SQL Database Assistant
alirezarezvani/claude-skills
A skill your agent uses when the user asks to write SQL queries, optimize database performance, generate migrations, explore database schemas, or work with ORMs like Prisma, Drizzle, TypeORM, or…
数据库代码审查 + Migration 安全检查. An agent skill from 312362115/claude.
$ npx skills add 312362115/claude --skill db-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install 312362115/claude db-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/db-review .claude/skills/db-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "db-review" agent skill from https://github.com/312362115/claude/tree/main/skills/db-review into .claude/skills/db-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "db-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/312362115/claude/tree/main/skills/db-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add 312362115/claude --skill db-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install 312362115/claude db-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/db-review .agents/skills/db-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "db-review" agent skill from https://github.com/312362115/claude/tree/main/skills/db-review into .agents/skills/db-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "db-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add 312362115/claude --skill db-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install 312362115/claude db-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/db-review .cursor/skills/db-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "db-review" agent skill from https://github.com/312362115/claude/tree/main/skills/db-review into .cursor/skills/db-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "db-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/312362115/claude.git --path skills/db-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add 312362115/claude --skill db-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install 312362115/claude db-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/db-review .gemini/skills/db-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "db-review" agent skill from https://github.com/312362115/claude/tree/main/skills/db-review into .gemini/skills/db-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "db-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install 312362115/claude db-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add 312362115/claude --skill db-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/db-review .github/skills/db-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "db-review" agent skill from https://github.com/312362115/claude/tree/main/skills/db-review into .github/skills/db-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "db-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add 312362115/claude --skill db-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install 312362115/claude db-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/db-review .opencode/skills/db-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "db-review" agent skill from https://github.com/312362115/claude/tree/main/skills/db-review into .opencode/skills/db-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "db-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
db-review数据库代码审查 + Migration 安全检查. An agent skill from 312362115/claude.
DB Review is an agent skill from 312362115/claude. 数据库代码审查 + Migration 安全检查。 代码审查:锁表风险、索引缺失、慢 SQL 模式、N+1 查询。 Migration 审查:破坏性操作、Schema 漂移检测、回滚方案。 适用于 SQL(MySQL/PostgreSQL/SQLite)和 ORM(Prisma/TypeORM/Sequelize/SQLAlchemy/Drizzle)。 触发词:数据库检查、migration 检查、慢 SQL、索引、锁表、schema 漂移、db review。 触发场景:新增/修改 migration 文件后、数据库相关代码 review、上线前检查、性能排查中发现 DB 瓶颈。
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Databases, covering ORMs and data access and SQL. It works with SQL, Prisma, MySQL and SQLAlchemy. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 2d4fa49. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
DB Review loads about 1.8k tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 500 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from 312362115/claude at commit 2d4fa49, republished under its MIT licence (© 312362115). 500 words, ~1,790 tokens.
.claude/skills/db-review/SKILL.md (or your agent's skills folder).数据库问题的修复成本随阶段指数增长:代码审查 < migration 审查 < 上线后排查 < 数据修复。 尽早发现,尽早修复。
收到审查请求
│
├─ 代码审查模式(改了数据库相关代码)
│ └─ 检查 SQL 质量 + 查询性能 + 锁风险
│
├─ Migration 审查模式(新增/修改 migration 文件)
│ └─ 检查安全性 + Schema 漂移 + 回滚方案
│
└─ 全量审查(上线前 / 用户主动要求)
└─ 代码审查 + Migration 审查 + Schema 一致性自动检测项目使用的数据库和 ORM:
| 检测目标 | 检测方式 |
|---|---|
| Prisma | prisma/schema.prisma、@prisma/client |
| TypeORM | typeorm 依赖、@Entity() 装饰器 |
| Sequelize | sequelize 依赖、.define() 调用 |
| Drizzle | drizzle-orm 依赖、drizzle.config.ts |
| SQLAlchemy | sqlalchemy 依赖、Base.metadata |
| 原生 SQL | .sql 文件、query() / execute() 调用 |
| 数据库类型 | 连接字符串、驱动依赖(pg/mysql2/better-sqlite3) |
逐条检查以下反模式,对每个发现标注风险等级:
| 反模式 | 问题 | 正确做法 |
|---|---|---|
SELECT * | 取了不需要的列,浪费 IO 和内存 | 明确列出需要的字段 |
| 无 WHERE 的全表查询 | 数据量大时直接拖垮 DB | 加条件过滤,分页查询 |
| WHERE 中对列使用函数 | WHERE YEAR(created_at) = 2026 无法走索引 | 改为范围查询 WHERE created_at >= '2026-01-01' |
LIKE '%keyword%' | 前缀通配符无法走索引 | 考虑全文索引或搜索引擎 |
OR 条件跨列 | 优化器难以使用索引 | 拆成 UNION 或调整索引策略 |
| 子查询在 WHERE 中 | WHERE id IN (SELECT ...) 可能逐行执行 | 改为 JOIN |
ORDER BY 无索引支撑 | 大表排序触发 filesort | 确保排序字段有索引 |
DISTINCT 掩盖重复 | 通常是 JOIN 写错的信号 | 检查 JOIN 条件是否正确 |
审查方法:
findAll() 没加条件等价于 SELECT * 全表扫描这是 ORM 项目最常见的性能杀手。
# 反模式:循环中查询
users = User.findAll()
for user in users:
orders = Order.findAll({ where: { userId: user.id } }) # N 次查询
# 正确:预加载/JOIN
users = User.findAll({ include: [Order] }) # 1 次查询检查方法:
for/forEach/map 中的 find/query/select)include/joinedload/with)以下操作在大表上可能导致长时间锁表:
| 操作 | MySQL 风险 | PostgreSQL 风险 | 安全替代 |
|---|---|---|---|
ALTER TABLE ADD COLUMN (有默认值) | 锁表重写(MySQL < 8.0) | 8.0+ 大多即时 | MySQL < 8.0 用 pt-online-schema-change |
ALTER TABLE ADD INDEX | 锁表 | 支持 CONCURRENTLY | PG: CREATE INDEX CONCURRENTLY |
ALTER TABLE MODIFY COLUMN 改类型 | 锁表重写 | 可能锁表 | 分步迁移:新列 → 同步数据 → 切换 |
UPDATE 无 WHERE 大批量 | 行锁升级为表锁 | 大量行锁 | 分批更新(每批 1000-5000 行) |
DELETE 大批量 | 同上 | 同上 | 分批删除 + 短暂 sleep |
| 长事务中的 DDL | 锁等待、死锁 | 锁等待 | DDL 独立事务、短事务 |
审查方法:
| 检查项 | 问题信号 |
|---|---|
| 缺失索引 | WHERE/JOIN/ORDER BY 中的列没有索引 |
| 冗余索引 | INDEX(a) 和 INDEX(a, b) 并存(前者被后者包含) |
| 过多索引 | 单表 >6 个索引,影响写入性能 |
| 索引列顺序 | 复合索引列顺序不符合查询模式(最左前缀原则) |
| 低选择性索引 | 在布尔/状态等低基数列上建索引(通常无效) |
| 未使用索引 | 有索引但查询没走到(函数包裹、类型不匹配) |
审查方法:
@Index()/index: true 也要检查| 检查项 | 关注点 |
|---|---|
| 事务范围 | 事务是否过大?包含了不必要的操作? |
| 死锁风险 | 多个事务是否以不同顺序操作同一组表? |
| 隔离级别 | 是否使用了过高的隔离级别(SERIALIZABLE)? |
| 连接泄漏 | 事务/连接是否在异常路径中正确释放? |
| 乐观锁 | 并发更新场景是否有版本号/乐观锁保护? |
以下操作不可逆或有数据丢失风险,必须标记为高风险:
| 操作 | 风险 | 安全做法 |
|---|---|---|
DROP TABLE | 数据永久丢失 | 先备份、确认无引用、保留回滚窗口 |
DROP COLUMN | 列数据丢失 | 确认代码已移除引用后再删列 |
RENAME TABLE/COLUMN | 代码引用断裂 | 分步:新建 → 同步 → 切换 → 清理旧的 |
TRUNCATE | 数据清空 | 不应出现在 migration 中 |
ALTER COLUMN 收窄类型 | 数据截断 | 先检查现有数据是否溢出 |
NOT NULL 约束(已有数据列) | 空值行报错 | 先填充默认值再加约束 |
审查方法:
这是你反复踩坑的问题:本地和服务端 schema 不一致、缺字段。
漂移来源:
1. 手动改了数据库但没写 migration(最常见)
2. migration 执行顺序不一致(分支合并后)
3. migration 只跑了一半(报错后手动修了但没记录)
4. ORM 的 model 定义和 migration 不同步
5. 多人开发时 migration 文件冲突检查流程:
Step 1: 收集当前 Schema 定义来源
├─ ORM model/entity 定义(代码中的"应该是什么")
├─ Migration 文件链("变更历史")
└─ 数据库实际状态(如果能连接)
Step 2: 交叉比对
├─ Model vs Migration:model 里的字段/类型/约束是否都有对应的 migration?
├─ Migration 完整性:migration 链是否连续?有没有遗漏?
└─ 新增字段检查:最近加的字段有 migration 吗?默认值/可空设置对吗?
Step 3: 输出不一致清单
每条记录:字段名、model 中的定义、migration 中的定义、差异描述具体检查项:
| 检查项 | 方法 |
|---|---|
| Model 和 Migration 字段一致 | 遍历 model 所有字段,确认每个字段在 migration 链中有对应的 CREATE/ALTER |
| 类型一致 | model 中的类型(String/Int/DateTime)和 migration 中的 SQL 类型匹配 |
| 可空性一致 | model 标记 optional/nullable 的字段,migration 中没加 NOT NULL |
| 默认值一致 | model 中有 @default() 的字段,migration 中有 DEFAULT |
| 索引一致 | model 中 @index/@unique 的字段,migration 中有对应的 INDEX |
| 关联关系一致 | model 中的外键关系,migration 中有对应的 FOREIGN KEY |
| migration 时间线连续 | 按时间戳排序,检查有没有跳跃或冲突 |
每个 migration 必须有可执行的回滚方案:
| 检查项 | 要求 |
|---|---|
| down/rollback 函数存在 | 不能是空函数或 throw new Error('not implemented') |
| down 函数逻辑正确 | up 中加的列,down 中要删;up 中改的类型,down 中要改回 |
| 数据恢复 | 破坏性操作的 down 需要说明数据恢复策略(即使无法完全自动恢复) |
| 实践 | 要求 |
|---|---|
| 单一职责 | 一个 migration 只做一件事(加表、加列、加索引分开) |
| 可重复执行 | migration 应该幂等,重复运行不报错(IF NOT EXISTS) |
| 数据迁移分离 | schema 变更和数据填充放在不同的 migration 中 |
| 命名规范 | 文件名能反映操作内容(add_email_to_users 而非 migration_042) |
| 等级 | 标准 | 处理要求 |
|---|---|---|
| 高危 | 数据丢失、锁表超 30s、schema 漂移(已知不一致)、无回滚方案 | 必须修复,给出具体方案 |
| 中危 | 性能隐患(N+1、缺索引)、回滚方案不完整、潜在的并发问题 | 建议修复,给出方向 |
| 低危 | 最佳实践缺失(命名、注释、冗余索引)、小表操作 | 记录,不阻断 |
快速审查(终端输出):
## DB Review 结果
🔴 高危 x N | 🟡 中危 x N | 🟢 低危 x N
### 高危
1. [锁表风险] migrations/20260409_add_index.sql:15 — 大表加索引未用 CONCURRENTLY
→ 修复:`CREATE INDEX CONCURRENTLY idx_users_email ON users(email);`
### 中危
1. [N+1] src/services/order.ts:42 — 循环内查询用户信息
→ 修复:使用 include/joinedload 预加载
### Schema 漂移
- ⚠️ User.phone: model 中存在(String, optional),但无对应 migration
- ⚠️ Order.discount: model 类型 Decimal,migration 中为 Float完整审查时,生成报告到 docs/audits/YYYY-MM-DD-db-review.md。
代码开发中
│
├─ 改了数据库代码?→ task-finish 自检时提示跑 db-review(代码审查模式)
├─ 新增 migration?→ 提交前跑 db-review(migration 审查模式)
│
↓ 上线前
├─ security-audit 审查注入防护(SQL 注入维度)
└─ db-review 全量审查(Schema 漂移 + 锁表 + 性能)© 312362115, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/db-review of 312362115/claude.
Open the folder on GitHubat commit 2d4fa49
DB Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| DB Review this skill312362115/claude | 107 | — | ~1.8k | Automated safety check: Pass | MIT | |
| SQL Database Assistantalirezarezvani/claude-skills | 28k | — | ~4k | Automated safety check: Pass | MIT | |
| Dsqlawslabs/agent-plugins | 916 | — | ~7.1k | Automated safety check: Pass | Apache-2.0 | |
| Database Testingpetrkindlmann/qa-skills | 170 | — | ~4.2k | Automated safety check: Pass | MIT | |
| Tsh SQL And Database UnderstandingTheSoftwareHouse/copilot-collections | 284 | — | ~11k | Automated safety check: Pass | MIT | |
| Database FundamentalsDanielPodolsky/ownyourcode | 290 | 1 repos | ~1.6k | Automated safety check: Pass | MIT |
alirezarezvani/claude-skills
A skill your agent uses when the user asks to write SQL queries, optimize database performance, generate migrations, explore database schemas, or work with ORMs like Prisma, Drizzle, TypeORM, or…
awslabs/agent-plugins
Build with Aurora DSQL — manage schemas, execute queries, handle migrations, diagnose query plans, diagnose cluster performance, load data, and develop applications with a serverless, distributed…
petrkindlmann/qa-skills
Validate database integrity, test migrations forward and backward, verify schema constraints, manage seed data, detect migration drift, and identify query performance issues.
TheSoftwareHouse/copilot-collections
SQL writing and database engineering patterns, standards, and procedures.
DanielPodolsky/ownyourcode
Reviews schema design, SQL queries, ORM patterns. An agent skill from DanielPodolsky/ownyourcode.
cin12211/orca-q
Database performance optimization, schema design, query analysis, and connection management across PostgreSQL, MySQL, MongoDB, and SQLite with ORM integration.
312362115/claude
专业图表生成技能:根据需求自动选择合适的图表类型,生成符合设计规范的 PNG 图表. An agent skill from 312362115/claude.
312362115/claude
深度调研技能:对任意命题进行系统性调研并输出专业研究报告. An agent skill from 312362115/claude.
312362115/claude
MD 文件浏览器预览:GitHub 风格渲染 + 左侧自动目录. An agent skill from 312362115/claude.
312362115/claude
通用写作技能:以"内容→组件→组合"的方式产出技术文档、产品文档、汇报材料. An agent skill from 312362115/claude.
312362115/claude
代码导读技能:帮助快速理解不熟悉的项目或模块,建立心智模型. An agent skill from 312362115/claude.
312362115/claude
依赖关系分析技能:回答"改这里会影响哪里". An agent skill from 312362115/claude.
Categories
数据库代码审查 + Migration 安全检查. An agent skill from 312362115/claude. DB Review is an agent skill from 312362115/claude.
DB Review fits situations like: tasks that involve ORMs and data access; tasks that involve SQL.
Run `npx skills add 312362115/claude --skill db-review -a claude-code`. Or copy the skill folder (skills/db-review in 312362115/claude) into .claude/skills/db-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add 312362115/claude --skill db-review -a codex`. Or copy the skill folder (skills/db-review in 312362115/claude) into .agents/skills/db-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add 312362115/claude --skill db-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/db-review, .gemini/skills/db-review, .github/skills/db-review and .opencode/skills/db-review in your project.
SKILL.md names no scripts, command-line tools or credentials: DB Review is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
DB Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with DB Review: SQL Database Assistant (alirezarezvani/claude-skills, 28k stars), Dsql (awslabs/agent-plugins, 916 stars), Database Testing (petrkindlmann/qa-skills, 170 stars) and Tsh SQL And Database Understanding (TheSoftwareHouse/copilot-collections, 284 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
312362115 (a GitHub user) maintains it in 312362115/claude, which has 107 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on May 14, 2026.
Source: 312362115/claude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.