Agent skill

Performance Assessment

by EmeaAppGbb in EmeaAppGbb/spec2cloud

Identify performance bottlenecks, inefficient patterns, and optimization opportunities through static analysis.

MITAuto-check passedSecurity

Install Performance Assessment

skills CLI
$ npx skills add EmeaAppGbb/spec2cloud --skill performance-assessment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install EmeaAppGbb/spec2cloud performance-assessment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/EmeaAppGbb/spec2cloud.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/performance-assessment .claude/skills/performance-assessment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performance-assessment
GitHub stars
100
Token cost
~2.2k tokens
SKILL.md length
931 words
Files
1
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

Identify performance bottlenecks, inefficient patterns, and optimization opportunities through static analysis.

  • Tasks that involve Static analysis and SAST
  • SKILL.md covers Role, Inputs, Important Disclaimer and Adaptive Depth Levels, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Performance Assessment is an agent skill from EmeaAppGbb/spec2cloud. Identify performance bottlenecks, inefficient patterns, and optimization opportunities through static analysis. Adaptive depth.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Static analysis and SAST. The licence is MIT.

When your agent uses it

  • Tasks that involve Static analysis and SAST

Example prompts

  • “/performance-assessment”

What it can do on your machine

Read from SKILL.md and the folder at commit 8e76618. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performance Assessment loads about 2.2k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 931 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from EmeaAppGbb/spec2cloud at commit 8e76618, republished under its MIT licence (© EmeaAppGbb). 931 words, ~2,245 tokens.

Download SKILL.mdSave it as .claude/skills/performance-assessment/SKILL.md (or your agent's skills folder).
name
performance-assessment
description
Identify performance bottlenecks, inefficient patterns, and optimization opportunities through static analysis. Adaptive depth.

Role

You are a performance analyst performing static code analysis. Your job is to identify patterns known to cause performance issues — not to measure actual performance. You flag code constructs that experience shows lead to bottlenecks, and you suggest targeted optimizations.

You are activated when the user selects the performance path. You do not run automatically.

Inputs

  • specs/docs/technology/* — Technology inventory from extraction
  • specs/docs/architecture/* — Architecture documentation from extraction
  • specs/docs/dependencies/* — Dependency manifests
  • Source code access for pattern analysis
  • Database schemas and query files (if available)

Important Disclaimer

This is static analysis only. Findings identify patterns that are known to cause performance issues based on established engineering knowledge. This assessment does not:

  • Run benchmarks or load tests
  • Measure actual response times or throughput
  • Profile memory usage or CPU consumption
  • Claim specific performance numbers

Use findings as investigation targets for runtime profiling, not as confirmed bottlenecks.

Adaptive Depth Levels

Level 1 — Common Hotspots

Scan for the most impactful and easily-identified performance anti-patterns:

  • N+1 query patterns: Loops that execute a database query per iteration. Look for ORM lazy-loading in loops, repeated single-record fetches, missing eager loading.
  • Missing database indexes: Cross-reference query WHERE/JOIN/ORDER BY clauses against schema indexes. Flag columns used in filters or joins that lack indexes.
  • Synchronous blocking calls: I/O operations (HTTP requests, file reads, database queries) executed synchronously in async-capable codebases. Blocking the event loop or thread pool.
  • Unbounded queries: SELECT without LIMIT, API endpoints returning full collections, missing pagination on list endpoints.
  • Large payload transfers: Endpoints returning full entity graphs when clients need subsets. Missing field selection or projection.

Estimated time: 10–20 minutes of analysis.

Escalation trigger: If Level 1 finds >3 high-severity patterns or database-layer concerns, auto-escalate to Level 2.

Level 2 — Optimization Opportunities

Deeper analysis of caching, resource management, and payload efficiency:

  • Caching opportunities:
    • Frequently-read, rarely-written data without caching
    • Expensive computations repeated with same inputs
    • Missing HTTP cache headers on static or semi-static responses
    • Cache invalidation patterns (or lack thereof)
  • Connection pooling:
    • Database connections opened/closed per request vs pooled
    • HTTP client connection reuse
    • Connection pool sizing relative to concurrency expectations
  • Payload size analysis:
    • API response sizes — over-fetching patterns
    • Image and asset optimization
    • Compression enabled on responses?
    • Bundle size for frontend applications (tree-shaking, code splitting)
  • Serialization overhead:
    • Large object serialization in hot paths
    • Inefficient serialization formats for the use case
    • Repeated serialization of the same data

Estimated time: 20–45 minutes of analysis.

Escalation trigger: If Level 2 finds concurrency issues or algorithmic concerns, escalate to Level 3.

Level 3 — Deep Pattern Analysis

Architectural and algorithmic performance review:

  • Concurrency patterns:
    • Lock contention — shared mutable state under concurrent access
    • Thread pool saturation — fixed pools with blocking operations
    • Async anti-patterns — async-over-sync, sync-over-async, missing cancellation
    • Parallel processing opportunities — sequential work that could be parallelized
  • Memory usage patterns:
    • Large object allocation in loops (GC pressure)
    • Unbounded collection growth (potential memory leaks)
    • String concatenation in loops vs builder patterns
    • Event handler or callback registration without cleanup
    • Large file processing without streaming
  • Algorithmic complexity hotspots:
    • Nested loops over large collections (O(n²) or worse)
    • Linear search where hash/tree lookup would work
    • Repeated sorting of the same data
    • Recursive algorithms without memoization on overlapping subproblems

Estimated time: 30–60 minutes of analysis.

Escalation Rules
Level 1: >3 high-severity patterns       → auto-escalate to Level 2
Level 2: concurrency or algorithmic issues → escalate to Level 3
User can force any level with:            "run performance assessment at level 3"
Show full SKILL.md (408 more words)Show less

Impact Ratings

Since this is static analysis, rate findings by estimated impact rather than measured severity:

  • High impact: Patterns that reliably cause visible performance degradation under normal load (N+1 queries on primary flows, missing indexes on frequently-queried tables, synchronous blocking in async hot paths).
  • Medium impact: Patterns that cause degradation under moderate-to-high load or with growing data volumes (missing caching, unbounded queries, connection churn).
  • Low impact: Patterns that contribute to inefficiency but are unlikely to cause visible issues alone (minor serialization overhead, suboptimal algorithms on small datasets).

Each finding includes:

  • Pattern identified
  • Location(s) in codebase
  • Why this pattern causes issues (brief explanation)
  • Suggested optimization
  • Estimated effort to fix
  • Confidence level (High: well-established anti-pattern / Medium: likely issue / Low: potential concern)

Output Format

Generate specs/assessment/performance.md with this structure:

markdown
# Performance Assessment

## Summary
- Assessment depth: Level [1/2/3]
- Total findings: [N]
- High impact: [N] | Medium impact: [N] | Low impact: [N]
- Primary concern areas: [list]
- Escalation triggered: [yes/no — reason]

## Findings by Category

### Database & Query Patterns
| # | Impact | Pattern | Location | Optimization | Effort | Confidence |
|---|--------|---------|----------|-------------|--------|------------|

### I/O & Async Patterns
(same table format)

### Caching & Resource Management
(same table format)

### Payload & Serialization
(same table format)

### Concurrency & Memory (Level 3)
(same table format)

### Algorithmic Complexity (Level 3)
(same table format)

## Optimization Roadmap
Priority-ordered optimization plan. Quick wins first, then structural improvements.

## Measurement Recommendations
For each high-impact finding, suggest how to validate the issue with runtime profiling.

## Decision Points
Items requiring user decision — linked to generated ADRs.

ADR Triggers

Generate ADRs via the adr skill when optimization requires architectural decisions:

  • Caching strategy: When introducing a caching layer (in-memory vs distributed, cache-aside vs write-through)
  • Database optimization approach: When query optimization alone is insufficient and schema or architecture changes are needed (read replicas, CQRS, denormalization)
  • Async architecture adoption: When synchronous architecture must shift to async/event-driven for performance
  • CDN and edge caching: When static asset or API response caching strategy needs definition

Important Notes

  • Do not fabricate performance numbers. Say "this pattern is known to cause latency under load" — not "this will add 500ms."
  • Quick wins matter. Prioritize findings that are easy to fix and high impact (missing indexes, N+1 fixes, enabling compression).
  • Context matters. An N+1 query on a list that always returns 3 items is low impact. The same pattern on a list with 10,000 items is high impact. Note the data volume context when available.
  • Frontend and backend performance are different disciplines. Clearly separate findings by layer.
  • Always suggest measurement before optimization. The roadmap should include "verify with profiling" steps.

Mandatory Completion Checklist

The orchestrator MUST verify ALL of the following before marking performance-assessment as complete:

  • specs/assessment/performance.md exists with: findings by layer (frontend / backend / database / network), severity ratings, and quick-win identification
  • Every finding has an impact level (high / medium / low) and estimated effort to fix
  • N+1 query patterns, missing indexes, and unoptimized queries are explicitly checked and reported
  • Frontend performance patterns are assessed separately from backend
  • "Measure before optimize" steps are included in the remediation roadmap
  • State JSON and audit log are updated

BLOCKING: If any item is unchecked, the skill has NOT completed successfully. The orchestrator must loop back and complete the missing items before advancing to planning.

© EmeaAppGbb, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/performance-assessment of EmeaAppGbb/spec2cloud.

Open the folder on GitHubat commit 8e76618

Compare with similar skills

Performance Assessment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performance Assessment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performance Assessment this skillEmeaAppGbb/spec2cloud100—~2.2kAutomated safety check: PassMIT
Semgrepvigolium/piolium1381 repos~2.4kAutomated safety check: NotesMIT
C To AstNarwhal-Lab/MagicSkills316—~1.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
LLM Sast ScannerSunWeb3Sec/llm-sast-scanner286—~6.2kAutomated safety check: PassNone
Sast SemgrepAgentSecOps/SecOpsAgentKit2192 repos~2.4kAutomated safety check: PassCustom licence

Similar skills

  • Semgrep

    vigolium/piolium

    Run Semgrep static analysis scan on a codebase using parallel subagents.

    138 GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • C To Ast

    Narwhal-Lab/MagicSkills

    Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

    316 GitHub stars~1.1k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • LLM Sast Scanner

    SunWeb3Sec/llm-sast-scanner

    General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.

    286 GitHub stars~6.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Sast Semgrep

    AgentSecOps/SecOpsAgentKit

    Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

    219 GitHub starsUsed in 2 repos~2.4k tokens
    SecurityAuto-check passed
  • Wp Phpstan

    Automattic/agent-skills

    A skill your agent uses when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and…

    211 GitHub starsUsed in 1 repo~1k tokens
    SecurityAuto-check passed

More from EmeaAppGbb/spec2cloud

All 39 skills in this repo
  • Azure Deployment

    EmeaAppGbb/spec2cloud

    Provision Azure infrastructure, deploy to Azure Container Apps, and verify via smoke tests.

    100 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Contract Generation

    EmeaAppGbb/spec2cloud

    Generate API contracts, shared TypeScript types, and infrastructure resource definitions from Gherkin scenarios and test files.

    100 GitHub stars~1.6k tokensUpdated 5 mo ago
    Auto-check passed
  • Ddd Modeling

    EmeaAppGbb/spec2cloud

    Create Domain-Driven Design proposals from product specs or brownfield extraction outputs.

    100 GitHub stars~2.4k tokensUpdated 5 mo ago
    Auto-check passed
  • Implementation

    EmeaAppGbb/spec2cloud

    Write application code to make failing tests pass using contract-driven, slice-based architecture.

    100 GitHub stars~2.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Spec Refinement

    EmeaAppGbb/spec2cloud

    Review PRDs and FRDs through product and technical lenses. An agent skill from EmeaAppGbb/spec2cloud.

    100 GitHub stars~2.2k tokensUpdated 5 mo ago
    Auto-check passed
  • State Management

    EmeaAppGbb/spec2cloud

    Read, write, and maintain .spec2cloud/state.json across phases and increments.

    100 GitHub stars~1.5k tokensUpdated 5 mo ago
    Auto-check passed

Categories

Questions about Performance Assessment

What does Performance Assessment do?

Identify performance bottlenecks, inefficient patterns, and optimization opportunities through static analysis. Performance Assessment is an agent skill from EmeaAppGbb/spec2cloud. Identify performance bottlenecks, inefficient patterns, and optimization opportunities through static analysis.

When should I use Performance Assessment?

Performance Assessment fits situations like: tasks that involve Static analysis and SAST.

How do I install Performance Assessment in Claude Code?

Run `npx skills add EmeaAppGbb/spec2cloud --skill performance-assessment -a claude-code`. Or copy the skill folder (.github/skills/performance-assessment in EmeaAppGbb/spec2cloud) into .claude/skills/performance-assessment in your project. Claude Code loads it when a task matches its description.

How do I install Performance Assessment in Codex?

Run `npx skills add EmeaAppGbb/spec2cloud --skill performance-assessment -a codex`. Or copy the skill folder (.github/skills/performance-assessment in EmeaAppGbb/spec2cloud) into .agents/skills/performance-assessment in your project. Codex loads it when a task matches its description.

Can I use Performance Assessment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EmeaAppGbb/spec2cloud --skill performance-assessment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performance-assessment, .gemini/skills/performance-assessment, .github/skills/performance-assessment and .opencode/skills/performance-assessment in your project.

What does Performance Assessment need to run?

SKILL.md names no scripts, command-line tools or credentials: Performance Assessment is instructions for the agent only.

Does Performance Assessment access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Performance Assessment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Performance Assessment use?

Performance Assessment is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performance Assessment use?

About 2.2k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Performance Assessment?

Skills that share tags, products or a category with Performance Assessment: Semgrep (vigolium/piolium, 138 stars), C To Ast (Narwhal-Lab/MagicSkills, 316 stars), Semgrep Security Scan (trailofbits/skills, 7.4k stars) and LLM Sast Scanner (SunWeb3Sec/llm-sast-scanner, 286 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performance Assessment?

EmeaAppGbb (a GitHub organization) maintains it in EmeaAppGbb/spec2cloud, which has 100 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on April 16, 2026.

Source: EmeaAppGbb/spec2cloud on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.