Agent skill

DB Review

by 312362115 in 312362115/claude

数据库代码审查 + Migration 安全检查. An agent skill from 312362115/claude.

MITAuto-check passedDatabases

Install DB Review

skills CLI
$ npx skills add 312362115/claude --skill db-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install 312362115/claude db-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/312362115/claude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/db-review .claude/skills/db-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
db-review
GitHub stars
107
Token cost
~1.8k tokens
SKILL.md length
500 words
Files
1
Skills in repo
20
Repo updated
First seen
Licence
MIT

At a glance

数据库代码审查 + Migration 安全检查. An agent skill from 312362115/claude.

  • Works in 3 steps: 搜索所有 SQL 语句(原生查询、ORM 的 raw query、query… → 对每条 SQL 判断是否命中上述反模式 → ORM 调用也要检查——findAll() 没加条件等价于 SELECT *…
  • Tasks that involve ORMs and data access
  • SKILL.md covers 第一步:确定审查范围和模式, 第二步:代码审查 — SQL 质量与性能, 第三步:Migration 审查 — 安全性与一致性 and 第四步:风险分级与输出, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

DB Review is an agent skill from 312362115/claude. 数据库代码审查 + Migration 安全检查。 代码审查:锁表风险、索引缺失、慢 SQL 模式、N+1 查询。 Migration 审查:破坏性操作、Schema 漂移检测、回滚方案。 适用于 SQL(MySQL/PostgreSQL/SQLite)和 ORM(Prisma/TypeORM/Sequelize/SQLAlchemy/Drizzle)。 触发词:数据库检查、migration 检查、慢 SQL、索引、锁表、schema 漂移、db review。 触发场景:新增/修改 migration 文件后、数据库相关代码 review、上线前检查、性能排查中发现 DB 瓶颈。

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Databases, covering ORMs and data access and SQL. It works with SQL, Prisma, MySQL and SQLAlchemy. The licence is MIT.

When your agent uses it

  • Tasks that involve ORMs and data access
  • Tasks that involve SQL

Example prompts

  • “/db-review”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. 搜索所有 SQL 语句(原生查询、ORM 的 raw query、query builder)
  2. 对每条 SQL 判断是否命中上述反模式
  3. ORM 调用也要检查——findAll() 没加条件等价于 SELECT * 全表扫描

What it can do on your machine

Read from SKILL.md and the folder at commit 2d4fa49. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

DB Review loads about 1.8k tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 500 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from 312362115/claude at commit 2d4fa49, republished under its MIT licence (© 312362115). 500 words, ~1,790 tokens.

Download SKILL.mdSave it as .claude/skills/db-review/SKILL.md (or your agent's skills folder).
name
db-review
description
数据库代码审查 + Migration 安全检查。 代码审查:锁表风险、索引缺失、慢 SQL 模式、N+1 查询。 Migration 审查:破坏性操作、Schema 漂移检测、回滚方案。 适用于 SQL(MySQL/PostgreSQL/SQLite)和 ORM(Prisma/TypeORM/Sequelize/SQLAlchemy/Drizzle)。 触发词:数据库检查、migration 检查、慢 SQL、索引、锁表、schema 漂移、db review。 触发场景:新增/修改 migration 文件后、数据库相关代码 review、上线前检查、性能排查中发现 DB 瓶颈。
version
1.0.0
last_updated
2026-04-09
repository
https://github.com/312362115/claude

数据库审查(DB Review)

数据库问题的修复成本随阶段指数增长:代码审查 < migration 审查 < 上线后排查 < 数据修复。 尽早发现,尽早修复。


第一步:确定审查范围和模式

收到审查请求
  │
  ├─ 代码审查模式(改了数据库相关代码)
  │   └─ 检查 SQL 质量 + 查询性能 + 锁风险
  │
  ├─ Migration 审查模式(新增/修改 migration 文件)
  │   └─ 检查安全性 + Schema 漂移 + 回滚方案
  │
  └─ 全量审查(上线前 / 用户主动要求)
      └─ 代码审查 + Migration 审查 + Schema 一致性
技术栈识别

自动检测项目使用的数据库和 ORM:

检测目标检测方式
Prismaprisma/schema.prisma、@prisma/client
TypeORMtypeorm 依赖、@Entity() 装饰器
Sequelizesequelize 依赖、.define() 调用
Drizzledrizzle-orm 依赖、drizzle.config.ts
SQLAlchemysqlalchemy 依赖、Base.metadata
原生 SQL.sql 文件、query() / execute() 调用
数据库类型连接字符串、驱动依赖(pg/mysql2/better-sqlite3)

第二步:代码审查 — SQL 质量与性能

检查维度 1:慢 SQL 模式

逐条检查以下反模式,对每个发现标注风险等级:

反模式问题正确做法
SELECT *取了不需要的列,浪费 IO 和内存明确列出需要的字段
无 WHERE 的全表查询数据量大时直接拖垮 DB加条件过滤,分页查询
WHERE 中对列使用函数WHERE YEAR(created_at) = 2026 无法走索引改为范围查询 WHERE created_at >= '2026-01-01'
LIKE '%keyword%'前缀通配符无法走索引考虑全文索引或搜索引擎
OR 条件跨列优化器难以使用索引拆成 UNION 或调整索引策略
子查询在 WHERE 中WHERE id IN (SELECT ...) 可能逐行执行改为 JOIN
ORDER BY 无索引支撑大表排序触发 filesort确保排序字段有索引
DISTINCT 掩盖重复通常是 JOIN 写错的信号检查 JOIN 条件是否正确

审查方法:

  1. 搜索所有 SQL 语句(原生查询、ORM 的 raw query、query builder)
  2. 对每条 SQL 判断是否命中上述反模式
  3. ORM 调用也要检查——findAll() 没加条件等价于 SELECT * 全表扫描
检查维度 2:N+1 查询

这是 ORM 项目最常见的性能杀手。

# 反模式:循环中查询
users = User.findAll()
for user in users:
    orders = Order.findAll({ where: { userId: user.id } })  # N 次查询

# 正确:预加载/JOIN
users = User.findAll({ include: [Order] })  # 1 次查询

检查方法:

  1. 搜索循环体内的数据库调用(for/forEach/map 中的 find/query/select)
  2. 检查 ORM 的关联查询是否使用了 eager loading(include/joinedload/with)
  3. 检查 GraphQL resolver 中的数据加载是否使用了 DataLoader
检查维度 3:锁表风险

以下操作在大表上可能导致长时间锁表:

操作MySQL 风险PostgreSQL 风险安全替代
ALTER TABLE ADD COLUMN (有默认值)锁表重写(MySQL < 8.0)8.0+ 大多即时MySQL < 8.0 用 pt-online-schema-change
ALTER TABLE ADD INDEX锁表支持 CONCURRENTLYPG: CREATE INDEX CONCURRENTLY
ALTER TABLE MODIFY COLUMN 改类型锁表重写可能锁表分步迁移:新列 → 同步数据 → 切换
UPDATE 无 WHERE 大批量行锁升级为表锁大量行锁分批更新(每批 1000-5000 行)
DELETE 大批量同上同上分批删除 + 短暂 sleep
长事务中的 DDL锁等待、死锁锁等待DDL 独立事务、短事务

审查方法:

  1. 检查 migration 文件中的 ALTER TABLE 操作
  2. 评估目标表的数据量(如果能拿到)
  3. 大表(>10 万行)的 DDL 操作标记为高风险
检查维度 4:索引审查
检查项问题信号
缺失索引WHERE/JOIN/ORDER BY 中的列没有索引
冗余索引INDEX(a) 和 INDEX(a, b) 并存(前者被后者包含)
过多索引单表 >6 个索引,影响写入性能
索引列顺序复合索引列顺序不符合查询模式(最左前缀原则)
低选择性索引在布尔/状态等低基数列上建索引(通常无效)
未使用索引有索引但查询没走到(函数包裹、类型不匹配)

审查方法:

  1. 读取 schema/migration 中的索引定义
  2. 对照查询语句的 WHERE/JOIN/ORDER BY 检查索引覆盖
  3. ORM 的 @Index()/index: true 也要检查
检查维度 5:事务与并发
检查项关注点
事务范围事务是否过大?包含了不必要的操作?
死锁风险多个事务是否以不同顺序操作同一组表?
隔离级别是否使用了过高的隔离级别(SERIALIZABLE)?
连接泄漏事务/连接是否在异常路径中正确释放?
乐观锁并发更新场景是否有版本号/乐观锁保护?

第三步:Migration 审查 — 安全性与一致性

Show full SKILL.md (217 more words)Show less
3.1 破坏性操作检查

以下操作不可逆或有数据丢失风险,必须标记为高风险:

操作风险安全做法
DROP TABLE数据永久丢失先备份、确认无引用、保留回滚窗口
DROP COLUMN列数据丢失确认代码已移除引用后再删列
RENAME TABLE/COLUMN代码引用断裂分步:新建 → 同步 → 切换 → 清理旧的
TRUNCATE数据清空不应出现在 migration 中
ALTER COLUMN 收窄类型数据截断先检查现有数据是否溢出
NOT NULL 约束(已有数据列)空值行报错先填充默认值再加约束

审查方法:

  1. 逐行读 migration 文件,标记所有 DROP/RENAME/ALTER 操作
  2. 每个破坏性操作必须有对应的回滚方案(down migration)
  3. 检查 down migration 是否真的能回滚(不是空函数)
3.2 Schema 漂移检测

这是你反复踩坑的问题:本地和服务端 schema 不一致、缺字段。

漂移来源:

1. 手动改了数据库但没写 migration(最常见)
2. migration 执行顺序不一致(分支合并后)
3. migration 只跑了一半(报错后手动修了但没记录)
4. ORM 的 model 定义和 migration 不同步
5. 多人开发时 migration 文件冲突

检查流程:

Step 1: 收集当前 Schema 定义来源
  ├─ ORM model/entity 定义(代码中的"应该是什么")
  ├─ Migration 文件链("变更历史")
  └─ 数据库实际状态(如果能连接)

Step 2: 交叉比对
  ├─ Model vs Migration:model 里的字段/类型/约束是否都有对应的 migration?
  ├─ Migration 完整性:migration 链是否连续?有没有遗漏?
  └─ 新增字段检查:最近加的字段有 migration 吗?默认值/可空设置对吗?

Step 3: 输出不一致清单
  每条记录:字段名、model 中的定义、migration 中的定义、差异描述

具体检查项:

检查项方法
Model 和 Migration 字段一致遍历 model 所有字段,确认每个字段在 migration 链中有对应的 CREATE/ALTER
类型一致model 中的类型(String/Int/DateTime)和 migration 中的 SQL 类型匹配
可空性一致model 标记 optional/nullable 的字段,migration 中没加 NOT NULL
默认值一致model 中有 @default() 的字段,migration 中有 DEFAULT
索引一致model 中 @index/@unique 的字段,migration 中有对应的 INDEX
关联关系一致model 中的外键关系,migration 中有对应的 FOREIGN KEY
migration 时间线连续按时间戳排序,检查有没有跳跃或冲突
3.3 回滚方案检查

每个 migration 必须有可执行的回滚方案:

检查项要求
down/rollback 函数存在不能是空函数或 throw new Error('not implemented')
down 函数逻辑正确up 中加的列,down 中要删;up 中改的类型,down 中要改回
数据恢复破坏性操作的 down 需要说明数据恢复策略(即使无法完全自动恢复)
3.4 Migration 最佳实践
实践要求
单一职责一个 migration 只做一件事(加表、加列、加索引分开)
可重复执行migration 应该幂等,重复运行不报错(IF NOT EXISTS)
数据迁移分离schema 变更和数据填充放在不同的 migration 中
命名规范文件名能反映操作内容(add_email_to_users 而非 migration_042)

第四步:风险分级与输出

风险等级
等级标准处理要求
高危数据丢失、锁表超 30s、schema 漂移(已知不一致)、无回滚方案必须修复,给出具体方案
中危性能隐患(N+1、缺索引)、回滚方案不完整、潜在的并发问题建议修复,给出方向
低危最佳实践缺失(命名、注释、冗余索引)、小表操作记录,不阻断
输出格式

快速审查(终端输出):

## DB Review 结果

🔴 高危 x N | 🟡 中危 x N | 🟢 低危 x N

### 高危
1. [锁表风险] migrations/20260409_add_index.sql:15 — 大表加索引未用 CONCURRENTLY
   → 修复:`CREATE INDEX CONCURRENTLY idx_users_email ON users(email);`

### 中危
1. [N+1] src/services/order.ts:42 — 循环内查询用户信息
   → 修复:使用 include/joinedload 预加载

### Schema 漂移
- ⚠️ User.phone: model 中存在(String, optional),但无对应 migration
- ⚠️ Order.discount: model 类型 Decimal,migration 中为 Float

完整审查时,生成报告到 docs/audits/YYYY-MM-DD-db-review.md。


与其他 skill 的衔接

代码开发中
  │
  ├─ 改了数据库代码?→ task-finish 自检时提示跑 db-review(代码审查模式)
  ├─ 新增 migration?→ 提交前跑 db-review(migration 审查模式)
  │
  ↓ 上线前
  ├─ security-audit 审查注入防护(SQL 注入维度)
  └─ db-review 全量审查(Schema 漂移 + 锁表 + 性能)
  • perf-profiling:发现 DB 慢查询后,交给 db-review 做 SQL 层面的深度分析
  • security-audit:SQL 注入是安全问题,由 security-audit 负责;查询性能是 db-review 负责
  • task-finish:改动涉及 migration 文件时,提示跑 db-review

注意事项

  • 先理解业务再审查:脱离业务的索引建议是无意义的。先搞清楚查询频率和数据量
  • 小表不教条:几百行的配置表不需要纠结索引优化
  • ORM 不是借口:ORM 生成的 SQL 也可能很烂,必要时看生成的实际 SQL
  • 环境差异:本地 SQLite + 生产 PostgreSQL 时,migration 语法差异是漂移的常见来源
  • 不替代 DBA:复杂的分库分表、主从延迟等架构级问题需要 DBA 介入

© 312362115, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/db-review of 312362115/claude.

Open the folder on GitHubat commit 2d4fa49

Compare with similar skills

DB Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

DB Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
DB Review this skill312362115/claude107—~1.8kAutomated safety check: PassMIT
SQL Database Assistantalirezarezvani/claude-skills28k—~4kAutomated safety check: PassMIT
Dsqlawslabs/agent-plugins916—~7.1kAutomated safety check: PassApache-2.0
Database Testingpetrkindlmann/qa-skills170—~4.2kAutomated safety check: PassMIT
Tsh SQL And Database UnderstandingTheSoftwareHouse/copilot-collections284—~11kAutomated safety check: PassMIT
Database FundamentalsDanielPodolsky/ownyourcode2901 repos~1.6kAutomated safety check: PassMIT

Similar skills

  • SQL Database Assistant

    alirezarezvani/claude-skills

    A skill your agent uses when the user asks to write SQL queries, optimize database performance, generate migrations, explore database schemas, or work with ORMs like Prisma, Drizzle, TypeORM, or…

    28k GitHub stars~4k tokensUpdated 1 mo ago
    DatabasesAuto-check passed
  • Dsql

    awslabs/agent-plugins

    Official

    Build with Aurora DSQL — manage schemas, execute queries, handle migrations, diagnose query plans, diagnose cluster performance, load data, and develop applications with a serverless, distributed…

    916 GitHub stars~7.1k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Database Testing

    petrkindlmann/qa-skills

    Validate database integrity, test migrations forward and backward, verify schema constraints, manage seed data, detect migration drift, and identify query performance issues.

    170 GitHub stars~4.2k tokensUpdated 4 mo ago
    DatabasesAuto-check passed
  • Tsh SQL And Database Understanding

    TheSoftwareHouse/copilot-collections

    SQL writing and database engineering patterns, standards, and procedures.

    284 GitHub stars~11k tokensUpdated 5 days ago
    DatabasesAuto-check passed
  • Database Fundamentals

    DanielPodolsky/ownyourcode

    Reviews schema design, SQL queries, ORM patterns. An agent skill from DanielPodolsky/ownyourcode.

    290 GitHub starsUsed in 1 repo~1.6k tokens
    DatabasesAuto-check passed
  • Database Expert

    cin12211/orca-q

    Database performance optimization, schema design, query analysis, and connection management across PostgreSQL, MySQL, MongoDB, and SQLite with ORM integration.

    224 GitHub stars~2.8k tokensUpdated 19 days ago
    DatabasesAuto-check passed

More from 312362115/claude

All 20 skills in this repo
  • Diagram

    312362115/claude

    专业图表生成技能:根据需求自动选择合适的图表类型,生成符合设计规范的 PNG 图表. An agent skill from 312362115/claude.

    107 GitHub stars~2.7k tokensUpdated 5 mo ago
    Auto-check passed
  • Deep Research

    312362115/claude

    深度调研技能:对任意命题进行系统性调研并输出专业研究报告. An agent skill from 312362115/claude.

    107 GitHub stars~6.6k tokensUpdated 5 mo ago
    Auto-check passed
  • Preview Md

    312362115/claude

    MD 文件浏览器预览:GitHub 风格渲染 + 左侧自动目录. An agent skill from 312362115/claude.

    107 GitHub stars~636 tokensUpdated 5 mo ago
    Auto-check passed
  • Writing

    312362115/claude

    通用写作技能:以"内容→组件→组合"的方式产出技术文档、产品文档、汇报材料. An agent skill from 312362115/claude.

    107 GitHub stars~1.6k tokensUpdated 5 mo ago
    Auto-check passed
  • Code Walkthrough

    312362115/claude

    代码导读技能:帮助快速理解不熟悉的项目或模块,建立心智模型. An agent skill from 312362115/claude.

    107 GitHub stars~1k tokensUpdated 5 mo ago
    Auto-check: notes
  • Dependency Map

    312362115/claude

    依赖关系分析技能:回答"改这里会影响哪里". An agent skill from 312362115/claude.

    107 GitHub stars~888 tokensUpdated 5 mo ago
    Auto-check passed

Categories

Questions about DB Review

What does DB Review do?

数据库代码审查 + Migration 安全检查. An agent skill from 312362115/claude. DB Review is an agent skill from 312362115/claude.

When should I use DB Review?

DB Review fits situations like: tasks that involve ORMs and data access; tasks that involve SQL.

How do I install DB Review in Claude Code?

Run `npx skills add 312362115/claude --skill db-review -a claude-code`. Or copy the skill folder (skills/db-review in 312362115/claude) into .claude/skills/db-review in your project. Claude Code loads it when a task matches its description.

How do I install DB Review in Codex?

Run `npx skills add 312362115/claude --skill db-review -a codex`. Or copy the skill folder (skills/db-review in 312362115/claude) into .agents/skills/db-review in your project. Codex loads it when a task matches its description.

Can I use DB Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add 312362115/claude --skill db-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/db-review, .gemini/skills/db-review, .github/skills/db-review and .opencode/skills/db-review in your project.

What does DB Review need to run?

SKILL.md names no scripts, command-line tools or credentials: DB Review is instructions for the agent only.

Does DB Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is DB Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does DB Review use?

DB Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does DB Review use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to DB Review?

Skills that share tags, products or a category with DB Review: SQL Database Assistant (alirezarezvani/claude-skills, 28k stars), Dsql (awslabs/agent-plugins, 916 stars), Database Testing (petrkindlmann/qa-skills, 170 stars) and Tsh SQL And Database Understanding (TheSoftwareHouse/copilot-collections, 284 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains DB Review?

312362115 (a GitHub user) maintains it in 312362115/claude, which has 107 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on May 14, 2026.

Source: 312362115/claude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.