n1-analyze

A code-analysis command that checks an application for N+1 database queries and other performance problems using four parallel reviewers.

In plain words
What is it for?
Inspecting supported Node.js, Python, Go, Java, Ruby, and PHP projects, identifying their frameworks and databases, and reviewing frontend, backend, ORM, and source-code performance.
Why use it?
It helps find slow or wasteful data access that may be spread across different parts of an application.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/hculap/better-code/n1-analyze
Clone the repo
git clone --depth 1 https://github.com/hculap/better-code
Per session 14 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,897 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00014 $0.01897
Opus 5 $0.00007 $0.00949
Sonnet 5 $0.00003 $0.00379
Haiku 4.5 $0.00001 $0.00190

Measured 2d ago against content hash d3bd7145aaf5, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

n1-analyze scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/n1-optimizer/commands/n1-analyze.md · 217 lines

How it starts

The opening of the file, as written. The whole thing — 217 lines — stays where its author put it; the contents beside it link to each section on GitHub.

N+1 Optimizer Analysis

Perform comprehensive performance analysis by launching 4 specialized agents IN PARALLEL. Each agent focuses on a different layer of the application stack.

Step 1: Detect Tech Stack

Check these files to identify the tech stack (use Read tool):

File Stack Check For
package.json Node.js Look at dependencies for: react/vue/angular (frontend), express/fastify/nest (backend), prisma/typeorm/sequelize (ORM)
requirements.txt or pyproject.toml Python django, flask, fastapi, sqlalchemy, tortoise-orm
go.mod Go gin, echo, fiber, gorm, ent
pom.xml or build.gradle Java spring-boot, hibernate, jpa
Gemfile Ruby rails, sinatra, activerecord
composer.json PHP laravel, symfony, doctrine

Also identify source directories by checking for: src/, app/, lib/, services/, api/, components/, pages/.

Record: Frontend framework, Backend framework, ORM/Database library, Source directories.

Step 2: Launch 4 Agents IN PARALLEL

CRITICAL: Launch ALL 4 agents in a SINGLE message with multiple Task tool calls. Do NOT launch them sequentially.

Use subagent_type with plugin namespace n1-optimizer:<agent-name>:

Agent 1: n1-optimizer:database-analyzer

Prompt: "Analyze this codebase for database performance issues.

Working directory: [WORKING_DIR]
Tech stack: [DETECTED_STACK - e.g., Node.js + Prisma + PostgreSQL]
Source directories: [DIRS - e.g., src/, services/]

Focus on:
- N+1 queries (queries inside loops, lazy loading)
- Missing indexes on frequently queried columns
- Inefficient JOINs
- Unbounded queries (no LIMIT)
- Query patterns in loops

Return findings in format: [SEVERITY] Issue - file:line"

Agent 2: n1-optimizer:backend-analyzer

Prompt: "Analyze this codebase for backend performance issues.

Working directory: [WORKING_DIR]
Tech stack: [DETECTED_STACK]
Source directories: [DIRS]

Focus on:
- O(n²) algorithms (nested loops on collections)
- Blocking operations in async code
- Memory leaks (unclosed resources, growing arrays)
- Redundant computations (missing memoization)
- Sequential awaits that could be parallel

Return findings in format: [SEVERITY] Issue - file:line"

Read the full file on GitHub · 217 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 217 lines · 14 tokens per session scan A d3bd7145aaf5

Subscribe to this mod's changes

n1-analyze is a command published in the GitHub repository hculap/better-code (2 stars, last pushed 7mo ago), licensed MIT. It adds 14 tokens to every session and 1,897 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.