performance-review
Detects time and space complexity hotspots via AST scan Skill: performance-review Owner: athola Summary: Detects time and space complexity hotspots via AST scan Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:19:06.422Z | user Release v1.9.19 v1.9.17 | 2026-07-30T05:39:18.228Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:56:01.066Z | user Release v1.9.16 v1.9.14 | 2026-06-30T18:04:19.616Z | user Release v1.9.14 v1.9.13 | 2026-06-27T16:22:19.651Z | user Rele
Rank
62
Safety
84
Downloads
1.0k
Updated
Oct 11, 2026
Version
1.9.19
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1K downloadsadoption · observed Oct 11, 2026
- Latest release
- 1.9.19release · observed Aug 26, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-pensive-performance-review- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-performance-review/snapshot"
Run-check
$0.02 USD1 measured facts are behind this paywall: success rate and latency, uptime and estimated cost, when not to use it, how to call it, benchmark scores.
Agents pay $0.02 in USDC. A card payment is $0.50, the smallest a card allows.
Documentation
CLAWHUB
144,315 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: performance-review
description: Detects time and space complexity hotspots via AST scan
version: 1.9.8
triggers:
- performance
- complexity
- algorithms
- ast
- static-analysis
- code feels slow
- before performance-sensitive merges
- or to find O(n²) regressions
metadata: {"openclaw": {"homepage": "https://github.com/athola/claude-night-market/tree/master/plugins/pensive", "emoji": "\ud83e\udd9e", "requires": {"config": ["night-market.pensive:shared"]}}}
source: claude-night-market
source_plugin: pensive
---
> **Night Market Skill** — ported from [claude-night-market/pensive](https://github.com/athola/claude-night-market/tree/master/plugins/pensive). For the full experience with agents, hooks, and commands, install the Claude Code plugin.
## Table of Contents
- [Quick Start](#quick-start)
- [When to Use](#when-to-use)
- [When NOT to Use](#when-not-to-use)
- [Required TodoWrite Items](#required-todowrite-items)
- [Workflow](#workflow)
- [Tiered Analysis](#tiered-analysis)
- [Output Format](#output-format)
- [Cross-Plugin Dependencies](#cross-plugin-dependencies)
- [Supporting Modules](#supporting-modules)
# Performance Review
Static-analysis review of time and space complexity hotspots.
The skill runs in three escalating tiers. Tier 1 uses Python's
stdlib `ast` and always runs. Tier 2 uses gauntlet's tree-sitter
parser to extend detection across languages when gauntlet is
installed. Tier 3 uses the gauntlet code graph to upgrade
severity when hotspots reach other hotspots transitively. If
gauntlet is missing, Tiers 2 and 3 no-op and Tier 1 still
produces useful findings on Python source.
## Quick Start
```bash
/performance-review # scan changed files
/performance-review path/to/file.py # scan one file
/performance-review --tier 1 # force Tier 1 only
```
Programmatic use:
```python
from pensive.skills.performance_review import PerformanceReviewSkill
skill = PerformanceReviewSkill()
result = skill.analyze(context, "src/module.py")
for f in result.issues:
print(f"[{f.severity}] {f.file}:{f.line} {f.message}")
```
## When to Use
- Pre-merge review of code that runs on user-scaled inputs.
- Triage of a function that "feels slow" before reaching for a
profiler.
- Audit a refactor for newly introduced O(n²) patterns.
- Guardrail for AI-generated code where nested-loop hot spots
are common.
## When NOT to Use
- The target needs **runtime** measurement (memory profile, CPU
time on real data). Use `Skill(parseltongue:python-performance)`
instead: that skill drives `cProfile`, `py-spy`, and benchmarks.
- General refactoring guidance not focused on hotspots: use
`Skill(pensive:code-refinement)` whose `algorithm-efficiency`
module covers broader optimization patterns. This skill
detects; that skill teaches.
- Architecture-level performance (sharding, caching layers,
queue placement): use `Skill(pensive:architecture-review)`.
## Required TodoWrite Items
1. `perf-review:con_meta.json
{
"ownerId": "kn7d107jg9jv602h9ytsegydq184a42s",
"slug": "nm-pensive-performance-review",
"version": "1.9.19",
"publishedAt": 1787750346422
}modules/gauntlet-integration.md
---
module: gauntlet-integration
description: Tier 2/3 contract via gauntlet tree-sitter and graph
parent_skill: performance-review
category: integration
tags:
- gauntlet
- tree-sitter
- graph
- optional-dependency
---
# Gauntlet Integration
Performance review is a Tier-1 skill out of the box. Tiers 2 and
3 enrich the analysis when gauntlet is installed.
## Optional-import contract
At module load time, `performance_review.py` runs two
try-imports to module-level sentinels:
```python
try:
from gauntlet.treesitter_parser import parse_file as _gt_parse
except (ImportError, ModuleNotFoundError):
_gt_parse = None
try:
from gauntlet.graph import GraphStore as _GraphStore
except (ImportError, ModuleNotFoundError):
_GraphStore = None
```
The dual-exception catch matches the precedent in
`plugins/leyline/src/leyline/tokens.py:25-32`. It survives the
case where the import fails for a reason other than the module
being absent (e.g., a transitive ImportError deep inside
gauntlet's own stack).
Each tier helper checks its sentinel and early-returns:
```python
def _tier2_findings(self, context, file_path):
if _gt_parse is None:
return []
...
def _tier3_findings(self, context, existing, file_path):
if _GraphStore is None:
return []
...
```
This is the same pattern proven in
`plugins/pensive/hooks/pr_blast_radius.py:52-56`, where
gauntlet's blast-radius graph is consulted only when the
plugin is installed.
## Tier 2: Tree-sitter coverage
When `_gt_parse` is set, `_tier2_findings` invokes
`parse_file(path)` and receives `(nodes, edges)` describing the
target file's AST in gauntlet's neutral graph format.
Languages currently parsed: Python, JavaScript, TypeScript, Go,
Rust, Java, C, C++, C#, Ruby, PHP, Kotlin, Swift, Scala (per
gauntlet's `_EXT_TO_LANG` map).
The patterns translated to Tier 2 are the language-agnostic
ones:
- T1 (nested loop over same iterable): present in every
imperative language.
- T2 (membership in list): adapts to language idioms (e.g.,
`Array.includes` in JS, `slices.Contains` in Go).
- S1 (append in nested loops): `arr.push(...)` in JS,
`append(slice, ...)` in Go.
Patterns that do NOT translate (skipped at Tier 2):
- T3 (`re.compile` in a loop): Python-specific call shape.
- T6 (list comprehension passed to a reducer): Python-specific
syntax.
- T4 (string `+=`): many languages have language-level string
builders that handle this; the cost model differs.
## Tier 3: Transitive call analysis
When both `_GraphStore` is set AND a `.gauntlet/graph.db` file
exists in the working tree, `_tier3_findings` opens the graph
and queries `impact_radius()` for each existing finding's
function.
If a function reachable from a Tier-1/2 hotspot is itself a
hotspot, the original finding's severity is upgraded one step:
| Original | Upgraded |
|----------|----------|
| LOW | MEDIUM |
| MEDIUM | HIGH |
| HIGH | CRITICAL |
This catches cases where the surface code lookmodules/kuva-visualization.md
---
module: kuva-visualization
category: output
dependencies: [Bash, Read]
estimated_tokens: 350
---
# Visualizing Performance Findings with kuva
**When a performance review produces before/after benchmark data,
render it as a chart.** Text comparisons like "380ms → 60ms" are
correct but hard to scan across multiple hotspots. A scatter or
bar chart makes regressions and wins immediately visible.
[kuva](https://github.com/Psy-Fer/kuva) is a Rust scientific
plotting library (and CLI binary) that renders directly from TSV/CSV
input to SVG, PNG, or the terminal. Install once; pipe benchmark
data in without modifying project source.
## Install
```bash
cargo install kuva --features cli
```
## Rendering a before/after benchmark comparison
### criterion (Rust)
criterion writes per-benchmark timing samples to
`target/criterion/<name>/new/estimates.json`. Extract the mean and
pipe to kuva:
```bash
# Collect before/after means for all criterion benchmarks
python3 - <<'EOF'
import json, pathlib, sys
rows = ["benchmark\tstage\tns"]
for est in pathlib.Path("target/criterion").rglob("estimates.json"):
bench = est.parts[-3]
data = json.loads(est.read_text())
mean_ns = data["mean"]["point_estimate"]
# Distinguish before/after by tag; adjust to your workflow.
rows.append(f"{bench}\tafter\t{mean_ns:.1f}")
print("\n".join(rows))
EOF | kuva bar /dev/stdin --x benchmark --y ns --color-by stage \
--title "Before vs After" --terminal
```
For a paired comparison where you have both runs saved:
```bash
# before.tsv and after.tsv each contain: benchmark<TAB>ns
kuva scatter before.tsv after.tsv \
--x ns --y ns --color-by stage \
--title "Hotspot timing (lower is better)" \
-o perf-comparison.svg
```
### pytest-benchmark (Python)
```bash
pytest --benchmark-json=bench.json tests/
# Convert to TSV
python3 -c "
import json, sys
d = json.load(open('bench.json'))
print('name\tns')
for b in d['benchmarks']:
print(b['name'] + '\t' + str(b['stats']['mean'] * 1e9))
" | kuva bar /dev/stdin --x name --y ns \
--title "Benchmark means (ns)" -o bench.svg
```
### Ad-hoc timing table
If you are capturing timings manually (e.g., from production traces
as in the mlock war story):
```tsv
stage p50_ms p99_ms
before_mlock 180 380
after_mlock 35 60
```
```bash
kuva bar timings.tsv --x stage --y p99_ms \
--title "p99 barge-in latency (ms)" -o latency.svg
```
## Terminal output (no file required)
For quick CI feedback without writing an SVG artifact, add
`--terminal` to any kuva command. The chart renders as Unicode
block characters directly in the shell, visible in CI logs.
```bash
kuva bar timings.tsv --x stage --y p99_ms --terminal
```
## When to attach a chart as evidence
The `Skill(imbue:proof-of-work)` discipline requires evidence
references `[E1]`/`[E2]` for before/after claims. A kuva-rendered
SVG in the PR description or comments is a valid `[E2]` when it
shows the post-fix benchmark result alongside the pre-fix bmodules/space-complexity.md
---
module: space-complexity
description: AST patterns for space-complexity hotspot detection
parent_skill: performance-review
category: code-quality
tags:
- space-complexity
- memory
- ast
- python
---
# Space Complexity Detectors
Three AST patterns that signal likely space-complexity hotspots.
Each detector cites the AST node it matches, the heuristic, and
a concrete fix.
## S1: Unbounded `.append()` inside nested loops (MEDIUM)
**AST shape**: `ast.Call` whose `func` is `ast.Attribute` named
`append`, found while the loop stack has depth >= 2.
**Why it matters**: A single-loop accumulator is bounded by the
input size, which is usually fine. A nested-loop accumulator
grows multiplicatively (n×m or n²) and is the typical "result
explosion" pattern that drives memory exhaustion.
**Note**: The detector deliberately does not flag single-loop
appends. They are common, expected, and rarely a hotspot. If
single-loop accumulation becomes a problem, that is a runtime
profiling concern handled by
`Skill(parseltongue:python-performance)`.
**Fix**: If the consumer can iterate, yield instead of
materialize:
```python
def all_pairs(xs):
for x in xs:
for y in xs:
yield (x, y) # streaming, O(1) space
```
When the full list is genuinely needed, document the size
bound:
```python
# Bounded: |xs| <= 100, so output <= 10000 pairs.
out = [(x, y) for x in xs for y in xs]
```
## S2: List wrapping a generator inside a reducer (LOW)
**AST shape**: `ast.Call` to one of `sum`, `max`, `min`, `any`,
`all`, `sorted`, `set`, `frozenset`, where the first arg is
itself an `ast.Call` to `list`, `dict`, `tuple`, or `set` with
an `ast.GeneratorExp` as its first argument.
**Why it matters**: `max(list(g))` allocates the full list, then
walks it. The wrapper is redundant: reducers accept generators
directly.
**Fix**:
```python
# Before
return max(list(x * 2 for x in xs))
# After
return max(x * 2 for x in xs)
```
For `sorted` / `set` the wrapper is sometimes intentional (to
force evaluation), but it's still cheaper to let `sorted` /
`set` consume the generator directly.
## S3: Per-iteration allocation inside a loop (MEDIUM)
**AST shape**: `ast.Call` inside a loop body where either:
- The `func` is an `ast.Attribute` with name `copy`, or
- The `func` is an `ast.Name` of `dict`, `list`, or `tuple`
with a non-comprehension first argument (the comprehension
case is a builder, not a copy).
**Why it matters**: `base.copy()` per iteration allocates a new
container N times. If only one or two fields change per
iteration, a single allocation outside the loop with selective
mutation costs less.
**Fix**: Hoist when possible.
```python
# Before
for x in items:
snapshot = base.copy()
snapshot["key"] = x
out.append(snapshot)
# After (when downstream tolerates shared dict identity):
shared = {**base}
for x in items:
shared["key"] = x
out.append(dict(shared)) # explicit copy at the boundary
```
When the snapshots must be indeAionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/athola/skills/nm-pensive-performance-review",
"sourceUrl": "https://clawhub.ai/athola/skills/nm-pensive-performance-review",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T17:49:39.875Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-performance-review/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-performance-review/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T17:49:39.875Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1K downloads",
"href": "https://clawhub.ai/athola/nm-pensive-performance-review",
"sourceUrl": "https://clawhub.ai/athola/nm-pensive-performance-review",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T17:49:39.875Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.9.19",
"href": "https://clawhub.ai/athola/nm-pensive-performance-review",
"sourceUrl": "https://clawhub.ai/athola/nm-pensive-performance-review",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-26T13:19:06.422Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-performance-review/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-pensive-performance-review/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.9.19",
"description": "Release v1.9.19",
"href": "https://clawhub.ai/athola/nm-pensive-performance-review",
"sourceUrl": "https://clawhub.ai/athola/nm-pensive-performance-review",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-26T13:19:06.422Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
