Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
A MEASURED performance problem: start from a benchmark, flame graph, perf sample or profiler run, locate the hot symbol the profile names, test structural hypotheses (memory-bound → cache-line data…
$ npx skills add redhat-et/ripwire --skill ripwire-perf-target -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install redhat-et/ripwire ripwire-perf-target --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/redhat-et/ripwire.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ripwire-perf-target .claude/skills/ripwire-perf-target && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "ripwire-perf-target" agent skill from https://github.com/redhat-et/ripwire/tree/main/skills/ripwire-perf-target into .claude/skills/ripwire-perf-target/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ripwire-perf-target", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/redhat-et/ripwire/tree/main/skills/ripwire-perf-targetType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add redhat-et/ripwire --skill ripwire-perf-target -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install redhat-et/ripwire ripwire-perf-target --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/redhat-et/ripwire.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/ripwire-perf-target .agents/skills/ripwire-perf-target && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "ripwire-perf-target" agent skill from https://github.com/redhat-et/ripwire/tree/main/skills/ripwire-perf-target into .agents/skills/ripwire-perf-target/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ripwire-perf-target", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add redhat-et/ripwire --skill ripwire-perf-target -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install redhat-et/ripwire ripwire-perf-target --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/redhat-et/ripwire.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/ripwire-perf-target .cursor/skills/ripwire-perf-target && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "ripwire-perf-target" agent skill from https://github.com/redhat-et/ripwire/tree/main/skills/ripwire-perf-target into .cursor/skills/ripwire-perf-target/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ripwire-perf-target", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/redhat-et/ripwire.git --path skills/ripwire-perf-target--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add redhat-et/ripwire --skill ripwire-perf-target -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install redhat-et/ripwire ripwire-perf-target --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/redhat-et/ripwire.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/ripwire-perf-target .gemini/skills/ripwire-perf-target && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "ripwire-perf-target" agent skill from https://github.com/redhat-et/ripwire/tree/main/skills/ripwire-perf-target into .gemini/skills/ripwire-perf-target/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ripwire-perf-target", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install redhat-et/ripwire ripwire-perf-targetInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add redhat-et/ripwire --skill ripwire-perf-target -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/redhat-et/ripwire.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/ripwire-perf-target .github/skills/ripwire-perf-target && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "ripwire-perf-target" agent skill from https://github.com/redhat-et/ripwire/tree/main/skills/ripwire-perf-target into .github/skills/ripwire-perf-target/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ripwire-perf-target", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add redhat-et/ripwire --skill ripwire-perf-target -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install redhat-et/ripwire ripwire-perf-target --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/redhat-et/ripwire.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/ripwire-perf-target .opencode/skills/ripwire-perf-target && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "ripwire-perf-target" agent skill from https://github.com/redhat-et/ripwire/tree/main/skills/ripwire-perf-target into .opencode/skills/ripwire-perf-target/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "ripwire-perf-target", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
ripwire-perf-targetA MEASURED performance problem: start from a benchmark, flame graph, perf sample or profiler run, locate the hot symbol the profile names, test structural hypotheses (memory-bound → cache-line data…
Ripwire Perf Target is an agent skill from redhat-et/ripwire. A MEASURED performance problem: start from a benchmark, flame graph, perf sample or profiler run, locate the hot symbol the profile names, test structural hypotheses (memory-bound → cache-line data layout). Static metrics are change-risk signals, not runtime heat. Inspect only the symbols the profile names.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Performance optimization. The repository describes itself as: The ripgrep of AI context: a zero-dependency C++23 CLI + MCP server for coding agents. Find what you want without reading the repo, then check you built what you meant — blast… The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 60dd3b3. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Ripwire Perf Target loads about 2.4k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 1,222 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, ReadAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from redhat-et/ripwire at commit 60dd3b3, republished under its Apache-2.0 licence (© redhat-et). 1,222 words, ~2,353 tokens.
.claude/skills/ripwire-perf-target/SKILL.md (or your agent's skills folder).Nearest neighbours: • Repo-wide quality/health sweep (not perf-specific) → ripwire-fresh-eyes (also uses --hotspots). • Finding a specific BUG, not a slow path → ripwire-find-bug.
Trigger: a representative benchmark, flame graph, trace, or profiler has identified a slow operation, file, stack, or symbol and you need to understand where a safe optimization belongs. If you have no measurement yet, create the smallest representative benchmark/profile first; ripwire cannot infer runtime cost from source shape.
<dir> = repo root.
Pin the measured evidence — record the workload, baseline, profiler/trace result, and the symbol or subsystem it implicates. Keep the same workload for the after measurement.
Navigate the measured surface — ripwire <dir> --for="measured operation or symbol" --detail=3, then
--callers=SYM, --callees=SYM, or --around=SYM as needed. This turns runtime evidence into a bounded
source-reading set without pretending the graph measured execution.
Maintenance/change-risk context — ripwire <dir> --hotspots --legend=compact
Output: <hotspots> ranked by score = churn × ccx (churn = git commit frequency over
12mo; ccx = cognitive complexity). The top= attribute names the highest-complexity
function in each file. High-score files are frequently changed and structurally complex: useful evidence
about optimization risk and validation scope, but structural evidence, not runtime heat.
A slowdown/regression traced to a specific change, not an all-time read — use the recent-churn
lens: ripwire <dir> --hotspots --legend=compact --since="2 weeks ago" (or --since=HEAD~20 for a deterministic rev)
ranks by commits after that point instead of all-history, which is the right lens for "this got slower
after X" rather than a static hot-function scan.
Static dependency + shape hypotheses — ripwire <dir> --metrics --legend=compact --top-k=50
Output: the ranked map with in= (fan-in), cx=/ccx= (complexity), cbo= (coupling
between objects — how many other types this symbol touches), loc= (body size), and
nest= (max nesting depth) on each symbol. in= is static dependency fan-in, not execution frequency.
Use cbo/nest/loc to form code-reading hypotheses inside the already-measured surface: coupling may
constrain a rewrite, nesting may hide branchy or quadratic work, and large bodies may combine unrelated
work. Read nest= with its profile, never alone — it is a max, so humps= (regions reaching the
nesting bar) and deep= (lines inside them, a floor) on the same row are what separate a body that
sustains depth from a long flat one whose max is a single inner loop; deep/loc is the discriminator
(→ ripwire-quality-bar). Confirm every suspected bottleneck with the benchmark/profile.
On C-family/C# code, discount a ppalt=-carrying body: cx=/ccx=/nest=/loc=/locals= sum
ALL #else/#ifdef branches, not just the one your build compiles, so a hot function that also happens
to be preprocessor-heavy can look structurally worse than the code path actually executing.
4a2. Join the measured heat onto the static findings — ripwire <dir> --lint --legend=compact --with-profile=REPORT
REPORT is a RIPWIRE_PROFILE build's own stderr report (its #PROF_TSV block, verbatim). Every --lint
finding whose enclosing symbol contains a PROFILE_SCOPE site gains heat_* attributes — the scope's
measured calls, total_ms, and whichever counter columns that run armed (heat_l1d_mpki etc.; an ABSENT
column was not measured, never zero). This is the one-command answer to "which of these cache-* rows are
actually HOT": static shape × PMU weight (SYZYGY's advice mode, Hundt CGO 2006). heat_joined="0" on
the root is honest — no finding sits inside a profiled scope — never an error.
4b. If the profile points at MEMORY, not compute — cheapest first, ripwire <dir> --lint --legend=compact runs the
built-in cache-* pack (8 static data-layout checks, e.g. cache-gather-subscript,
cache-vector-of-indirect, cache-pointer-chase-loop) as part of an ordinary lint pass — no profile
required, so it is worth a look before reaching for the heavier lens below. When a specific struct is
already implicated, --field-affinity[=STRUCT]
When to reach for it. The measurement already implicates a struct-heavy path and the shape of the
evidence says data layout, not algorithm: cache-miss or memory-stall counters dominating the profile,
a loop whose cost does not track its instruction count, a hot/cold field mix (a couple of fields read on
every pass, a dozen touched only on cold paths), or a wide struct threaded through many callers. Bare =
every aggregate in the repo ranked by separation cost; =STRUCT narrows to the one the profile named —
prefer the narrow form, per this skill's stop rule.
Output: per struct, which fields the indexed C/C++/ObjC functions access TOGETHER, diffed against the
declared field order and 64-byte cache-line geometry (Chilimbi's separation weight, PLDI 1999 — cited,
not invented here). Exactly two findings fire, both with a direction defensible in one sentence:
split-line (a co-accessed pair at wt="0.00", i.e. ≥64 bytes apart — no field order can put them
on one line) and straddle (one co-accessed field crossing a line boundary, so every access to that ONE
field touches two lines).
What it does NOT detect — the boundary matters more than the findings, because a layout change made on the wrong evidence is expensive and hard to unwind:
fns= counts distinct indexed functions (counts_floor="1") and w= is a
static call-graph reachability proxy (weighting="fanin-floor") — a struct can top the ranking and
cost nothing because it is constructed once.<function, struct type>. Only dot/arrow syntax counts, so a bare field name inside its own method is
invisible, and a field name declared by two aggregates is REFUSED into amb_skipped= rather than
guessed.sizeof/alignment under templates, virtuals, bases and your target ABI. All geometry is an
LP64 model (model="lp64-approx"); a definition the layout model refuses (modeled="0") contributes
its co-access graph and no geometry finding.for loop's advance as index/chase/mixed/unknown and can flag a
declared field as the traversal's chase pointer (chase="1" loops="N"). It is purely syntactic,
C-family only, and range-for/while/recursion always read unknown (as_unknown=), so a zero there
means "not classified", never "no chases." It ships report-only — it does not move the ranking. This is a HYPOTHESIS GENERATOR, not a measurement — same rule as every static signal on this page.
For runtime truth, go back to the counters: <validate> names the instrumented PROFILE_SCOPE whose
hardware counters would confirm or refute the hypothesis (the PMC backend is src/infra/profilePmc.h —
kpep on macOS, perf_event_open on Linux), bench/bench_field_ab.cpp is the A/B harness, and
docs/FIELDAFFINITY.md records a worked example in which the static hypothesis was refuted under one
access pattern. Confirm on hardware before changing a layout, exactly as with every other item on this
list. Exit is always 0: a report, not a gate.
Expand measured candidates — ripwire <dir> --expand=SYM --legend=compact for the implicated symbols.
Output: full body + callee signatures. Look for inner-loop allocations, redundant work,
or O(N²) patterns that profiler data would confirm.
Re-measure — make one bounded change, rerun the same workload, and report latency/throughput plus any correctness/determinism gate. A structurally attractive refactor with no measured improvement is not a performance win.
Measured baseline and workload; the profiler/trace evidence; the bounded symbol/caller/callee surface; structural hypotheses clearly labeled as non-runtime evidence; the change; and the same after measurement.
© redhat-et, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/ripwire-perf-target of redhat-et/ripwire.
Open the folder on GitHubat commit 60dd3b3
Ripwire Perf Target next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Ripwire Perf Target this skillredhat-et/ripwire | 2.4k | — | ~2.4k | Automated safety check: Notes | Apache-2.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| LLM Torch Profiler Analysissgl-project/sglang | 37k | 2 repos | ~6.4k | Automated safety check: Pass | Apache-2.0 | |
| Pycrazyguitar/pysheeet | 8.2k | — | ~886 | Automated safety check: Pass | MIT | |
| Cmux Debugging Guidemanaflow-ai/cmux | 28k | 1 repos | ~1.1k | Automated safety check: Pass | Custom licence | |
| Electron Heap Snapshot Analysiskeybase/client | 9.3k | — | ~875 | Automated safety check: Pass | BSD-3-Clause |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
sgl-project/sglang
Unified LLM torch-profiler triage skill for sglang, vllm, TensorRT-LLM, and TokenSpeed.
crazyguitar/pysheeet
Comprehensive Python programming reference covering syntax, concurrency, networking, databases, ML/LLM development, and HPC.
manaflow-ai/cmux
Covers debug logging, the Debug menu, profiling rules and runtime pitfalls for working on the cmux macOS terminal app.
keybase/client
Analyzes V8, Chrome and Electron .heapsnapshot files with Node scripts to find memory leaks, detached DOM nodes and the retainer paths that keep objects alive.
ben-manes/caffeine
Runs controlled JMH experiments on the Caffeine cache to find shared contention and hot-path waste, then reviews correctness and returns a reviewable patch.
redhat-et/ripwire
Rules for writing and converting formatted output in ripwire's C++ source with its emit helpers, keeping every printed byte identical to the old printf output.
redhat-et/ripwire
Checks whether a working-tree diff or a pull request is safe to merge: blast radius, tests to run, contract breaks, branch conflicts and stranded work.
redhat-et/ripwire
Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode.
redhat-et/ripwire
Produces a short brief for handing a code subsystem to a teammate or fresh session, using ripwire to rank symbols, expand bodies and surface design docs.
redhat-et/ripwire
Answers questions about a named symbol, such as its callers, what it calls, the path between two symbols or the downstream impact of changing it, using the ripwire CLI.
redhat-et/ripwire
Contributor guide for reading clang optimization remarks while editing ripwire's own C++, deciding between a source change and a build change such as LTO or PGO.
Categories
A MEASURED performance problem: start from a benchmark, flame graph, perf sample or profiler run, locate the hot symbol the profile names, test structural hypotheses (memory-bound → cache-line data…. Ripwire Perf Target is an agent skill from redhat-et/ripwire. A MEASURED performance problem: start from a benchmark, flame graph, perf sample or profiler run, locate the hot symbol the profile names, test structural hypotheses (memory-bound → cache-line data layout).
Ripwire Perf Target fits situations like: tasks that involve Performance optimization.
Run `npx skills add redhat-et/ripwire --skill ripwire-perf-target -a claude-code`. Or copy the skill folder (skills/ripwire-perf-target in redhat-et/ripwire) into .claude/skills/ripwire-perf-target in your project. Claude Code loads it when a task matches its description.
Run `npx skills add redhat-et/ripwire --skill ripwire-perf-target -a codex`. Or copy the skill folder (skills/ripwire-perf-target in redhat-et/ripwire) into .agents/skills/ripwire-perf-target in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add redhat-et/ripwire --skill ripwire-perf-target -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ripwire-perf-target, .gemini/skills/ripwire-perf-target, .github/skills/ripwire-perf-target and .opencode/skills/ripwire-perf-target in your project.
SKILL.md names no scripts, command-line tools or credentials: Ripwire Perf Target is instructions for the agent only. Its frontmatter pre-approves these tools: Bash, Read.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Ripwire Perf Target is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Ripwire Perf Target: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), LLM Torch Profiler Analysis (sgl-project/sglang, 37k stars), Py (crazyguitar/pysheeet, 8.2k stars) and Cmux Debugging Guide (manaflow-ai/cmux, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
redhat-et (a GitHub organization) maintains it in redhat-et/ripwire, which has 2,428 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 9, 2026.
Source: redhat-et/ripwire on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.