use the un-optimized equivalent. Flag as 🟡 Moderate with the optimized file as evidence.
After running scan recipes, look for these multi-allocation patterns that single-line recipes miss:
.Replace() chains: Methods that call .Replace() across multiple if/else branches — report total allocation count across all branches, not just per-line.+= with embedded allocating calls: Lines like result += $"...{Foo().ToLower()}" are 2+ allocations (interpolation + ToLower + concatenation) — flag the compound cost, not just the .ToLower().string.Format specificity: Distinguish resource-loaded format strings (not fixable) from compile-time literal format strings (fixable with interpolation). Enumerate the actionable sites.Assign each finding a severity:
| Severity | Criteria | Action |
|---|---|---|
| 🔴 Critical | Deadlocks, crashes, security vulnerabilities, >10x regression | Must fix |
| 🟡 Moderate | 2-10x improvement opportunity, best practice for hot paths | Should fix on hot paths |
| ℹ️ Info | Pattern applies but code may not be on a hot path | Consider if profiling shows impact |
Prioritization rules:
Scale-based severity escalation: When the same pattern appears across many instances, escalate severity:
Always report exact counts (from scan recipes), not estimates or agent summaries.
Keep findings compact. Each finding is one short block — not an essay. Group by severity (🔴 → 🟡 → ℹ️), not by file.
Format per finding:
#### ID. Title (N instances)
**Impact:** one-line impact statement
**Files:** file1.cs:L1, file2.cs:L2, ... (list locations, don't build tables)
**Fix:** one-line description of the change (e.g., "Add `StringComparison.Ordinal` parameter")
**Caveat:** only if non-obvious (version requirement, correctness risk)Rules for compact output:
File.cs:L42 format..ToLower() calls go in one finding, not split by file).✅ Pattern — evidence.End with a summary table and disclaimer:
| Severity | Count | Top Issue |
|----------|-------|-----------|
| 🔴 Critical | N | ... |
| 🟡 Moderate | N | ... |
| ℹ️ Info | N | ... |
> ⚠️ **Disclaimer:** These results are generated by an AI assistant and are non-deterministic. Findings may include false positives, miss real issues, or suggest changes that are incorrect for your specific context. Always verify recommendations with benchmarks and human review before applying changes to production code.Before delivering results, verify:
| Pitfall | Correct Approach |
|---|---|
Flagging every Dictionary as needing FrozenDictionary | Only flag if the dictionary is never mutated after construction |
Suggesting Span<T> in async methods | Use Memory<T> in async code; Span<T> only in sync hot paths |
| Reporting LINQ outside hot paths | Only flag LINQ in identified hot paths or tight loops; LINQ is acceptable in code that runs infrequently. Since .NET 7, LINQ Min/Max/Sum/Average are vectorized — blanket bans on LINQ are misguided |
Suggesting ConfigureAwait(false) in app code | Only applicable in library code; not primarily a performance concern |
Recommending ValueTask everywhere | Only for hot paths with frequent synchronous completion |
Flagging new HttpClient() in DI services | Check if IHttpClientFactory is already in use |
Suggesting [GeneratedRegex] for dynamic patterns | Only flag when the pattern string is a compile-time literal |
Suggesting CollectionsMarshal.AsSpan broadly | Only for ultra-hot paths with benchmarked evidence; adds complexity and fragility |
Suggesting unsafe code for micro-optimizations | Avoid unsafe except where absolutely necessary — do not recommend it for micro-optimizations that don't matter. Safe alternatives like Span<T>, stackalloc in safe context, and ArrayPool cover the vast majority of performance needs |
© dotnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (references) in plugins/dotnet-diag/skills/analyzing-dotnet-performance of dotnet/skills.
Open the folder on GitHubat commit 8d670fa
We found 4 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in dotnet/skills, which our catalogue first saw on October 7, 2026.
Analyzing .NET Performance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Analyzing .NET Performance this skilldotnet/skills | 5.6k | 3 repos | ~3.1k | Automated safety check: Pass | MIT | |
| Code Reviewdotnet/macios | 2.9k | — | ~1.7k | Automated safety check: Pass | Custom licence | |
| MAUI PR Performance Analysisdotnet/maui | 23k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Code Reviewjonathanpeppers/dotnes | 780 | — | ~2.1k | Automated safety check: Pass | MIT | |
| PR Code ReviewSamsung/TizenFX | 214 | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| Dotnet Copfmflurry/settings-opencode | 171 | — | ~2k | Automated safety check: Pass | MIT |
dotnet/macios
Review dotnet/macios PRs against established rules. An agent skill from dotnet/macios.
dotnet/maui
Interprets pinned managed benchmark evidence for a dotnet/maui pull request and writes a narrative for the performance review workflow, without running or publishing anything.
jonathanpeppers/dotnes
Review dotnes pull requests against established repository rules.
Samsung/TizenFX
Performs code review on every open PR of TizenFX and replies with technical responses to new comments left by other reviewers.
fmflurry/settings-opencode
Pre-merge code review for .NET 10 pull requests. An agent skill from fmflurry/settings-opencode.
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
dotnet/skills
Resolves .NET runtime frames in Apple .ips crash logs to function names, source files and line numbers using dSYM symbols, atos and the Microsoft symbol server.
dotnet/skills
Resolves native crash frames from .NET Android tombstones to function names, source files and line numbers using BuildIds, Microsoft's symbol server and llvm-symbolizer.
dotnet/skills
Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.
dotnet/skills
Activate this skill when BenchmarkDotNet (BDN) is involved in the task — creating, running, configuring, or reviewing BDN benchmarks.
dotnet/skills
Makes .NET projects compatible with Native AOT and trimming by resolving IL trim and AOT analyzer warnings through annotations rather than suppressions.
dotnet/skills
Configures automatic crash dumps or captures dumps from running processes for modern .NET apps on Linux, macOS and Windows, including Docker and Kubernetes.
Categories
Scans C# and .NET code for about 50 performance anti-patterns and reports prioritized findings with concrete fixes, at a scan depth you choose. The skill reads C# files, code blocks or repository paths and checks them against around 50 anti-patterns in async code, memory and strings, collections and LINQ, regex, serialization and I/O. Findings are classified by severity, ordered by priority and paired with specific fixes.
Analyzing .NET Performance fits situations like: reviewing C# code for performance optimization opportunities; auditing hot paths for allocation-heavy or inefficient patterns; running a systematic anti-pattern scan before a release; getting a second opinion after a manual performance review.
Run `npx skills add dotnet/skills --skill analyzing-dotnet-performance -a claude-code`. Or copy the skill folder (plugins/dotnet-diag/skills/analyzing-dotnet-performance in dotnet/skills) into .claude/skills/analyzing-dotnet-performance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dotnet/skills --skill analyzing-dotnet-performance -a codex`. Or copy the skill folder (plugins/dotnet-diag/skills/analyzing-dotnet-performance in dotnet/skills) into .agents/skills/analyzing-dotnet-performance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dotnet/skills --skill analyzing-dotnet-performance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-dotnet-performance, .gemini/skills/analyzing-dotnet-performance, .github/skills/analyzing-dotnet-performance and .opencode/skills/analyzing-dotnet-performance in your project.
SKILL.md names no scripts, command-line tools or credentials: Analyzing .NET Performance is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Analyzing .NET Performance is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Analyzing .NET Performance: Code Review (dotnet/macios, 2.9k stars), MAUI PR Performance Analysis (dotnet/maui, 23k stars), Code Review (jonathanpeppers/dotnes, 780 stars) and PR Code Review (Samsung/TizenFX, 214 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dotnet (a GitHub organization, an official publisher) maintains it in dotnet/skills, which has 5,568 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 7, 2026.
Source: dotnet/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.