Web Sqli
s0ld13rr/pentestcode
SQL injection detection→exploitation→proof for web apps and APIs.
A skill your agent uses when handling database errors in Frappe/ERPNext.
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-database -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-database --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/source/errors/frappe-errors-database .claude/skills/frappe-errors-database && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "frappe-errors-database" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-database into .claude/skills/frappe-errors-database/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-database", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-databaseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-database -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-database --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/source/errors/frappe-errors-database .agents/skills/frappe-errors-database && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "frappe-errors-database" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-database into .agents/skills/frappe-errors-database/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-database", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-database -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-database --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/source/errors/frappe-errors-database .cursor/skills/frappe-errors-database && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "frappe-errors-database" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-database into .cursor/skills/frappe-errors-database/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-database", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git --path skills/source/errors/frappe-errors-database--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-database -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-database --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/source/errors/frappe-errors-database .gemini/skills/frappe-errors-database && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "frappe-errors-database" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-database into .gemini/skills/frappe-errors-database/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-database", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-databaseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-database -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/source/errors/frappe-errors-database .github/skills/frappe-errors-database && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "frappe-errors-database" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-database into .github/skills/frappe-errors-database/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-database", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-database -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-database --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/source/errors/frappe-errors-database .opencode/skills/frappe-errors-database && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "frappe-errors-database" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-database into .opencode/skills/frappe-errors-database/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-database", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
frappe-errors-databaseA skill your agent uses when handling database errors in Frappe/ERPNext.
Frappe Errors Database is an agent skill from Impertio-Studio/Frappe_Claude_Skill_Package. Use when handling database errors in Frappe/ERPNext. Covers DuplicateEntryError, LinkValidationError, MandatoryError, TimestampMismatchError, CharacterLengthExceededError, InReadOnlyMode, QueryTimeoutError, SQL injection errors, frappe.db.sql parameter format (% vs %s), getvalue returning None, transaction deadlocks, MariaDB gone away, too many connections. Error-to-fix mapping for v14/v15/v16. Keywords: database error, DuplicateEntryError, TimestampMismatchError,, MariaDB error, MySQL error, column not found…
Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/anti-patterns.md`, `references/examples.md` and `references/patterns.md`). Compatibility notes: Claude Code, Claude.ai Projects, Claude API. Frappe v14-v16.
It sits in Security, covering Web application vulnerabilities and SQL. It works with MariaDB, SQL and MySQL. The repository describes itself as: 60 deterministic Claude AI skills for Frappe Framework & ERPNext v14-v16 development and operations. The licence is MIT.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 36cfa80. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Claude Code, Claude.ai Projects, Claude API. Frappe v14-v16.
From compatibility in the SKILL.md frontmatter.
Frappe Errors Database loads about 3.9k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 162 tokens; SKILL.md has 567 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Impertio-Studio/Frappe_Claude_Skill_Package at commit 36cfa80, republished under its MIT licence (© Impertio-Studio). 567 words, ~3,881 tokens.
.claude/skills/frappe-errors-database/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Cross-ref: frappe-core-database (API syntax), frappe-errors-controllers (controller errors).
| Error / Exception | HTTP | Cause | Fix |
|---|---|---|---|
DuplicateEntryError | 409 | Unique constraint violation on insert/rename | Check existence first OR catch and return existing |
DoesNotExistError | 404 | get_doc() on missing record | Use frappe.db.exists() first OR catch exception |
LinkValidationError | 417 | Link field points to non-existent record | Validate link target exists before save |
LinkExistsError | N/A | Delete blocked by linked documents | Show linked docs to user; use force=True carefully |
MandatoryError | 417 | Required field is empty on save | Set all mandatory fields before insert/save |
TimestampMismatchError | N/A | Concurrent edit detected (modified changed) | Reload doc and retry, or inform user to refresh |
CharacterLengthExceededError | 417 | String exceeds field maxlength / DB column size | Truncate input or increase field length |
DataTooLongException | 417 | Value exceeds DB column storage capacity | Same as CharacterLengthExceededError |
InReadOnlyMode | 503 | Write attempted during read-only mode | Check frappe.flags.in_import or site config |
QueryTimeoutError | N/A | Query exceeded time limit [v15+] | Add indexes, reduce result set, paginate |
QueryDeadlockError | N/A | Two transactions waiting on each other | Retry with backoff; reduce transaction scope |
TooManyWritesError | N/A | Excessive writes in single request | Batch operations; use background jobs |
InternalError (gone away) | N/A | MariaDB connection dropped | Reconnect with frappe.db.connect() |
InternalError (too many) | N/A | Connection pool exhausted | Check max_connections; close idle connections |
ValidationError | 417 | General validation failure in save | Read error message; fix field values |
| SQL syntax error | N/A | Wrong frappe.db.sql() parameter format | Use %(name)s with dict, NOT %s with tuple |
Exception
├── frappe.ValidationError (HTTP 417)
│ ├── frappe.MandatoryError
│ ├── frappe.LinkValidationError
│ ├── frappe.CharacterLengthExceededError
│ ├── frappe.DataTooLongException
│ ├── frappe.UniqueValidationError
│ ├── frappe.UpdateAfterSubmitError
│ └── frappe.DataError
├── frappe.DoesNotExistError (HTTP 404)
├── frappe.DuplicateEntryError (HTTP 409) ← inherits NameError
├── frappe.TimestampMismatchError
├── frappe.LinkExistsError
├── frappe.QueryTimeoutError
├── frappe.QueryDeadlockError
├── frappe.TooManyWritesError
├── frappe.InReadOnlyMode (HTTP 503)
└── frappe.db.InternalError ← MariaDB/Postgres driver error# ❌ WRONG — %s with positional tuple (works but fragile)
frappe.db.sql("SELECT * FROM `tabItem` WHERE name = %s", ("ITEM-001",))
# ❌ WRONG — f-string or .format() — SQL INJECTION!
frappe.db.sql(f"SELECT * FROM `tabItem` WHERE name = '{item_name}'")
frappe.db.sql("SELECT * FROM `tabItem` WHERE name = '{}'".format(item_name))
# ❌ WRONG — bare % operator
frappe.db.sql("SELECT * FROM `tabItem` WHERE name = '%s'" % item_name)
# ✅ CORRECT — named parameters with dict (ALWAYS use this)
frappe.db.sql(
"SELECT * FROM `tabItem` WHERE name = %(name)s AND warehouse = %(wh)s",
{"name": item_name, "wh": warehouse},
as_dict=True
)
# ✅ CORRECT — frappe.qb (query builder, no injection risk)
Item = frappe.qb.DocType("Item")
result = (
frappe.qb.from_(Item)
.select(Item.name, Item.item_name)
.where(Item.warehouse == warehouse)
.run(as_dict=True)
)Rule: ALWAYS use %(name)s with a dict parameter. NEVER use string formatting for SQL values.
# ❌ DANGEROUS — get_value returns None, not raises
credit = frappe.db.get_value("Customer", "CUST-001", "credit_limit")
if credit > 1000: # TypeError: '>' not supported between NoneType and int
pass
# ✅ CORRECT — handle None explicitly
credit = frappe.db.get_value("Customer", "CUST-001", "credit_limit")
if credit is None:
frappe.throw(_("Customer not found"))
credit = credit or 0 # Default to 0 if field is empty
# ✅ CORRECT — get_value with as_dict for multiple fields
data = frappe.db.get_value("Customer", "CUST-001",
["credit_limit", "disabled"], as_dict=True)
if not data: # None when record not found
frappe.throw(_("Customer not found"))
if data.disabled:
frappe.throw(_("Customer is disabled"))Key behavior by method:
| Method | Record Not Found | Empty Field |
|---|---|---|
get_doc() | Raises DoesNotExistError | Returns field default |
get_value() | Returns None | Returns None or "" |
get_all() | Returns [] | Included in result |
exists() | Returns False | N/A |
set_value() | Silently does nothing | N/A |
db.sql() | Returns [] or () | Included in result |
# Pattern: Insert with duplicate handling
def create_or_get(doctype, data):
try:
doc = frappe.get_doc({"doctype": doctype, **data})
doc.insert()
return doc
except frappe.DuplicateEntryError:
# Race condition safe: someone else created it
name = frappe.db.get_value(doctype, data, "name")
return frappe.get_doc(doctype, name)# Pattern: Concurrent edit detection
try:
doc = frappe.get_doc("Sales Invoice", name)
doc.update(updates)
doc.save()
except frappe.TimestampMismatchError:
frappe.throw(
_("Document modified by another user. Please refresh and try again."),
title=_("Concurrent Edit")
)# Pattern: Pre-validate before save
def safe_create_invoice(data):
errors = []
# Check mandatory fields
if not data.get("customer"):
errors.append(_("Customer is required"))
if not data.get("items"):
errors.append(_("At least one item is required"))
# Check link validity
if data.get("customer"):
if not frappe.db.exists("Customer", data["customer"]):
errors.append(_("Customer '{0}' not found").format(data["customer"]))
if errors:
frappe.throw("<br>".join(errors))
doc = frappe.get_doc({"doctype": "Sales Invoice", **data})
doc.insert()
return doc# Pattern: Truncate before save
def safe_set_description(doc, description):
max_len = 140 # Match field length in DocType
if len(description) > max_len:
description = description[:max_len - 3] + "..."
frappe.msgprint(_("Description truncated to {0} characters").format(max_len))
doc.description = description# Pattern: Paginated query to avoid timeout
def get_large_report(filters):
try:
return frappe.db.sql(query, filters, as_dict=True)
except frappe.QueryTimeoutError:
frappe.log_error(frappe.get_traceback(), "Report Query Timeout")
frappe.throw(
_("Report too large. Please narrow your date range or add filters."),
title=_("Query Timeout")
)# Pattern: Check before write
def safe_write(doctype, name, field, value):
if frappe.flags.in_import:
frappe.db.set_value(doctype, name, field, value)
return
try:
frappe.db.set_value(doctype, name, field, value)
except frappe.InReadOnlyMode:
frappe.log_error(f"Write blocked: {doctype}/{name}", "Read-Only Mode")
frappe.throw(_("System is in read-only mode. Please try again later."))# ❌ CAUSES DEADLOCKS — long transaction with many writes
def process_all():
for inv in frappe.get_all("Sales Invoice", limit=10000):
doc = frappe.get_doc("Sales Invoice", inv.name)
doc.custom_field = "value"
doc.save() # Each save locks rows; other processes wait
# ✅ CORRECT — batch with commits to release locks
def process_all():
invoices = frappe.get_all("Sales Invoice", limit=10000)
BATCH = 100
for i in range(0, len(invoices), BATCH):
for inv in invoices[i:i + BATCH]:
frappe.db.set_value("Sales Invoice", inv.name, "custom_field", "value")
frappe.db.commit() # Release locks after each batch
# ✅ CORRECT — retry on deadlock
import time
def with_deadlock_retry(func, max_retries=3):
for attempt in range(max_retries):
try:
return func()
except frappe.QueryDeadlockError:
if attempt < max_retries - 1:
frappe.db.rollback()
time.sleep(0.5 * (attempt + 1))
else:
raise# Pattern: Connection recovery
def reliable_operation():
try:
return frappe.db.sql("SELECT 1")
except frappe.db.InternalError as e:
msg = str(e).lower()
if "gone away" in msg or "lost connection" in msg:
frappe.db.connect() # Reconnect
return frappe.db.sql("SELECT 1")
if "too many connections" in msg:
frappe.log_error("Too many DB connections", "Connection Pool")
frappe.throw(_("Server busy. Please try again in a moment."))
raise # Unknown InternalError — re-raisePrevention:
wait_timeout in MariaDB config (default 28800s)max_connections setting matches your workload| Context | Auto-Commit? | Manual Commit? |
|---|---|---|
| Web request (POST/PUT) | YES | NEVER |
| Controller hooks (validate, on_update) | YES | NEVER |
| doc_events hooks | YES | NEVER |
| Scheduler tasks | NO | ALWAYS |
| Background jobs (frappe.enqueue) | NO | ALWAYS |
| bench execute | NO | ALWAYS |
def complex_operation():
frappe.db.savepoint("before_risky")
try:
risky_database_operation()
except Exception:
frappe.db.rollback(save_point="before_risky")
safe_alternative() # Continue with fallback
# Transaction hooks [v15+]
frappe.db.after_commit.add(lambda: send_notification())
frappe.db.after_rollback.add(lambda: cleanup_files())# ❌ INJECTION VULNERABLE — all of these
frappe.db.sql(f"SELECT * FROM `tabItem` WHERE name = '{user_input}'")
frappe.db.sql("SELECT * FROM `tabItem` WHERE name = '%s'" % user_input)
frappe.db.sql("SELECT * FROM `tabItem` WHERE name = '{}'".format(user_input))
# ❌ ALSO VULNERABLE — in permission_query_conditions
def query_conditions(user):
return f"owner = '{user}'" # Unescaped!
# ✅ SAFE — parameterized query
frappe.db.sql("SELECT * FROM `tabItem` WHERE name = %(name)s", {"name": user_input})
# ✅ SAFE — frappe.db.escape() for dynamic SQL (permission hooks)
def query_conditions(user):
return f"owner = {frappe.db.escape(user)}"
# ✅ SAFE — query builder
Item = frappe.qb.DocType("Item")
frappe.qb.from_(Item).where(Item.name == user_input).run()
# ✅ SAFE — ORM methods
frappe.get_all("Item", filters={"name": user_input})
frappe.db.get_value("Item", user_input, "item_name")# ❌ DANGEROUS — no error if record doesn't exist
frappe.db.set_value("Customer", "NONEXISTENT", "status", "Active")
# Returns without error! No rows updated.
# ✅ ALWAYS verify existence before set_value
if not frappe.db.exists("Customer", customer_name):
frappe.throw(_("Customer '{0}' not found").format(customer_name))
frappe.db.set_value("Customer", customer_name, "status", "Active")
# Note: set_value skips validate/on_update hooks
# Use doc.save() when you need validation to run%(name)s dict params in frappe.db.sql() — NEVER string formattingfrappe.db.exists() before get_doc() — or catch DoesNotExistErrorDuplicateEntryError on every insert() callTimestampMismatchError on every save() in APIsfrappe.db.commit() in scheduler and background jobslimit parameterget_value() result for None before using itfrappe.db.escape() in dynamic SQL stringsf"", .format(), %) for SQL valuesfrappe.db.commit() in controller hooks or doc_eventsException and pass — log or re-raise specific typesdb.set_value() succeeded — it fails silently on missing recordslimit — memory/timeout risktry:
doc = frappe.get_doc("Customer", name)
except frappe.DoesNotExistError:
frappe.throw(_("Not found"))
try:
doc.insert()
except frappe.DuplicateEntryError:
existing = frappe.db.get_value("Customer", filters, "name")
except frappe.MandatoryError as e:
frappe.throw(_("Missing required field: {0}").format(e))
try:
doc.save()
except frappe.TimestampMismatchError:
frappe.throw(_("Document modified. Please refresh."))
except frappe.CharacterLengthExceededError:
frappe.throw(_("Text too long for field"))
try:
frappe.delete_doc("Customer", name)
except frappe.LinkExistsError:
frappe.throw(_("Cannot delete — linked documents exist"))
try:
frappe.db.sql(query, values)
except frappe.QueryTimeoutError: # [v15+]
frappe.throw(_("Query too slow. Add filters."))
except frappe.QueryDeadlockError:
frappe.db.rollback() # Retry with backoff
except frappe.db.InternalError as e:
frappe.log_error(frappe.get_traceback(), "DB Error")| File | Contents |
|---|---|
references/patterns.md | Complete error handling patterns for all DB operations |
references/examples.md | Full working examples with error handling |
references/anti-patterns.md | Common mistakes with wrong/correct pairs |
frappe-core-database — Database API syntax and query builderfrappe-errors-controllers — Controller error handlingfrappe-errors-hooks — Hook error handlingfrappe-core-permissions — Permission patterns© Impertio-Studio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/source/errors/frappe-errors-database of Impertio-Studio/Frappe_Claude_Skill_Package.
Open the folder on GitHubat commit 36cfa80
Frappe Errors Database next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Frappe Errors Database this skillImpertio-Studio/Frappe_Claude_Skill_Package | 187 | — | ~3.9k | Automated safety check: Pass | MIT | |
| Web Sqlis0ld13rr/pentestcode | 817 | — | ~710 | Automated safety check: Pass | MIT | |
| Golang Databaseunxed/f4 | 240 | 2 repos | ~2.9k | Automated safety check: Pass | MIT | |
| SQL Code Reviewgithub/awesome-copilot | 40k | 1 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Mysqlericrisco/rsc-harness | 156 | — | ~3.7k | Automated safety check: Pass | MIT | |
| Tsh SQL And Database UnderstandingTheSoftwareHouse/copilot-collections | 284 | — | ~11k | Automated safety check: Pass | MIT |
s0ld13rr/pentestcode
SQL injection detection→exploitation→proof for web apps and APIs.
unxed/f4
Comprehensive guide for Go database access — parameterized queries, struct scanning, NULLable columns, transactions, isolation levels, SELECT FOR UPDATE, connection pool, batch processing, context…
github/awesome-copilot
Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across all SQL databases (MySQL, PostgreSQL, SQL Server, Oracle).
ericrisco/rsc-harness
A skill your agent uses when designing, querying, indexing or operating a MySQL or MariaDB database and engine-specific behaviour matters — schema and type choices, index design, reading EXPLAIN…
TheSoftwareHouse/copilot-collections
SQL writing and database engineering patterns, standards, and procedures.
0xShe/PHP-Code-Audit-Skill
ThinkPHP 框架特效安全审计工具。针对 ThinkPHP 常见的鉴权/CSRF/模板转义/ORM 写入(Mass Assignment)/调试与配置暴露等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/TPL/XSS/LOGIC/CFG/SESS/SQL 等)。
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when receiving vague or unclear ERPNext/Frappe development requests that need interpretation.
Impertio-Studio/Frappe_Claude_Skill_Package
Deploy HTML/CSS websites to ERPNext/Frappe (v15/v16) as Web Pages via the REST API.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when building ERPNext/Frappe API integrations (v14/v15/v16) including REST API, RPC API, authentication, webhooks, and rate limiting.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when implementing hooks.py configurations in a Frappe custom app.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when building API endpoints with @frappe.whitelist() in Frappe.
A skill your agent uses when handling database errors in Frappe/ERPNext. Frappe Errors Database is an agent skill from Impertio-Studio/Frappe_Claude_Skill_Package. Use when handling database errors in Frappe/ERPNext.
Frappe Errors Database fits situations like: handling database errors in Frappe/ERPNext; tasks that involve Web application vulnerabilities; tasks that involve SQL.
Run `npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-database -a claude-code`. Or copy the skill folder (skills/source/errors/frappe-errors-database in Impertio-Studio/Frappe_Claude_Skill_Package) into .claude/skills/frappe-errors-database in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-database -a codex`. Or copy the skill folder (skills/source/errors/frappe-errors-database in Impertio-Studio/Frappe_Claude_Skill_Package) into .agents/skills/frappe-errors-database in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-database -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/frappe-errors-database, .gemini/skills/frappe-errors-database, .github/skills/frappe-errors-database and .opencode/skills/frappe-errors-database in your project.
SKILL.md names no scripts, command-line tools or credentials: Frappe Errors Database is instructions for the agent only. Our summary lists: Python 3. Compatibility (from SKILL.md): Claude Code, Claude.ai Projects, Claude API. Frappe v14-v16..
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Frappe Errors Database is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Frappe Errors Database: Web Sqli (s0ld13rr/pentestcode, 817 stars), Golang Database (unxed/f4, 240 stars), SQL Code Review (github/awesome-copilot, 40k stars) and Mysql (ericrisco/rsc-harness, 156 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Impertio-Studio (a GitHub organization) maintains it in Impertio-Studio/Frappe_Claude_Skill_Package, which has 187 GitHub stars. The repository holds 61 skills in this directory. The repository was last updated on September 17, 2026.
Source: Impertio-Studio/Frappe_Claude_Skill_Package on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.