skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
nishilbhave/codeprobe105 installs

codeprobe-performance

Scans code for performance and scalability issues — N+1 queries, missing indexes, unbounded queries, memory inefficiencies, caching gaps, algorithmic complexity, concurrency bugs, and frontend performance problems. Generates severity-scored findings with copy-pasteable fix prompts. Trigger phrases: "performance audit", "performance check", "N+1 detection", "query optimization", "slow code", "performance review".

How do I install this agent skill?

npx skills add https://github.com/nishilbhave/codeprobe --skill codeprobe-performance
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    The skill is designed to audit source code for performance bottlenecks, concurrency issues, and scalability gaps. While the logic is functionally focused, it carries a low risk of indirect prompt injection because it ingests untrusted source code and has access to powerful system tools like Bash.

  • Socketpass

    No alerts

  • Snykpass

    Risk: LOW · No issues

What does this agent skill do?

Standalone Mode

If invoked directly (not via the orchestrator), you must first:

  1. Read ../codeprobe/shared-preamble.md (resolve relative to this SKILL.md's location — the sibling codeprobe skill directory — not the user's project) for the output contract, execution modes, and constraints.
  2. Load applicable reference files from ../codeprobe/references/ (same resolution) based on the project's tech stack.
  3. Default to full mode unless the user specifies otherwise.

Performance & Scalability Auditor

Domain Scope

This sub-skill detects performance and scalability issues across these categories:

  1. N+1 Queries — Lazy-loading relationships inside loops
  2. Missing Indexes — WHERE/ORDER BY on non-indexed columns
  3. Unbounded Queries — Model::all() without pagination/limit
  4. Memory — Loading entire files into memory, array accumulation in loops
  5. Caching — Repeated identical queries, missing TTL, stale cache after writes
  6. Algorithmic Efficiency — O(n^2) in hot paths, nested loops, sorting in loops
  7. Concurrency — Race conditions, non-idempotent queue jobs, shared mutable state
  8. Frontend Performance — Unnecessary re-renders, bundle size, missing lazy loading

What It Does NOT Flag

  • Premature optimization in non-hot-path code — proportional design matters. A utility function called once at startup doesn't need the same optimization as a request handler.
  • Development-only debug queries — queries in seeders, dev-only commands, or debug endpoints.
  • Batch processing scripts — scripts intentionally designed to process everything (migrations, data backfills) where unbounded queries may be appropriate.
  • O(n^2) on small bounded collections (<100 items) — nested loops on small known-size arrays are fine.
  • Frontend SSR/build-time code — server components and build scripts have different performance profiles than client-side code.

Detection Instructions

N+1 Queries

ID PrefixWhat to DetectHow to DetectSeverity
PERFEloquent relationship access inside loop without eager loadingSearch for foreach/for loops iterating over a collection, then accessing a relationship property (e.g., $order->items, $user->profile) inside the loop body. Check whether the query that produced the collection includes with() or load() for that relationship.Major
PERFAny ORM lazy-loading inside iterationLook for patterns where a database query is implicitly triggered inside a loop: Django querysets accessed per-iteration, SQLAlchemy lazy loads, Prisma relation access in .map().Major
PERFTemplate/view triggering queriesBlade templates, Jinja2 templates, or React components calling relationship properties that trigger queries during rendering.Major

Missing Indexes

ID PrefixWhat to DetectHow to DetectSeverity
PERFWHERE/ORDER BY on non-indexed columnsCross-reference query conditions (where(), orderBy(), WHERE, ORDER BY) with migration files or schema definitions to check for matching indexes.Major
PERFForeign keys without indexesCheck migration files for foreignId(), foreign(), references() without corresponding index definitions. Most ORMs add these automatically, but raw migrations may miss them.Minor
PERFComposite queries needing compound indexesMultiple where() conditions on different columns in the same query, or where() + orderBy() combinations that would benefit from a compound index.Minor

Unbounded Queries

ID PrefixWhat to DetectHow to DetectSeverity
PERFModel::all() or SELECT * without limitSearch for .all(), ::all(), findAll(), SELECT * FROM without LIMIT, paginate(), take(), or limit().Major
PERFMissing cursor/chunk for large dataset processingOperations that get() or load entire collections when processing large datasets. Should use cursor(), chunk(), lazy(), or equivalent streaming approach.Major

Memory

ID PrefixWhat to DetectHow to DetectSeverity
PERFLoading entire files into memoryfile_get_contents() on user uploads or large files, fs.readFileSync() on variable-size files, Python open().read() without size limits.Major
PERFArray accumulation in loopsArrays that grow inside loops without bounds or cleanup — collecting results in memory that could be streamed or yielded.Minor
PERFLarge collections instead of generatorsReturning full arrays/lists where generators (yield), lazy collections, or iterators would be more memory-efficient for large datasets.Minor

Caching

ID PrefixWhat to DetectHow to DetectSeverity
PERFRepeated identical queries in same requestSame query pattern executed multiple times within a single request/function call without caching the result.Minor
PERFCache without TTLCache::put(), cache.set(), Redis SET without expiration. Data cached forever risks staleness.Minor
PERFCache not invalidated after writesWrite operations (create/update/delete) that don't clear or update related cache entries. Stale cache served after mutation.Major

Algorithmic Efficiency

ID PrefixWhat to DetectHow to DetectSeverity
PERFO(n^2) or worse in hot pathsNested loops iterating over the same or related collections. array_search/in_array/includes() inside loops (linear search in a loop = O(n^2)).Major
PERFSorting inside loopssort(), usort(), array_sort(), .sort() called inside a loop body.Major
PERFHashmap-replaceable linear searchin_array(), .includes(), .indexOf(), list.index() used repeatedly on the same array where building a Set/dict/hashmap first would be O(1) per lookup.Minor

Concurrency

ID PrefixWhat to DetectHow to DetectSeverity
PERFRace conditions in read-modify-writePatterns that read a value, modify it, and write back without locking: incrementing counters, updating balances, toggling flags in concurrent contexts.Critical
PERFQueue jobs without idempotencyQueue/job handlers that don't check for duplicate execution. Jobs that create resources without checking if already created. Missing unique constraints on job-created data.Major
PERFShared mutable state in async contextsGlobal/module-level mutable variables accessed in async handlers, request-scoped data stored in module scope.Major

Frontend Performance

ID PrefixWhat to DetectHow to DetectSeverity
PERFUnnecessary re-rendersMissing React.memo, useMemo, useCallback on expensive computations or components receiving new object/array references on every render. Objects/arrays created inline in JSX props.Minor
PERFLarge bundle importsimport _ from 'lodash' (imports entire library), import moment from 'moment' (large library where date-fns or dayjs suffice), import * as icons from 'icon-library'.Minor
PERFMissing lazy loadingNo React.lazy() / dynamic import() for route-level code splitting. Heavy components loaded eagerly on initial page load.Minor

Optional Script Integration

When scripts/complexity_scorer.py output is available (run by the orchestrator during /codeprobe audit), use it to identify high-complexity functions as performance hot-spot candidates. Functions rated "high" or "very_high" that also appear in hot paths (request handlers, loop bodies, frequently-called utilities) are strong signals for algorithmic efficiency findings.


ID Prefix & Fix Prompt Examples

All findings use the PERF- prefix, numbered sequentially: PERF-001, PERF-002, etc.

Fix Prompt Examples

  • "In OrderController@index (line 22), add ->with('items', 'customer') to the Order::query() call to fix the N+1 problem — currently loading 2 relations lazily inside the Blade loop at orders/index.blade.php:15."
  • "Replace Product::all() at line 30 of CatalogService.php with Product::query()->paginate(25) or Product::cursor() if processing all records. The current query loads all products into memory."
  • "In ReportGenerator@aggregate (lines 45-60), the nested loop iterating $orders inside $customers is O(n*m). Build a lookup hashmap before the outer loop: $ordersByCustomerId = collect($orders)->groupBy('customer_id')."
  • "Replace import _ from 'lodash' at line 3 of src/utils/helpers.ts with specific imports: import debounce from 'lodash/debounce' to reduce bundle size."

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/nishilbhave/codeprobe/codeprobe-performance">View codeprobe-performance on skillZs</a>