Agent skill

Memory Load Check

by simstudioai in simstudioai/sim

Review PRs and diffs for unbounded memory loading, concurrency explosions, oversized payload materialization, and missing pagination or byte caps.

Apache-2.0Auto-check passedBackend & APIs

Install Memory Load Check

skills CLI
$ npx skills add simstudioai/sim --skill memory-load-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install simstudioai/sim memory-load-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/memory-load-check .claude/skills/memory-load-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
memory-load-check
GitHub stars
30k
Token cost
~2.6k tokens
SKILL.md length
1,152 words
Files
1
Skills in repo
40
Repo updated
First seen
Licence
Apache-2.0

At a glance

Review PRs and diffs for unbounded memory loading, concurrency explosions, oversized payload materialization, and missing pagination or byte caps.

  • Works in 7 steps: Identify every changed data source → For each source, write down the maximum… → Trace whether data is processed… → …
  • Reviewing cleanup jobs
  • SKILL.md covers Review Goal, References, Sim Helpers To Prefer and KB Connector File Size Handling, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Memory Load Check is an agent skill from simstudioai/sim. Review PRs and diffs for unbounded memory loading, concurrency explosions, oversized payload materialization, and missing pagination or byte caps. Use when reviewing cleanup jobs, background jobs, data imports/exports, file parsing, API fan-out, workflow execution payloads, large arrays/files, or any change that reads many rows, files, responses, logs, or external API pages into process memory.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Background jobs. The repository describes itself as: Sim is the collaborative workspace to build, deploy, and monitor AI agents and workflows. Used by 100,000+ builders. The licence is Apache-2.0.

When your agent uses it

  • Reviewing cleanup jobs
  • Background jobs
  • Data imports/exports
  • Workflow execution payloads

Example prompts

  • “/memory-load-check”

Requirements

  • Node.js

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Identify every changed data source
  2. For each source, write down the maximum cardinality and maximum bytes. If the code does not enforce one, it is unbounded.
  3. Trace whether data is processed incrementally or accumulated
  4. Check concurrency separately from memory
  5. Verify SQL shape
  6. Verify byte safety
  7. Confirm failure behavior

What it can do on your machine

Read from SKILL.md and the folder at commit b1b084d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • nodejs.org
    • blog.sequinstream.com
    • citusdata.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Memory Load Check loads about 2.6k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 1,152 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from simstudioai/sim at commit b1b084d, republished under its Apache-2.0 licence (© simstudioai). 1,152 words, ~2,589 tokens.

Download SKILL.mdSave it as .claude/skills/memory-load-check/SKILL.md (or your agent's skills folder).
name
memory-load-check
description
Review PRs and diffs for unbounded memory loading, concurrency explosions, oversized payload materialization, and missing pagination or byte caps. Use when reviewing cleanup jobs, background jobs, data imports/exports, file parsing, API fan-out, workflow execution payloads, large arrays/files, or any change that reads many rows, files, responses, logs, or external API pages into process memory.

Memory Load Check

Use this skill when a PR or diff could load unbounded data into a Node/Bun process, especially in cron routes, background tasks, API routes, workflow execution, file parsing, cleanup jobs, migrations, import/export flows, and external API integrations.

Review Goal

Prove each changed path has explicit bounds for:

  • rows held in memory
  • bytes held in memory
  • concurrent promises, DB queries, HTTP calls, storage operations, and jobs
  • number of pages, batches, chunks, retries, and retained intermediate objects

If any bound depends only on current production size or "probably small" data, treat it as a finding.

References

Read these when doing a deeper pass:

Sim Helpers To Prefer

  • apps/sim/lib/cleanup/batch-delete.ts
    • chunkedBatchDelete: bounded SELECT -> optional side effect -> DELETE loop.
    • batchDeleteByWorkspaceAndTimestamp: common workspace/timestamp cleanup wrapper.
    • selectRowsByIdChunks: chunks large ID sets and enforces an overall row cap.
  • chunkArray from @sim/utils/helpers: use only after the input set itself is already bounded.
  • apps/sim/lib/core/utils/stream-limits.ts
    • PayloadSizeLimitError
    • assertKnownSizeWithinLimit
    • assertContentLengthWithinLimit
    • readStreamToBufferWithLimit
    • readNodeStreamToBufferWithLimit
    • readResponseToBufferWithLimit
    • readResponseTextWithLimit
  • Cleanup dispatcher pattern in apps/sim/lib/billing/cleanup-dispatcher.ts
    • page active workspaces with WHERE id > afterId ORDER BY id LIMIT N
    • dispatch concrete chunks (workspaceIds, retention, label) instead of one giant scope
    • prefer Trigger.dev queue/concurrency keys when available
    • execute inline fallback chunks sequentially, not with unbounded Promise.all
  • File parse pattern in apps/sim/lib/internal/file/parser.ts and apps/sim/lib/uploads/utils/fetch-external-url.server.ts
    • cap downloads and parsed output separately
    • preserve partial results when a later item exceeds the cap
    • never read untrusted response bodies without a byte cap
  • KB connector file downloads in apps/sim/connectors/utils.ts
    • CONNECTOR_MAX_FILE_BYTES: shared per-file cap (aligned with the manual KB upload limit)
    • readBodyWithLimit: stream a download body to a Buffer with a hard byte cap (null on overflow)
    • stubOrSkipBySize: listing-time skip when the reported size exceeds the cap
    • markSkipped / sizeLimitSkipReason: surface oversized files as failed (skipped) KB rows
    • ConnectorFileTooLargeError: thrown mid-download when the listing under-reported size
  • Large workflow value payloads
    • prefer durable references/manifests over inlining large arrays or files
    • materialize refs only behind an explicit byte budget

KB Connector File Size Handling

The connector size pattern in apps/sim/connectors/utils.ts (CONNECTOR_MAX_FILE_BYTES + readBodyWithLimit + stubOrSkipBySize/markSkipped) exists for one risk: a knowledge-base connector downloading arbitrary, user-controlled file bytes that the source does not hard-cap. Apply it by that risk, not by the connector's name.

Use the pattern when the connector downloads file content via a stream/download_url where the user controls the size:

  • file-storage connectors: Dropbox, OneDrive, SharePoint, Google Drive, S3, GitHub, GitLab, Azure DevOps
  • any connector that fetches a file via a download URL even if it is not a "storage" service (e.g. the Zoom transcript .vtt)

For those, require all three:

  • stream the body with readBodyWithLimit(resp, CONNECTOR_MAX_FILE_BYTES) — never raw response.text()/response.arrayBuffer()
  • skip oversize at listing (stubOrSkipBySize with the reported size) and again at fetch time (overflow -> markSkipped), since the listing size can be missing or under-reported
  • never drop/truncate silently — oversized files become content-less failed rows carrying skippedReason, so they stay visible in the KB UI instead of vanishing from the index

Skip the pattern when the source already bounds the payload:

  • pure API/structured-data connectors (Jira, Linear, Sentry, Slack, Zendesk, Gmail, ...) — paginated JSON/text; apply normal pagination + concurrency bounds instead of a per-file byte cap
  • native-document connectors whose platform caps each document — a 100 MB cap can never fire there

Some connectors also budget the response body (google-docs MAX_DOCS_RESPONSE_BYTES, google-sheets MAX_CONTENT_BYTES, a remaining-bytes budget in notion); Confluence attachments use the full file pattern. Follow the connector's existing approach rather than adding a cap to every response.json().

Litmus test: "Can a user make this one fetch arbitrarily large, with nothing upstream stopping it?" Yes -> use the pattern. No (platform hard-cap, or already paginated) -> a per-file byte cap adds noise, not safety. Borderline: a user-configured/self-hosted endpoint with no platform cap (e.g. Obsidian) — bound it only if the content is genuinely unbounded.

Show full SKILL.md (529 more words)Show less

Review Workflow

  1. Identify every changed data source:
    • database queries
    • storage lists/downloads/uploads
    • external API pagination
    • file reads and HTTP responses
    • workflow logs, snapshots, payloads, arrays, and manifests
    • queues, cron routes, and background jobs
  2. For each source, write down the maximum cardinality and maximum bytes. If the code does not enforce one, it is unbounded.
  3. Trace whether data is processed incrementally or accumulated:
    • arrays from select, findMany, Promise.all, map, filter, flatMap
    • maps/sets keyed by all users, workspaces, executions, files, or rows
    • Buffer.concat, response.arrayBuffer(), response.text(), JSON.stringify, JSON.parse
    • queues of promises or job payloads built before dispatch
  4. Check concurrency separately from memory:
    • no Promise.all(items.map(...)) unless items is already small and bounded
    • use chunks, sequential loops, queue concurrency, or a concurrency limiter
    • align concurrency with DB pool size, storage/API limits, and task queue semantics
  5. Verify SQL shape:
    • every bulk query has LIMIT
    • large pagination uses cursor/keyset style (id > afterId, timestamps plus unique ID), not deep OFFSET
    • IN (...) lists are chunked
    • side-effect rows selected before delete have per-batch and per-run caps
  6. Verify byte safety:
    • check Content-Length when available
    • stream with cumulative byte accounting
    • cap both input bytes and expanded output bytes
    • reject or reference oversized values before serializing large JSON responses
  7. Confirm failure behavior:
    • exceeding a cap should stop before loading more data
    • partial successful work should be preserved when the API contract expects it
    • retries should not duplicate huge in-memory state
    • cleanup jobs should make progress over future runs instead of widening one run

Red Flags

  • loads all active workspaces, users, executions, logs, files, messages, or subscriptions before filtering
  • builds a full Map or Set for a platform-wide scope
  • uses Promise.all over rows from an unbounded query
  • fetches all pages from an external API before processing
  • reads an entire file, HTTP response, or stream without a max byte budget
  • checks size only after Buffer.concat, arrayBuffer, text, JSON.parse, or parse expansion
  • a KB connector silently drops or truncates an oversized file instead of recording it as a failed (skipped) row
  • chunks only after loading the complete dataset
  • paginates with unbounded/deep OFFSET on a mutable or large table
  • creates one queue job per row without batching or a queue-level concurrency key
  • accumulates per-row errors/results with no maximum
  • adds a cache, singleton, or module-level collection without eviction or size limits

Preferred Fixes

  • Move filters into SQL/API requests and select only needed columns.
  • Replace full-table loads with cursor/keyset pagination and a deterministic order.
  • Process one page/batch at a time; do not keep previous pages unless needed.
  • Add per-batch and per-run row caps so long backlogs drain across repeated jobs.
  • Split large ID lists with selectRowsByIdChunks or chunkArray after bounding the source.
  • Use chunkedBatchDelete for cleanup loops with row side effects.
  • Use stream-limit helpers for file/HTTP/body reads.
  • Store large workflow values as refs/manifests and materialize only within a caller budget.
  • Replace unbounded Promise.all with sequential chunk loops, queue concurrency, or a small limiter.
  • Include tests that prove caps stop work early and partial results or progress are preserved.

Findings Format

Lead with concrete findings, ordered by risk:

markdown
## Findings

- **P1 Unbounded workspace load in cleanup dispatch** (`path/to/file.ts`)
  The new path calls `select().from(workspace)` without a limit, then builds maps for every row before dispatch. In production this scales with all active workspaces and can exhaust the app process. Page by `workspace.id` with a fixed limit and dispatch bounded chunks.

## Good Signals

- Uses `readResponseToBufferWithLimit` for external downloads.
- Inline fallback processes chunks sequentially.

## Residual Risk

- The row cap is explicit, but no test currently proves the loop stops at the cap.

Only say "good to go" when every changed source has explicit row, byte, and concurrency bounds or the boundedness is proven by a stable invariant.

© simstudioai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/memory-load-check of simstudioai/sim.

Open the folder on GitHubat commit b1b084d

Compare with similar skills

Memory Load Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Memory Load Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Memory Load Check this skillsimstudioai/sim30k—~2.6kAutomated safety check: PassApache-2.0
Trigger.dev Configurationpapermark/papermark9.2k—~1.2kAutomated safety check: PassCustom licence
FoundatioFoundatioFx/Foundatio2.1k—~3.9kAutomated safety check: PassApache-2.0
Laravel SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT
Trigger.dev Realtimepapermark/papermark9.2k—~1.7kAutomated safety check: PassCustom licence
NubaseOtterMind/Nubase623—~2.2kAutomated safety check: NotesApache-2.0

Similar skills

  • Trigger.dev Configuration

    papermark/papermark

    Configures Trigger.dev projects through trigger.config.ts, with build extensions for Prisma, Playwright, Puppeteer, FFmpeg, Python and system packages.

    9.2k GitHub stars~1.2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Foundatio

    FoundatioFx/Foundatio

    A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.

    2.1k GitHub stars~3.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Laravel Specialist

    Jeffallan/claude-skills

    Builds Laravel 10+ applications with Eloquent models, Sanctum authentication, Horizon queues, API resources and Livewire components, tested with Pest or PHPUnit.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    Backend & APIsAuto-check passed
  • Trigger.dev Realtime

    papermark/papermark

    Shows how to subscribe to Trigger.dev task runs from the backend and from React for progress indicators, live dashboards, AI response streams and approval waits.

    9.2k GitHub stars~1.7k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Nubase

    OtterMind/Nubase

    A skill your agent uses when the user mentions Nubase broadly, wants a backend for an AI-generated app, or needs to deploy/publish generated code online — across Database, Auth, Storage, Assets…

    623 GitHub stars~2.2k tokensUpdated 11 days ago
    Backend & APIsAuto-check: notes
  • AI Model Nodejs

    TencentCloudBase/CloudBase-AI-Toolkit

    A skill your agent uses for Node.js backend AI via @cloudbase/node-sdk (=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration.

    1.1k GitHub starsUsed in 2 repos~5k tokens
    Backend & APIsAuto-check passed

More from simstudioai/sim

All 40 skills in this repo
  • Sim Helm

    simstudioai/sim

    Install, upgrade, and operate the Sim Helm chart on Kubernetes.

    30k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Add Column Type

    simstudioai/sim

    Add a new table column type to Sim — registry entry, icon, storage shape, coercion, and the behavioral hooks the grid and API read.

    30k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Add Enrichment

    simstudioai/sim

    Add a code-defined table enrichment (registry entry) under apps/sim/enrichments/ backed by an ordered provider cascade, ensuring every provider tool it calls has hosted-key support.

    30k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Add Hosted Key

    simstudioai/sim

    Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own.

    30k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Add Managed CLI

    simstudioai/sim

    Add or upgrade a curated, immutable managed CLI for Sim Function sandboxes, including client-safe catalog metadata, a pinned server-only installation recipe, checksum and executable verification…

    30k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Add Selector

    simstudioai/sim

    Add or update a Sim dynamic selector using the shared manifest, server attachment, and selectors.execute path.

    30k GitHub stars~1.7k tokensUpdated today
    Auto-check passed

Categories

Questions about Memory Load Check

What does Memory Load Check do?

Review PRs and diffs for unbounded memory loading, concurrency explosions, oversized payload materialization, and missing pagination or byte caps. Memory Load Check is an agent skill from simstudioai/sim. Review PRs and diffs for unbounded memory loading, concurrency explosions, oversized payload materialization, and missing pagination or byte caps.

When should I use Memory Load Check?

Memory Load Check fits situations like: reviewing cleanup jobs; background jobs; data imports/exports; workflow execution payloads.

How do I install Memory Load Check in Claude Code?

Run `npx skills add simstudioai/sim --skill memory-load-check -a claude-code`. Or copy the skill folder (.agents/skills/memory-load-check in simstudioai/sim) into .claude/skills/memory-load-check in your project. Claude Code loads it when a task matches its description.

How do I install Memory Load Check in Codex?

Run `npx skills add simstudioai/sim --skill memory-load-check -a codex`. Or copy the skill folder (.agents/skills/memory-load-check in simstudioai/sim) into .agents/skills/memory-load-check in your project. Codex loads it when a task matches its description.

Can I use Memory Load Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add simstudioai/sim --skill memory-load-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/memory-load-check, .gemini/skills/memory-load-check, .github/skills/memory-load-check and .opencode/skills/memory-load-check in your project.

What does Memory Load Check need to run?

SKILL.md names no scripts, command-line tools or credentials: Memory Load Check is instructions for the agent only. Our summary lists: Node.js.

Does Memory Load Check access the network?

SKILL.md names 3 domains. As links in the text: nodejs.org, blog.sequinstream.com and citusdata.com. This is read from the text; nothing was executed.

Is Memory Load Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Memory Load Check use?

Memory Load Check is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Memory Load Check use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Memory Load Check?

Skills that share tags, products or a category with Memory Load Check: Trigger.dev Configuration (papermark/papermark, 9.2k stars), Foundatio (FoundatioFx/Foundatio, 2.1k stars), Laravel Specialist (Jeffallan/claude-skills, 12k stars) and Trigger.dev Realtime (papermark/papermark, 9.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Memory Load Check?

simstudioai (a GitHub organization) maintains it in simstudioai/sim, which has 29,792 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 9, 2026.

Source: simstudioai/sim on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.