Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Analyze Firefox performance profiles using the profiler-cli CLI tool.
$ npx skills add SAP/project-foxhound --skill profiler-analysis -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install SAP/project-foxhound profiler-analysis --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/SAP/project-foxhound.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/profiler-analysis .claude/skills/profiler-analysis && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "profiler-analysis" agent skill from https://github.com/SAP/project-foxhound/tree/main/.agents/skills/profiler-analysis into .claude/skills/profiler-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "profiler-analysis", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/SAP/project-foxhound/tree/main/.agents/skills/profiler-analysisType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add SAP/project-foxhound --skill profiler-analysis -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install SAP/project-foxhound profiler-analysis --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SAP/project-foxhound.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/profiler-analysis .agents/skills/profiler-analysis && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "profiler-analysis" agent skill from https://github.com/SAP/project-foxhound/tree/main/.agents/skills/profiler-analysis into .agents/skills/profiler-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "profiler-analysis", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SAP/project-foxhound --skill profiler-analysis -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install SAP/project-foxhound profiler-analysis --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SAP/project-foxhound.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/profiler-analysis .cursor/skills/profiler-analysis && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "profiler-analysis" agent skill from https://github.com/SAP/project-foxhound/tree/main/.agents/skills/profiler-analysis into .cursor/skills/profiler-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "profiler-analysis", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/SAP/project-foxhound.git --path .agents/skills/profiler-analysis--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add SAP/project-foxhound --skill profiler-analysis -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install SAP/project-foxhound profiler-analysis --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SAP/project-foxhound.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/profiler-analysis .gemini/skills/profiler-analysis && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "profiler-analysis" agent skill from https://github.com/SAP/project-foxhound/tree/main/.agents/skills/profiler-analysis into .gemini/skills/profiler-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "profiler-analysis", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install SAP/project-foxhound profiler-analysisInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add SAP/project-foxhound --skill profiler-analysis -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/SAP/project-foxhound.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/profiler-analysis .github/skills/profiler-analysis && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "profiler-analysis" agent skill from https://github.com/SAP/project-foxhound/tree/main/.agents/skills/profiler-analysis into .github/skills/profiler-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "profiler-analysis", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SAP/project-foxhound --skill profiler-analysis -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install SAP/project-foxhound profiler-analysis --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SAP/project-foxhound.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/profiler-analysis .opencode/skills/profiler-analysis && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "profiler-analysis" agent skill from https://github.com/SAP/project-foxhound/tree/main/.agents/skills/profiler-analysis into .opencode/skills/profiler-analysis/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "profiler-analysis", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
profiler-analysisAnalyze Firefox performance profiles using the profiler-cli CLI tool.
Profiler Analysis is an agent skill from SAP/project-foxhound, published by the product's own GitHub organization. Analyze Firefox performance profiles using the profiler-cli CLI tool. Trigger when given a profiler.firefox.com or share.firefox.dev link, a local profile path, or when the user wants to investigate an issue in a Firefox profile. Always use this skill instead of WebFetch for Firefox profiler URLs; WebFetch only retrieves the profiler UI's HTML shell and cannot access profile data, whereas profiler-cli downloads and parses the actual profile into a local daemon that supports structured queries over stacks…
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 19 other files, including reference files (for example `references/firefox-macos-startup-font-initialization-cli.md`, `references/firefox-macos-startup-font-initialization.md` and `references/macos-extensions-hang-infinite-recursion-cli.md`).
It sits in Development, covering Performance optimization. The repository describes itself as: A web browser with dynamic data-flow tracking enabled in the Javascript engine and DOM, based on Mozilla Firefox (https://github.com/mozilla-firefox/firefox). It can be used to… The licence is GPL-3.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9dcb850. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(profiler-cli:*)Bash(searchfox-cli:*)Bash(jq:*)ReadGrepGlobFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Profiler Analysis loads about 1.1k tokens when it runs, and up to ~37k if it reads all its reference files. Until then it costs about 140 tokens; SKILL.md has 477 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from SAP/project-foxhound at commit 9dcb850, republished under its GPL-3.0 licence (© SAP). 477 words, ~1,119 tokens.
.claude/skills/profiler-analysis/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.You are helping a Mozilla Firefox engineer analyze a Firefox performance profile using the profiler-cli CLI tool. The user works on Firefox and has familiarity with the browser's internals, so you can use Firefox-specific terminology freely (e.g. Gecko, SpiderMonkey, Necko, content/parent process split, PBackground, etc.) without explaining it.
When invoked:
profiler-cli guide first and read the entire output. It is approximately 400 lines. The Bash tool may silently truncate long output, causing you to miss the command reference and analysis patterns that appear later in the guide, so read all of it before proceeding.$ARGUMENTS contains a profile path or URL, load it with profiler-cli load.If the URL is a profiler.firefox.com/from-file/... or profiler.firefox.com/from-browser/... link, stop and tell the user it cannot be loaded. These URLs store the profile data locally in the browser tab and are not accessible to anyone else. Ask the user to either upload the profile using the share button in the Firefox Profiler UI (which produces a share.firefox.dev or profiler.firefox.com/public/... link), or pass a local file path to the profile JSON directly.
Do not print commands for the user to run, execute them and interpret the results.
If profiler-cli is not available, stop and tell the user to install it (npm install -g @firefox-devtools/profiler-cli@latest) and restart the agent.
Before giving the user a result or summary, always run profiler-cli stop to shut down the background daemon process (it persists beyond individual commands and must be explicitly stopped to free the port and memory), then present the findings.
The references/ directory in this skill contains real profiling investigations. Each scenario has two files:
macos-extensions-hang-infinite-recursion.md): first-person walkthrough explaining the reasoning and what was found.macos-extensions-hang-infinite-recursion-cli.md): step-by-step profiler-cli commands with real output and annotations. These are the most useful for calibrating your approach.Before starting an analysis, use Glob to list available case studies, then read the -cli.md file that most closely matches the current scenario:
firefox-macos-startup-font-initialization-cli.mdmacos-extensions-hang-infinite-recursion-cli.mdmacos-ipc-blob-url-accumulation-cli.mdsimpleperf-non-rooted-firefox-startup-cli.mdsimpleperf-non-rooted-fenix-sync-history-fetch-cli.mdresource-usage-linux-fat-aar-build-cli.mdmacos-network-pr-bad-descriptor-error-cli.mdmacos-network-nss-doh-deadlock-cli.mdwindows-broken-stackwalk-jpeg-avx2-cli.mdIf the scenario is unclear, read firefox-macos-startup-font-initialization-cli.md as a general-purpose baseline.
The list above is for calibration only. The actual problem may be novel or not covered by any case study. Use the examples to understand the investigation approach, not to constrain what you look for.
© SAP, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 18 other files (references) in .agents/skills/profiler-analysis of SAP/project-foxhound.
Open the folder on GitHubat commit 9dcb850
We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in SAP/project-foxhound, which our catalogue first saw on October 7, 2026.
Profiler Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Profiler Analysis this skillSAP/project-foxhound | 180 | 1 repos | ~1.1k | Automated safety check: Pass | GPL-3.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| LLM Torch Profiler Analysissgl-project/sglang | 37k | 2 repos | ~6.4k | Automated safety check: Pass | Apache-2.0 | |
| Pycrazyguitar/pysheeet | 8.2k | — | ~886 | Automated safety check: Pass | MIT | |
| Cmux Debugging Guidemanaflow-ai/cmux | 28k | 1 repos | ~1.1k | Automated safety check: Pass | Custom licence | |
| Electron Heap Snapshot Analysiskeybase/client | 9.3k | — | ~875 | Automated safety check: Pass | BSD-3-Clause |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
sgl-project/sglang
Unified LLM torch-profiler triage skill for sglang, vllm, TensorRT-LLM, and TokenSpeed.
crazyguitar/pysheeet
Comprehensive Python programming reference covering syntax, concurrency, networking, databases, ML/LLM development, and HPC.
manaflow-ai/cmux
Covers debug logging, the Debug menu, profiling rules and runtime pitfalls for working on the cmux macOS terminal app.
keybase/client
Analyzes V8, Chrome and Electron .heapsnapshot files with Node scripts to find memory leaks, detached DOM nodes and the retainer paths that keep objects alive.
ben-manes/caffeine
Runs controlled JMH experiments on the Caffeine cache to find shared contention and hot-path waste, then reviews correctness and returns a reviewable patch.
SAP/project-foxhound
Performs an accessibility code review of a local diff or Phabricator revision in the style of the Firefox accessibility team.
SAP/project-foxhound
Structured performance opportunity investigation for SpiderMonkey (the Firefox JavaScript engine).
SAP/project-foxhound
File a Bugzilla bug for Firefox/Gecko work, or draft a bug summary and description.
SAP/project-foxhound
Map relationships between a web spec section, its Firefox implementation code, and Web Platform Tests.
SAP/project-foxhound
Manage Redash queries and dashboards on Mozilla's STMO (sql.telemetry.mozilla.org) using stmo-cli.
SAP/project-foxhound
Guide for creating new Android gradle modules in the android-components project.
Categories
Analyze Firefox performance profiles using the profiler-cli CLI tool. Profiler Analysis is an agent skill from SAP/project-foxhound, published by the product's own GitHub organization. Analyze Firefox performance profiles using the profiler-cli CLI tool.
Profiler Analysis fits situations like: given a profiler.firefox.com; share.firefox.dev link; A local profile path; the user wants to investigate an issue in a Firefox profile.
Run `npx skills add SAP/project-foxhound --skill profiler-analysis -a claude-code`. Or copy the skill folder (.agents/skills/profiler-analysis in SAP/project-foxhound) into .claude/skills/profiler-analysis in your project. Claude Code loads it when a task matches its description.
Run `npx skills add SAP/project-foxhound --skill profiler-analysis -a codex`. Or copy the skill folder (.agents/skills/profiler-analysis in SAP/project-foxhound) into .agents/skills/profiler-analysis in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SAP/project-foxhound --skill profiler-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/profiler-analysis, .gemini/skills/profiler-analysis, .github/skills/profiler-analysis and .opencode/skills/profiler-analysis in your project.
Going by SKILL.md and its folder, Profiler Analysis needs the command-line tools its instructions call (npm). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash(profiler-cli:*), Bash(searchfox-cli:*), Bash(jq:*), Read, Grep, Glob.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Profiler Analysis is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 36k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Profiler Analysis: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), LLM Torch Profiler Analysis (sgl-project/sglang, 37k stars), Py (crazyguitar/pysheeet, 8.2k stars) and Cmux Debugging Guide (manaflow-ai/cmux, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
SAP (a GitHub organization, an official publisher) maintains it in SAP/project-foxhound, which has 180 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 6, 2026.
Source: SAP/project-foxhound on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.