All skills

Use this Skill: https://skilld.dev/gh/garrytan/gstack/review

This session only. Nothing lands on disk.

specialistsperformance.md

≈655 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Performance Specialist Review Checklist

Scope: When SCOPE_BACKEND=true OR SCOPE_FRONTEND=true Output: JSON objects, one finding per line. Schema: {"severity":"CRITICAL|INFORMATIONAL","confidence":N,"path":"file","line":N,"category":"performance","summary":"...","fix":"...","fingerprint":"path:line:performance","specialist":"performance"} Optional: line, fix, fingerprint, evidence, test_stub. If no findings: output NO FINDINGS and nothing else.


Categories

N+1 Queries

  • ActiveRecord/ORM associations traversed in loops without eager loading (.includes, joinedload, include)
  • Database queries inside iteration blocks (each, map, forEach) that could be batched
  • Nested serializers that trigger lazy-loaded associations
  • GraphQL resolvers that query per-field instead of batching (check for DataLoader usage)

Missing Database Indexes

  • New WHERE clauses on columns without indexes (check migration files or schema)
  • New ORDER BY on non-indexed columns
  • Composite queries (WHERE a AND b) without composite indexes
  • Foreign key columns added without indexes

Algorithmic Complexity

  • O(n^2) or worse patterns: nested loops over collections, Array.find inside Array.map
  • Repeated linear searches that could use a hash/map/set lookup
  • String concatenation in loops (use join or StringBuilder)
  • Sorting or filtering large collections multiple times when once would suffice

Bundle Size Impact (Frontend)

  • New production dependencies that are known-heavy (moment.js, lodash full, jquery)
  • Barrel imports (import from 'library') instead of deep imports (import from 'library/specific')
  • Large static assets (images, fonts) committed without optimization
  • Missing code splitting for route-level chunks

Rendering Performance (Frontend)

  • Fetch waterfalls: sequential API calls that could be parallel (Promise.all)
  • Unnecessary re-renders from unstable references (new objects/arrays in render)
  • Missing React.memo, useMemo, or useCallback on expensive computations
  • Layout thrashing from reading then writing DOM properties in loops
  • Missing loading="lazy" on below-fold images

Missing Pagination

  • List endpoints that return unbounded results (no LIMIT, no pagination params)
  • Database queries without LIMIT that grow with data volume
  • API responses that embed full nested objects instead of IDs with expansion

Blocking in Async Contexts

  • Synchronous I/O (file reads, subprocess, HTTP requests) inside async functions
  • time.sleep() / Thread.sleep() inside event-loop-based handlers
  • CPU-intensive computation blocking the main thread without worker offload

Source: SKILL.md on GitHub

2 warningstoday5 checks · Risk SAFE
  • Gen Agent Trust Hubtoday

    A comprehensive code review skill for the gstack ecosystem that automates PR analysis, security auditing, and design reviews using specialist subagents and local helper tools.

  • Sockettoday

    No alerts

  • Snyktoday

    Risk: LOW · No issues

  • Runlayer6mo

    2/2 files flagged

  • ZeroLeaks5mo

    2 findings · Score: 54/100

Signed by skilld at dcaea52. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 15 hours ago.

Activeupdated 2 days ago
What it can do
Runs commands Reads files Edits files Network
preamble-tier
4
version
1.0.0
All 9 allowed tools
BashReadEditWriteGrepGlobAgentAskUserQuestionWebSearch
Other metadata
triggers
[
  "review this pr",
  "code review",
  "check my diff",
  "pre-landing review"
]

README badge

README badge for garrytan/gstack/review

Analyzes diffs against the base branch for SQL safety, LLM trust boundary violations, conditional side effects, and other structural issues. Use when reviewing pull requests before landing or merging code changes. Runs preamble checks and proactively suggests review when appropriate.

Generated from the current SKILL.md.

What does this skill check for in a diff?
The skill analyzes diffs against the base branch for SQL safety, LLM trust boundary violations, conditional side effects, and other structural issues.
When should I invoke this skill?
Use it when asked to 'review this PR', 'code review', 'pre-landing review', or 'check my diff'. The skill can also be proactively suggested when you are about to merge or land code changes.
Does this skill work in plan mode?
Yes. In plan mode, the skill takes precedence over generic plan mode behavior and follows its workflow step by step. AskUserQuestion calls satisfy plan mode's end-of-turn requirement.
What tools does this skill use?
The skill uses Bash, Read, Edit, Write, Grep, Glob, Agent, AskUserQuestion, and WebSearch to analyze and review code changes.

Generated from the current SKILL.md. These answers refresh after source changes.