scale-canary
Performance complexity and resource allocation canary — checks for O(N^2) loops, database N+1 query patterns, memory leaks (unbounded collections), and blocking calls in main event loop. Triggers on keywords: "/scale-canary", "scale-canary", "performance audit", "scale audit". Us
Install
npx skills add https://github.com/TheColliery/CoalMine/tree/main/plugin/skills/scale-canary
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install hetcreep-coalmine@llmmart
git clone https://github.com/TheColliery/CoalMine.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole hetcreep/coalmine collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
Scale Canary (Performance & Resource Allocation Audit)
Language: Generate EVERYTHING at runtime in the user's language — questions, answer options, menu labels, recommendations, report narrative. Detect from their messages; never default to English just because this file is English. English is allowed only for technical terms: commands, paths, code identifiers, severity labels (CRITICAL/HIGH/MEDIUM/LOW), and tier names (Light/Standard/Heavy).
Config reads — every config key, always the CASCADE, never the bare project file: ~/.claude/.coalmine.json first, then the project config (own agent dir → other known agent dirs → legacy <gitroot>/.coalmine.json), project wins per key. A bare project read is ABSENT on a machine configured only globally, so it silently yields defaults.
Audit code for scalability issues, performance bottlenecks, and resource leaks.
Auditing Categories
- O(N^2) Complexity — nested loops over growable collections without indexing or caching (crashes at scale).
- N+1 Database Queries — querying records in a loop instead of a batch JOIN or bulk prefetch.
- Memory Bloat / Leaks — appending to global arrays/maps without clearing them → unbounded growth.
- Blocking Main Loop — synchronous FS ops or CPU-heavy work on the main event thread (lag/hangs).
- Resource Leakage — streams, connections, or handles left open without a
finallyclose.
Per-ORM N+1 shapes, per-stack blocking patterns, and what NOT to flag: read references/checks.md before scanning.
Fix mode (choice-gated)
In Agent Context, after the report, present via ask_question:
- Apply safe optimizations: async-ify synchronous file ops; insert
finallyblocks for stream closing. Each fix: checkpoint (git stash/commit in a git repo; else copy the file aside — never assume git) → apply → build + tests → auto-revert if newly red. - Let me pick: user selects specific optimizations.
- Report only: exit unchanged.
Grants & denials (CLASSIFY-BLOCK)
| class | step it powers | grant | on denial |
|---|---|---|---|
| read | scan loops/queries/caches for the categories above | Read·Grep·Glob |
refuse that file, name it — never a clean bill |
| write | Fix mode's safe-optimization apply, incl. checkpoint → build+tests → auto-revert if newly red | Edit·Bash (checkpoint/build/revert need exec) |
report the fix as NOT applied AND the checkpoint/revert as NOT available, never claim done |
A denial reaches the WORKER as a visible message and propagates no further — never to a caller, never as a catchable condition. Every row above states a grant or an explicit death; a step that dies says so in the output, never as a false "done"/"skipped"/"clean".
- read denied → refuse before scanning; never a false clean bill.
- write denied → report the change as NOT applied — never claim done.
- network denied/unfetchable →
⚠️ unverified: check [source]. - spawn denied → degrade per Escalation's own capability-lever fallback (never fake parallelism) and say the fan-out did not happen — already discharged there; a row above is only for a spawn this skill does OUTSIDE tier escalation.
Output
| file:line | bottleneck | severity | finding | optimization plan |
Severity: CRITICAL (O(N^2) on user-facing API / unclosed file handles) · HIGH (N+1 query pattern / blocking main loop) · MEDIUM (unbounded cache growth) · LOW (minor efficiency suggestions)
Reporting: call ReportFindings when callable — file/line MUST be the defect site, never the enclosing function; an unresolvable line reports your best guess, named imprecise in the wrap-up — never dropped, never faked. Severity prefixed in summary (e.g. [HIGH] …), ranked most-severe first, SUSPECTED as verdict: PLAUSIBLE; chat then carries only the wrap-up line (counts · coverage gaps · overflow past 32 · any imprecise-line findings) + the fix menu, never a restatement of findings. Not callable → the table above, unchanged. An Apply-fixes click = consent to the safe-fix class only — gated the same as this skill's own fix-mode (Hook Context needs an interactive session, per the Hook Context rule below) — composing with (never bypassing) the fix-mode discipline. After any fix round, re-report the same findings with outcome: fixed/skipped/no_change_needed — skipping this leaves the round UNFINISHED.
Escalation — Scope & Model Quality
Tiers are capability targets, not platform commands — resolve each to your host's nearest lever. No lever for one? Degrade gracefully — never fake parallelism you can't do; escalate via model tier + reasoning depth instead.
| Level | Intent | Capability target | Cost |
|---|---|---|---|
| Light | Spot performance check, hot paths only | Cheapest model · single agent, no sub-agents. | Low |
| Standard | Balanced scalability audit, multi-category | Balanced model · raised reasoning · sub-agents per category only if your platform runs concurrent workers (else single-agent). | Balanced |
| Heavy | Full 5-category audit + adversarial profiling verify | Most capable model + largest context · deepest reasoning · max sub-agent fan-out if supported · adversarial cross-check where available. | High |
Per-platform Heavy levers + Heavy-run durability: read references/escalation.md before a Heavy run. No concurrent fan-out on your host → escalate by model + reasoning only.
Agent Context (interactive): score the tier rubric, then call ask_question once with the 3 tiers — the pick marked ✓, score shown, labels localized — and wait for the choice before starting. ask_question = your platform's question tool: Claude Code AskUserQuestion · Cline ask_question · Copilot askQuestions · Gemini CLI ask_user (business-tier product; individual tiers ended 2026-06-18 → Antigravity CLI) · Codex request_user_input · Cursor/Devin Desktop (ex-Windsurf)/Antigravity built-in prompts; none → numbered text menu.
Tier rubric (deterministic): +1 each — ① >20 files or whole-repo/cross-module reach ② >2 of this skill's categories relevant ③ release/security/pre-ship context ④ findings will drive code changes. 0–1 Light · 2–3 Standard · 4 Heavy. Freshness cap: scope already audited ≥Standard this session → cap at Light (re-auditing fresh ground wastes tokens; scope to what changed). Default tier: honor .coalmine.json defaultTier unless the user requests a tier for that run — an explicit request overrides everything.
Hook Context (auto-triggered): auto-Light, no tier question, no sub-agents — report first. Interactive session (a user is present) → follow this skill's own Fix mode section, if it defines one, for what to offer after the report; non-interactive → report-only. Where a Fix mode section exists, never fix without a chosen option.
Entanglement: after the report, if confirmed findings fall in another canary's domain, offer it once via ask_question (one line, max one offer): perf/N+1 → scale-canary · contract/serialization/config → drift-canary · failure-path/retry → resilience-audit · logging/metrics → telemetry-canary · coupling/DI → testability-canary · dependency/CVE → supply-chain-audit · unverified version-sensitive claim → source-grounding · missing/stale rule → gold-standard.
Self error-report: if this skill misbehaves (contradictory instruction, broken procedure, wrong finding class), OFFER to file it at https://github.com/HetCreep/CoalMine/issues/new/choose with a user-reviewed summary — never auto-submit, never include unapproved code or paths.
Files (coalmine)
-
references
-
checks.md 2 KB
<!-- coalmine: verified 2026-06-12 · revalidate 90d · definition file for scale-canary --> # Scale canary — concrete detection procedures ## 1. O(N²) on growable data - Nested loops where the inner iterates a collection that grows with usage (users, orders, files) — `for ... { for ... { } }`, `.filter().map()` inside `.forEach`, `Where` inside `foreach`. - `Array.includes`/`indexOf`/`list.Contains` inside a loop over another list → suggest Set/Dictionary index (O(N²)→O(N)). - Only flag when N is unbounded user data; fixed small enums are fine. ## 2. N+1 queries (per-ORM shapes) | ORM | Smell | Fix | |---|---|---| | EF Core | navigation property access in a loop (lazy load) | `.Include()` / projection | | Prisma | `findUnique`/`findMany` inside `for`/`map` over rows | single `findMany({ where: { in } })` / `include` | | Sequelize | per-row `.get...()` association calls | `include` eager load | | Django | attribute access on FK in template/loop | `select_related`/`prefetch_related` | | Raw SQL | query call inside loop | batch `IN (...)` / JOIN | ## 3. Memory bloat / unbounded growth - Appends to module/global collections that never clear: `cache.push(...)`, `dict[key] = ...` in long-lived process without eviction/TTL. - Event listeners/subscriptions added per request and never removed. - Caches: flag any hand-rolled cache without max-size or TTL. ## 4. Blocking the main/event loop | Stack | Patterns | |---|---| | Node | `fs.*Sync`, `child_process.execSync`, `crypto.pbkdf2Sync`, JSON.parse on multi-MB payloads — inside server handlers | | C# | `.Result`, `.Wait()`, `Task.Run(...).Result` in async context (deadlock + thread starvation) | | Python (async) | sync `requests`/file I/O inside `async def` without `to_thread` | | UI apps | disk/network on UI thread | - CLI/startup code may legitimately use sync I/O — scope to request/event paths. ## 5. Resource leakage - Streams/connections/handles opened without `using`/`try-finally`/`with`/`defer` close. - Pools: connections acquired and returned on the happy path only — check the error path. -
escalation.md 1.4 KB
<!-- coalmine: verified 2026-07-23 · revalidate 30d · shared escalation detail for all canaries --> # Heavy-tier escalation — per-platform levers & durability Read this only before a **Heavy** run (deep fan-out). Light/Standard never need it. ## Per-platform Heavy lever Use your host's, if it has concurrent fan-out: - **Claude Code** → Dynamic Workflows / `ultracode` (≤16 concurrent agents) - **OpenAI Codex** → `xhigh` + subagents + Cloud `--attempts` - **Cursor** → Max Mode + parallel Cloud Agents - **Amp** → Oracle + subagents - **GitHub Copilot** → `/fleet` (Copilot CLI) + Cloud agent - **Goose** → subagents - **JetBrains** → Junie CLI - **Gemini CLI (business-tier product; individual tiers ended 2026-06-18 → Antigravity CLI) / Cline (read-only) / Devin Desktop (ex-Windsurf)** → subagents No concurrent fan-out on your host → escalate by model tier + reasoning depth only; never fake parallelism you cannot do. ⚠️ Subagent support CHURNS fast — most major agents added it through 2026 — so verify your platform's current capability rather than trusting this list. ## Heavy-run durability Run in short phases, reading results between them. If a run dies, recover finished sub-agent results from your platform's run records and re-spawn only what is missing. On Claude Code, fan out with the bundled `coalmine-scanner` agent (read-only, one dimension per spawn, table output).
-
-
skill-meta.json 195 B
{ "lightIntent": "Spot performance check, hot paths only", "standardIntent": "Balanced scalability audit, multi-category", "heavyIntent": "Full 5-category audit + adversarial profiling verify" } -
SKILL.md 8 KB
--- name: scale-canary description: >- Performance complexity and resource allocation canary — checks for O(N^2) loops, database N+1 query patterns, memory leaks (unbounded collections), and blocking calls in main event loop. Triggers on keywords: "/scale-canary", "scale-canary", "performance audit", "scale audit". Use when writing loops over growing data, DB queries, caches, or async/event-loop code. --- # Scale Canary (Performance & Resource Allocation Audit) **Language:** Generate EVERYTHING at runtime in the user's language — questions, answer options, menu labels, recommendations, report narrative. Detect from their messages; never default to English just because this file is English. English is allowed only for technical terms: commands, paths, code identifiers, severity labels (CRITICAL/HIGH/MEDIUM/LOW), and tier names (Light/Standard/Heavy). **Config reads — every config key, always the CASCADE, never the bare project file:** `~/.claude/.coalmine.json` first, then the project config (own agent dir → other known agent dirs → legacy `<gitroot>/.coalmine.json`), project wins per key. A bare project read is ABSENT on a machine configured only globally, so it silently yields defaults. Audit code for scalability issues, performance bottlenecks, and resource leaks. ## Auditing Categories 1. **O(N^2) Complexity** — nested loops over growable collections without indexing or caching (crashes at scale). 2. **N+1 Database Queries** — querying records in a loop instead of a batch JOIN or bulk prefetch. 3. **Memory Bloat / Leaks** — appending to global arrays/maps without clearing them → unbounded growth. 4. **Blocking Main Loop** — synchronous FS ops or CPU-heavy work on the main event thread (lag/hangs). 5. **Resource Leakage** — streams, connections, or handles left open without a `finally` close. Per-ORM N+1 shapes, per-stack blocking patterns, and what NOT to flag: read `references/checks.md` before scanning. ## Fix mode (choice-gated) In Agent Context, after the report, present via `ask_question`: - **Apply safe optimizations:** async-ify synchronous file ops; insert `finally` blocks for stream closing. Each fix: checkpoint (git stash/commit in a git repo; else copy the file aside — never assume git) → apply → build + tests → auto-revert if newly red. - **Let me pick:** user selects specific optimizations. - **Report only:** exit unchanged. ## Grants & denials (CLASSIFY-BLOCK) | class | step it powers | grant | on denial | |---|---|---|---| | read | scan loops/queries/caches for the categories above | `Read`·`Grep`·`Glob` | refuse that file, name it — never a clean bill | | write | Fix mode's safe-optimization apply, incl. checkpoint → build+tests → auto-revert if newly red | `Edit`·`Bash` (checkpoint/build/revert need exec) | report the fix as NOT applied AND the checkpoint/revert as NOT available, never claim done | A denial reaches the WORKER as a visible message and propagates no further — never to a caller, never as a catchable condition. Every row above states a grant or an explicit death; a step that dies says so in the output, never as a false "done"/"skipped"/"clean". - **read** denied → refuse before scanning; never a false clean bill. - **write** denied → report the change as NOT applied — never claim done. - **network** denied/unfetchable → `⚠️ unverified: check [source]`. - **spawn** denied → degrade per Escalation's own capability-lever fallback (never fake parallelism) and say the fan-out did not happen — already discharged there; a row above is only for a spawn this skill does OUTSIDE tier escalation. ## Output `| file:line | bottleneck | severity | finding | optimization plan |` Severity: CRITICAL (O(N^2) on user-facing API / unclosed file handles) · HIGH (N+1 query pattern / blocking main loop) · MEDIUM (unbounded cache growth) · LOW (minor efficiency suggestions) **Reporting:** call `ReportFindings` when callable — `file`/`line` MUST be the defect site, never the enclosing function; an unresolvable line reports your best guess, named imprecise in the wrap-up — **never dropped, never faked.** Severity prefixed in `summary` (e.g. `[HIGH] …`), ranked most-severe first, SUSPECTED as `verdict: PLAUSIBLE`; chat then carries only the wrap-up line (counts · coverage gaps · overflow past 32 · any imprecise-line findings) + the fix menu, never a restatement of findings. Not callable → the table above, unchanged. An Apply-fixes click = consent to the safe-fix class only — gated the same as this skill's own fix-mode (Hook Context needs an interactive session, per the Hook Context rule below) — composing with (never bypassing) the fix-mode discipline. **After any fix round, re-report the same findings with `outcome: fixed`/`skipped`/`no_change_needed` — skipping this leaves the round UNFINISHED.** ## Escalation — Scope & Model Quality Tiers are **capability targets**, not platform commands — resolve each to your host's nearest lever. No lever for one? **Degrade gracefully — never fake parallelism you can't do**; escalate via model tier + reasoning depth instead. | Level | Intent | Capability target | Cost | |---|---|---|---| | **Light** | Spot performance check, hot paths only | Cheapest model · single agent, no sub-agents. | Low | | **Standard** | Balanced scalability audit, multi-category | Balanced model · raised reasoning · sub-agents per category **only if your platform runs concurrent workers** (else single-agent). | Balanced | | **Heavy** | Full 5-category audit + adversarial profiling verify | Most capable model + largest context · deepest reasoning · max sub-agent fan-out **if supported** · adversarial cross-check where available. | High | Per-platform Heavy levers + Heavy-run durability: read `references/escalation.md` before a Heavy run. No concurrent fan-out on your host → escalate by model + reasoning only. **Agent Context (interactive):** score the tier rubric, then call `ask_question` once with the 3 tiers — the pick marked `✓`, score shown, labels localized — and wait for the choice before starting. `ask_question` = your platform's question tool: Claude Code `AskUserQuestion` · Cline `ask_question` · Copilot `askQuestions` · Gemini CLI `ask_user` (business-tier product; individual tiers ended 2026-06-18 → Antigravity CLI) · Codex `request_user_input` · Cursor/Devin Desktop (ex-Windsurf)/Antigravity built-in prompts; none → numbered text menu. **Tier rubric (deterministic):** +1 each — ① >20 files or whole-repo/cross-module reach ② >2 of this skill's categories relevant ③ release/security/pre-ship context ④ findings will drive code changes. **0–1 Light · 2–3 Standard · 4 Heavy.** **Freshness cap:** scope already audited ≥Standard this session → cap at Light (re-auditing fresh ground wastes tokens; scope to what changed). **Default tier:** honor `.coalmine.json` `defaultTier` unless the user requests a tier for that run — an explicit request overrides everything. **Hook Context (auto-triggered):** auto-Light, no tier question, no sub-agents — report first. Interactive session (a user is present) → follow this skill's own Fix mode section, if it defines one, for what to offer after the report; non-interactive → report-only. Where a Fix mode section exists, never fix without a chosen option. **Entanglement:** after the report, if confirmed findings fall in another canary's domain, offer it once via `ask_question` (one line, max one offer): perf/N+1 → scale-canary · contract/serialization/config → drift-canary · failure-path/retry → resilience-audit · logging/metrics → telemetry-canary · coupling/DI → testability-canary · dependency/CVE → supply-chain-audit · unverified version-sensitive claim → source-grounding · missing/stale rule → gold-standard. **Self error-report:** if this skill misbehaves (contradictory instruction, broken procedure, wrong finding class), OFFER to file it at https://github.com/HetCreep/CoalMine/issues/new/choose with a user-reviewed summary — never auto-submit, never include unapproved code or paths.
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.