Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Performance-trace Nub package-manager installs using the existing phase timings, structured diagnostics, and sampling-profiler workflow.
$ npx skills add nubjs/nub --skill pm-perf-tracing -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nubjs/nub pm-perf-tracing --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/pm-perf-tracing .claude/skills/pm-perf-tracing && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pm-perf-tracing" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/pm-perf-tracing into .claude/skills/pm-perf-tracing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pm-perf-tracing", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nubjs/nub/tree/main/.claude/skills/pm-perf-tracingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nubjs/nub --skill pm-perf-tracing -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nubjs/nub pm-perf-tracing --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/pm-perf-tracing .agents/skills/pm-perf-tracing && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pm-perf-tracing" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/pm-perf-tracing into .agents/skills/pm-perf-tracing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pm-perf-tracing", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nubjs/nub --skill pm-perf-tracing -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nubjs/nub pm-perf-tracing --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/pm-perf-tracing .cursor/skills/pm-perf-tracing && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pm-perf-tracing" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/pm-perf-tracing into .cursor/skills/pm-perf-tracing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pm-perf-tracing", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nubjs/nub.git --path .claude/skills/pm-perf-tracing--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nubjs/nub --skill pm-perf-tracing -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nubjs/nub pm-perf-tracing --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/pm-perf-tracing .gemini/skills/pm-perf-tracing && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pm-perf-tracing" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/pm-perf-tracing into .gemini/skills/pm-perf-tracing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pm-perf-tracing", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nubjs/nub pm-perf-tracingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nubjs/nub --skill pm-perf-tracing -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/pm-perf-tracing .github/skills/pm-perf-tracing && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pm-perf-tracing" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/pm-perf-tracing into .github/skills/pm-perf-tracing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pm-perf-tracing", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nubjs/nub --skill pm-perf-tracing -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nubjs/nub pm-perf-tracing --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nubjs/nub.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/pm-perf-tracing .opencode/skills/pm-perf-tracing && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pm-perf-tracing" agent skill from https://github.com/nubjs/nub/tree/main/.claude/skills/pm-perf-tracing into .opencode/skills/pm-perf-tracing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pm-perf-tracing", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pm-perf-tracingPerformance-trace Nub package-manager installs using the existing phase timings, structured diagnostics, and sampling-profiler workflow.
Pm Perf Tracing is an agent skill from nubjs/nub. Performance-trace Nub package-manager installs using the existing phase timings, structured diagnostics, and sampling-profiler workflow. Use when an install or package-manager operation is unexpectedly slow and the bottleneck needs to be localized before changing code.
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Performance optimization. The repository describes itself as: The fast all-in-one Node.js toolkit. The licence is MIT.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 568e73a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
cargoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pm Perf Tracing loads about 1.3k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 570 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from nubjs/nub at commit 568e73a, republished under its MIT licence (© nubjs). 570 words, ~1,293 tokens.
.claude/skills/pm-perf-tracing/SKILL.md (or your agent's skills folder).How to performance-trace the nub package manager (install/resolve/fetch/link) and find where the time actually goes — the method that cracked the hoisted-linker slowness (10.8s → root-caused to a per-file copy loop). Reach for this any time a nub install / PM operation is "mysteriously slow" — do NOT reverse-engineer from source; the instrumentation already exists, turn it on.
Phase timings — works under nub TODAY. RUST_LOG=debug nub install emits phase:<name> <elapsed> lines on stderr: phase:resolve, phase:fetch (N packages), phase:link (N files), phase:link_bins. This alone tells you the coarse split (is it network/resolve, or linking?). The aube engine wires these through the tracing crate.
Rich diagnostics layer — native under nub via NUB_DIAG_*. aube_util::diag emits structured JSONL to NUB_DIAG_FILE=<path> — including, for the linker, one event per file naming the strategy used (link_clonedir, link_reflink, link_macos_small_copy, link_copy, link_hardlink). This is the load-independent crux for a link-perf question. The full knob set (all off by default, zero cost when unset):
NUB_DIAG_FILE=<path> — JSONL events to a file.NUB_DIAG_PRINT=1 — live per-span lines to stderr.NUB_DIAG_SUMMARY=1 — end-of-run aggregate table.NUB_DIAG_CRITPATH=1 — retain records for the critical-path / lifecycle / starvation analyzers.NUB_DIAG_THRESHOLD_MS=<n> — filter live prints below <n> ms.NUB_DIAG_KERNEL=1 — getrusage kernel deltas around phases.NUB_BENCH_PHASES_FILE=<path> — per-run phase-timing JSON for the bench harness.cargo build -p nub-cli --profile fast # dev binary at <worktree>-target/fast/nub
NUB=<worktree>-target/fast/nub
NUB_DIAG_FILE=/tmp/d.jsonl NUB_DIAG_SUMMARY=1 "$NUB" install --offline
grep -o '"name":"link_[a-z_]*"' /tmp/d.jsonl | sort | uniq -c # per-strategy tally(The diag layer reads NUB_DIAG_* under the nub embedder profile via the diag_env_prefix hook — no source edit needed. AUBE_DIAG_* is NOT read under nub. The dev-tracing-telemetry thread / wiki/research/dev-tracing-telemetry.md tracks the optional chrome-trace/flamegraph export layer on top.)
The dev box runs load ~30–50 and never goes quiet, so absolute wall-clock is untrustworthy. Measure things contention can't ruin:
rm -rf node_modules and assert it's gone, warm store already populated, --offline (proves zero network: phase:fetch shows 0 packages), and check rc=0 on every run (a timing from an errored install — e.g. npm's rm: Directory not empty purge failures → rc=254 — is garbage).link_macos_small_copy, 0 took link_clonedir" is a fact regardless of load. That's what proves a design gap.--node-linker isolated on the same fixture, same load window → the relative delta (≈26×) is robust even when both absolutes are inflated.nub mirrors the incumbent layout: an npm/yarn/bun lockfile → hoisted layout (link.rs → hoisted::link_hoisted_importer); nub-identity / --node-linker isolated → isolated layout (materialize_into, the only path with the whole-dir clonefile(2) fast path). They have completely different perf characteristics. When a perf question is about linking, run BOTH (--node-linker isolated vs default) and diff — that A/B is what localized the hoisted-linker gap.
Span/JSONL instrumentation can distort a syscall-bound, parallel pass (observer effect). For "where inside the link phase do the syscalls go" use a sampling profiler on a release build: samply record -- <NUB> install --offline (macOS/Linux), or cargo flamegraph. Spans tell you which phase/strategy; the sampler tells you which syscalls/functions dominate.
/tmp/coffee2-demo — CoffeeScript 2.0.1, npm lockfileVersion:1, 519 pkgs / ~76k hoisted files. The canonical heavy-hoisted-layout fixture.package.json + package-lock.json with webpack@3.6.0 + underscore (no node_modules).RUST_LOG=debug nub install for the phase split; if it's phase:link, set NUB_DIAG_FILE=… for the per-file strategy tally; A/B against --node-linker isolated; judge by strategy-tally + ratio, never the contended absolute.
© nubjs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/pm-perf-tracing of nubjs/nub.
Open the folder on GitHubat commit 568e73a
Pm Perf Tracing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pm Perf Tracing this skillnubjs/nub | 4.4k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| LLM Torch Profiler Analysissgl-project/sglang | 37k | 2 repos | ~6.4k | Automated safety check: Pass | Apache-2.0 | |
| Pycrazyguitar/pysheeet | 8.2k | — | ~886 | Automated safety check: Pass | MIT | |
| Cmux Debugging Guidemanaflow-ai/cmux | 28k | 1 repos | ~1.1k | Automated safety check: Pass | Custom licence | |
| Electron Heap Snapshot Analysiskeybase/client | 9.3k | — | ~875 | Automated safety check: Pass | BSD-3-Clause |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
sgl-project/sglang
Unified LLM torch-profiler triage skill for sglang, vllm, TensorRT-LLM, and TokenSpeed.
crazyguitar/pysheeet
Comprehensive Python programming reference covering syntax, concurrency, networking, databases, ML/LLM development, and HPC.
manaflow-ai/cmux
Covers debug logging, the Debug menu, profiling rules and runtime pitfalls for working on the cmux macOS terminal app.
keybase/client
Analyzes V8, Chrome and Electron .heapsnapshot files with Node scripts to find memory leaks, detached DOM nodes and the retainer paths that keep objects alive.
ben-manes/caffeine
Runs controlled JMH experiments on the Caffeine cache to find shared contention and hot-path waste, then reviews correctness and returns a reviewable patch.
nubjs/nub
Diagnose and clear CPU, memory, and disk contention on the maintainer's dev host.
nubjs/nub
Reclaim disk on the maintainer's Mac when the volume is full or filling — ENOSPC, "no space left on device", a failed build or agent harness, or a routine sweep of Rust build residue.
nubjs/nub
Build a performance chart for nubjs.com — the SVG bar figures in blog posts, docs pages and social posts (a runtime augmentation against plain node, an install or dispatch comparison, a cross-tool…
nubjs/nub
A skill your agent uses when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a…
nubjs/nub
Run ad-hoc Nub tests and debugging probes on real local Linux guests.
nubjs/nub
A skill your agent uses when building or testing the nub Rust workspace inside a git worktree — cargo build/test/clippy for nub-cli/nub-core/aube in a worktree off origin/main.
Categories
Performance-trace Nub package-manager installs using the existing phase timings, structured diagnostics, and sampling-profiler workflow. Pm Perf Tracing is an agent skill from nubjs/nub. Performance-trace Nub package-manager installs using the existing phase timings, structured diagnostics, and sampling-profiler workflow.
Pm Perf Tracing fits situations like: package-manager operation is unexpectedly slow and the bottleneck needs to be localized before changing code; tasks that involve Performance optimization.
Run `npx skills add nubjs/nub --skill pm-perf-tracing -a claude-code`. Or copy the skill folder (.claude/skills/pm-perf-tracing in nubjs/nub) into .claude/skills/pm-perf-tracing in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nubjs/nub --skill pm-perf-tracing -a codex`. Or copy the skill folder (.claude/skills/pm-perf-tracing in nubjs/nub) into .agents/skills/pm-perf-tracing in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nubjs/nub --skill pm-perf-tracing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pm-perf-tracing, .gemini/skills/pm-perf-tracing, .github/skills/pm-perf-tracing and .opencode/skills/pm-perf-tracing in your project.
Going by SKILL.md and its folder, Pm Perf Tracing needs the command-line tools its instructions call (cargo).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Pm Perf Tracing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Pm Perf Tracing: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), LLM Torch Profiler Analysis (sgl-project/sglang, 37k stars), Py (crazyguitar/pysheeet, 8.2k stars) and Cmux Debugging Guide (manaflow-ai/cmux, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nubjs (a GitHub organization) maintains it in nubjs/nub, which has 4,375 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 9, 2026.
Source: nubjs/nub on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.