Code Review Checklist
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Runs mecatl's offline benchmark and scenario harness to measure, profile with pprof, optimize and prove a performance win with benchstat, then adds a regression benchmark.
$ npx skills add stacklok/mecatl --skill perf-optimization -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install stacklok/mecatl perf-optimization --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/stacklok/mecatl.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/perf-optimization .claude/skills/perf-optimization && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "perf-optimization" agent skill from https://github.com/stacklok/mecatl/tree/main/.claude/skills/perf-optimization into .claude/skills/perf-optimization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "perf-optimization", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/stacklok/mecatl/tree/main/.claude/skills/perf-optimizationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add stacklok/mecatl --skill perf-optimization -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install stacklok/mecatl perf-optimization --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/stacklok/mecatl.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/perf-optimization .agents/skills/perf-optimization && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "perf-optimization" agent skill from https://github.com/stacklok/mecatl/tree/main/.claude/skills/perf-optimization into .agents/skills/perf-optimization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "perf-optimization", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add stacklok/mecatl --skill perf-optimization -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install stacklok/mecatl perf-optimization --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/stacklok/mecatl.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/perf-optimization .cursor/skills/perf-optimization && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "perf-optimization" agent skill from https://github.com/stacklok/mecatl/tree/main/.claude/skills/perf-optimization into .cursor/skills/perf-optimization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "perf-optimization", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/stacklok/mecatl.git --path .claude/skills/perf-optimization--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add stacklok/mecatl --skill perf-optimization -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install stacklok/mecatl perf-optimization --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/stacklok/mecatl.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/perf-optimization .gemini/skills/perf-optimization && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "perf-optimization" agent skill from https://github.com/stacklok/mecatl/tree/main/.claude/skills/perf-optimization into .gemini/skills/perf-optimization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "perf-optimization", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install stacklok/mecatl perf-optimizationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add stacklok/mecatl --skill perf-optimization -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/stacklok/mecatl.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/perf-optimization .github/skills/perf-optimization && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "perf-optimization" agent skill from https://github.com/stacklok/mecatl/tree/main/.claude/skills/perf-optimization into .github/skills/perf-optimization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "perf-optimization", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add stacklok/mecatl --skill perf-optimization -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install stacklok/mecatl perf-optimization --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/stacklok/mecatl.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/perf-optimization .opencode/skills/perf-optimization && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "perf-optimization" agent skill from https://github.com/stacklok/mecatl/tree/main/.claude/skills/perf-optimization into .opencode/skills/perf-optimization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "perf-optimization", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
perf-optimizationRuns mecatl's offline benchmark and scenario harness to measure, profile with pprof, optimize and prove a performance win with benchstat, then adds a regression benchmark.
This skill covers the offline side of mecatl's performance work: measure, profile, optimize, prove, then guard with a regression test. It runs task bench and task perf:scenarios, takes a memory profile into pprof to find the real hotspot, and uses benchstat to run an A/B comparison that proves a change actually helped rather than relying on a hypothesis. Allocation counts are checked before anything else, following an allocs-first gating discipline, and profile-guided optimization (PGO) can be wired in as part of the setup.
The discipline named in the skill includes following the profile rather than a guess, keeping pure-performance changes byte-identical to the behavior they replace, mutation-testing any cache guard that was added, and skipping an abstraction that turns out to be the wrong one rather than forcing it to fit. A playbook reference file carries the detailed steps. For diagnosing a running harness through its live performance MCP server, a separate perf-mcp-interpretation skill applies instead; this one is specific to mecatl's own benchmarks, not general Go profiling.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e731897. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gogitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
mecatl Offline Performance Optimization loads about 2.2k tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 197 tokens; SKILL.md has 963 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from stacklok/mecatl at commit e731897, republished under its Apache-2.0 licence (© stacklok). 963 words, ~2,161 tokens.
.claude/skills/perf-optimization/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.The companion to the regression-tracking design in
docs/perf-tracking.md. This skill
is the offline benchmark/scenario workflow: measure → profile → optimize →
prove → guard. For diagnosing a running harness via the perf MCP server, use
the perf-mcp-interpretation skill instead — different tool, different signals.
task bench — hot-path microbenchmarks (engine/prompt, engine/governance,
engine/agent). BENCHCOUNT default 10. Offline (mockllm + memfs). Not part of
task test. The engine is its own Go module (ADR 0036), so task bench/task fuzz
run these as cd engine && go test … ./prompt/ ./governance/ ./agent/. An ad-hoc
re-run on an engine package must do the same: cd engine && go test -bench=… ./agent/
(an explicit ./engine/agent/ path also resolves via the committed go.work, but the
./... wildcard does not cross the module boundary).task perf:scenarios — five whole-loop scenarios. Four live in
perf/scenarios/ (single-session-long, team-fanout, background-subagents,
compaction-cycle); the fifth (tui-scrollback) lives in cmd/mecatui/ui/, and the
task runs both packages — so go test ./perf/scenarios/ alone gives only four.
BENCHCOUNT default 6. MECATL_PERF_JSON=.scratch/x.json writes the KPI JSON.engine/ packages depend on the active go.work (the committed
workspace wires ./engine in alongside the root) — a GOWORK=off invocation resolves the engine
module standalone and won't see the host repo.allocs/op, bytes/op, goroutine-delta, and cache-hit-rate are deterministic and
portable — these are the real signal. ns/op and rss_* are machine-specific —
treat as advisory shape, never the headline. A perf change is done only when
allocs/op moves in benchstat; a wall-clock-only "win" on a shared machine is noise.
Run the relevant benchmark and confirm it reflects the workload you care about. A
benchmark whose per-iteration setup dwarfs the code under test, or that is
all-miss by construction, will hide a real win. If no benchmark covers the path,
add one first (match the existing bench_test.go style: for b.Loop(), results to a
package-level sink, offline).
Capture an allocation profile on the benchmark and follow it to a file:line:
go test -run='^$' -bench=BenchmarkX -benchmem -memprofile=.scratch/x.mprof -count=3 ./pkg/
go tool pprof -alloc_space -top -nodecount=25 .scratch/x.mprof # bytes
go tool pprof -alloc_objects -top -nodecount=25 .scratch/x.mprof # object count
go tool pprof -list=FuncName .scratch/x.mprof # line-levelSave profiles under .scratch/ (repo rule — never /tmp). Follow the profile to
the real site. The hypothesis is often wrong (see the playbook: the TUI hotspot was
the string join, not SetContent as assumed). Let -list show you the exact lines.
Optimize only what the profile proves is hot. Weigh the win against the real cost: a microsecond saved once per turn is invisible next to an LLM round-trip. The wrong abstraction is worse than the allocation — if the clean seam doesn't exist or the fix adds stateful invalidation surface for a marginal gain, it is a legitimate NO-GO. Say so and skip it rather than forcing it.
go test -run='^$' -bench=BenchmarkX -benchmem -count=10 ./pkg/ > .scratch/before.txt
# ... apply the change ...
go test -run='^$' -bench=BenchmarkX -benchmem -count=10 ./pkg/ > .scratch/after.txt
benchstat .scratch/before.txt .scratch/after.txt # go install golang.org/x/perf/cmd/benchstat@latestallocs/op / B/op must drop with a statistically significant delta. Re-run
task perf:scenarios and confirm the scenario KPI moved in the expected direction.
Update the baseline snapshot in docs/perf-tracking.md.
task test:golden must
stay green with zero golden diffs — you change HOW, never WHAT. Caveat: golden
refresh runs -update first, so a plain go test ./... (no -update) against the
committed goldens is what actually catches a regression; don't rely on the refresh
step to catch a stale serve.cp,
restore with cp — never git checkout, it wipes uncommitted work). A guard that
stays green when the behaviour is broken is worse than none.engine/ symbol trips the api-compat CI gate
(task api:check, ADR 0036/0037) — a failure mode a perf optimizer wouldn't expect. Keep
pure-perf changes byte-identical to the engine's public surface and it never fires; if the
surface legitimately changed, run task api:update and add an engine/CHANGELOG.md entry
classified per engine/COMPATIBILITY.md.b.Loop(); confirm with a
quick profile that setup isn't the dominant allocator.ns/op on a shared machine. Gate on allocs; ns is advisory.Beyond hand-optimizing a hot path, Profile-Guided Optimization lets the compiler optimize from a CPU profile (typically 2–14% CPU — but here sub-1% of wall-clock, since cost is network-dominated: a free set-and-forget win, not a latency feature). The mechanism is already wired:
task pgo:collect builds a PROVISIONAL offline profile under .scratch/pgo/.cmd/mecated/default.pgo is the reserved slot — go build's -pgo=auto applies it
automatically the moment a profile is dropped there (nothing in the build chain
passes -pgo=off)./debug/pprof/profile capture from a running
mecated under load.Full rationale, the per-binary decision, and the production refresh + staleness
process live in perf-tracking.md Phase 4 —
read it before touching PGO.
references/playbook.md — pprof flag cookbook + two
worked examples (a real win and a real NO-GO) showing the discipline end to end.docs/perf-tracking.md — the KPI
design, gating posture, baselines, and the full roadmap.perf-mcp-interpretation skill — the live counterpart (running-harness
diagnosis via the perf MCP server).© stacklok, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in .claude/skills/perf-optimization of stacklok/mecatl.
Open the folder on GitHubat commit e731897
mecatl Offline Performance Optimization next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| mecatl Offline Performance Optimization this skillstacklok/mecatl | 218 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| LLM Torch Profiler Analysissgl-project/sglang | 37k | 2 repos | ~6.4k | Automated safety check: Pass | Apache-2.0 | |
| Pycrazyguitar/pysheeet | 8.2k | — | ~886 | Automated safety check: Pass | MIT | |
| Cmux Debugging Guidemanaflow-ai/cmux | 28k | 1 repos | ~1.1k | Automated safety check: Pass | Custom licence | |
| Electron Heap Snapshot Analysiskeybase/client | 9.3k | — | ~875 | Automated safety check: Pass | BSD-3-Clause |
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
sgl-project/sglang
Unified LLM torch-profiler triage skill for sglang, vllm, TensorRT-LLM, and TokenSpeed.
crazyguitar/pysheeet
Comprehensive Python programming reference covering syntax, concurrency, networking, databases, ML/LLM development, and HPC.
manaflow-ai/cmux
Covers debug logging, the Debug menu, profiling rules and runtime pitfalls for working on the cmux macOS terminal app.
keybase/client
Analyzes V8, Chrome and Electron .heapsnapshot files with Node scripts to find memory leaks, detached DOM nodes and the retainer paths that keep objects alive.
ben-manes/caffeine
Runs controlled JMH experiments on the Caffeine cache to find shared contention and hot-path waste, then reviews correctness and returns a reviewable patch.
stacklok/mecatl
Interviews you about provider, cost, openness and image needs, then designs the models section of a mecatl settings file with aliases, slots and router categories.
stacklok/mecatl
Cuts a tagged mecatl release by dispatching the release-PR workflow, merging the bot's pull request and verifying the tag, images, Helm chart, signed archives and Homebrew formula.
stacklok/mecatl
Designs, validates and writes the learning section of a mecatl settings file, covering mode, sensitivity, reflection budgets and validated or evaluated activation.
stacklok/mecatl
Guides reading mecatl's perf MCP data to find why a running harness is slow, leaking goroutines or growing in memory, using cheap reads before any CPU capture.
stacklok/mecatl
Rebuilds the mecak8s image into the local mecatl-dev Kind cluster and builds mecatui, so you can try in-progress mecatl changes against a real Kubernetes deployment.
stacklok/mecatl
Review completed non-trivial code across four independent axes: Spec, Standards, Test adequacy, and installed Domain specialists.
Categories
Runs mecatl's offline benchmark and scenario harness to measure, profile with pprof, optimize and prove a performance win with benchstat, then adds a regression benchmark. This skill covers the offline side of mecatl's performance work: measure, profile, optimize, prove, then guard with a regression test. It runs task bench and task perf:scenarios, takes a memory profile into pprof to find the real hotspot, and uses benchstat to run an A/B comparison that proves a change actually helped rather than relying on a hypothesis.
mecatl Offline Performance Optimization fits situations like: investigating why a mecatl code path is slow or allocating heavily; pinpointing a hotspot in a Go benchmark with pprof; proving a performance fix with a benchstat A/B comparison; adding a regression benchmark after fixing a performance issue.
Run `npx skills add stacklok/mecatl --skill perf-optimization -a claude-code`. Or copy the skill folder (.claude/skills/perf-optimization in stacklok/mecatl) into .claude/skills/perf-optimization in your project. Claude Code loads it when a task matches its description.
Run `npx skills add stacklok/mecatl --skill perf-optimization -a codex`. Or copy the skill folder (.claude/skills/perf-optimization in stacklok/mecatl) into .agents/skills/perf-optimization in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add stacklok/mecatl --skill perf-optimization -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/perf-optimization, .gemini/skills/perf-optimization, .github/skills/perf-optimization and .opencode/skills/perf-optimization in your project.
Going by SKILL.md and its folder, mecatl Offline Performance Optimization needs the command-line tools its instructions call (go and git). Our summary lists: A checkout of the mecatl repository with its Go benchmark and scenario harness.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
mecatl Offline Performance Optimization is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with mecatl Offline Performance Optimization: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), LLM Torch Profiler Analysis (sgl-project/sglang, 37k stars), Py (crazyguitar/pysheeet, 8.2k stars) and Cmux Debugging Guide (manaflow-ai/cmux, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
stacklok (a GitHub organization) maintains it in stacklok/mecatl, which has 218 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 6, 2026.
Source: stacklok/mecatl on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.