SQL Code Review
github/awesome-copilot
Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across all SQL databases (MySQL, PostgreSQL, SQL Server, Oracle).
执行代码质量检查测试,基于阿里巴巴 P3C 规范对代码进行全面检查,包括命名规范、异常处理、并发安全、数据库规范、OOP 规范、安全规约和单元测试规范。Invoke when user needs to verify code quality against P3C standards.
$ npx skills add LeoYeAI/openclaw-master-skills --skill p3c-code-quality -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills p3c-code-quality --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/p3c-code-quality .claude/skills/p3c-code-quality && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "p3c-code-quality" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/p3c-code-quality into .claude/skills/p3c-code-quality/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "p3c-code-quality", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/p3c-code-qualityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LeoYeAI/openclaw-master-skills --skill p3c-code-quality -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills p3c-code-quality --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/p3c-code-quality .agents/skills/p3c-code-quality && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "p3c-code-quality" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/p3c-code-quality into .agents/skills/p3c-code-quality/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "p3c-code-quality", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill p3c-code-quality -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills p3c-code-quality --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/p3c-code-quality .cursor/skills/p3c-code-quality && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "p3c-code-quality" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/p3c-code-quality into .cursor/skills/p3c-code-quality/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "p3c-code-quality", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LeoYeAI/openclaw-master-skills.git --path skills/p3c-code-quality--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LeoYeAI/openclaw-master-skills --skill p3c-code-quality -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills p3c-code-quality --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/p3c-code-quality .gemini/skills/p3c-code-quality && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "p3c-code-quality" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/p3c-code-quality into .gemini/skills/p3c-code-quality/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "p3c-code-quality", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LeoYeAI/openclaw-master-skills p3c-code-qualityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LeoYeAI/openclaw-master-skills --skill p3c-code-quality -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/p3c-code-quality .github/skills/p3c-code-quality && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "p3c-code-quality" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/p3c-code-quality into .github/skills/p3c-code-quality/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "p3c-code-quality", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill p3c-code-quality -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills p3c-code-quality --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/p3c-code-quality .opencode/skills/p3c-code-quality && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "p3c-code-quality" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/p3c-code-quality into .opencode/skills/p3c-code-quality/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "p3c-code-quality", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
p3c-code-quality执行代码质量检查测试,基于阿里巴巴 P3C 规范对代码进行全面检查,包括命名规范、异常处理、并发安全、数据库规范、OOP 规范、安全规约和单元测试规范。Invoke when user needs to verify code quality against P3C standards.
P3c Code Quality is an agent skill from LeoYeAI/openclaw-master-skills. 执行代码质量检查测试,基于阿里巴巴 P3C 规范对代码进行全面检查,包括命名规范、异常处理、并发安全、数据库规范、OOP 规范、安全规约和单元测试规范。Invoke when user needs to verify code quality against P3C standards.
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `_meta.json`).
It sits in Development, covering Code quality. It works with MySQL, Java and SQL. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are java, markdown and yaml).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
P3c Code Quality loads about 2.8k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 586 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 586 words, ~2,752 tokens.
.claude/skills/p3c-code-quality/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.本技能基于阿里巴巴Java开发手册P3C规范,对代码进行全面的质量检查测试。
本测试技能涵盖以下P3C规范领域:
本技能使用 Trae IDE 内置工具进行代码质量检查,无需额外脚本:
Glob 工具查找所有 .java 文件Read 工具读取文件内容SearchCodebase 进行代码结构分析GetDiagnostics 获取编译错误和警告Grep 工具配合正则表达式匹配 P3C 规范违规Write 工具生成 Markdown 格式报告文件查找工具
Glob - 查找所有 .java 文件LS - 列出目录结构代码读取工具
Read - 读取文件内容SearchCodebase - 搜索代码库中的特定模式和结构代码分析工具
Grep - 使用正则表达式搜索代码,匹配 P3C 规则GetDiagnostics - 获取 Trae IDE 的语言诊断信息(编译错误、警告等)报告生成工具
Write - 生成 Markdown 格式的测试报告本技能是聚合技能,会调用以下子技能进行详细检查:
| 子技能 | 描述 | 检查内容 |
|---|---|---|
| p3c-coding-style | 代码风格规范 | 命名风格、代码格式、常量定义、注释规约 |
| p3c-exception-logging | 异常与日志规范 | 异常处理、日志规约、NPE防护 |
| p3c-advanced-coding | 高级编程规范 | 集合处理、并发处理、控制语句 |
| p3c-mysql-database | MySQL数据库规范 | 建表规约、SQL语句、索引规约、ORM映射 |
| p3c-oop-standards | OOP编程规范 | 方法覆写、equals/hashCode、包装类、序列化 |
| p3c-security-rules | 安全规约 | 权限控制、SQL注入防护、XSS/CSRF防护、参数验证 |
| p3c-unit-testing | 单元测试规范 | AIR原则、测试粒度、测试覆盖率、BCDE原则 |
使用 Trae IDE 内置工具扫描指定的Java源代码文件或目录:
Glob 查找所有 .java 文件Read 读取文件内容SearchCodebase 进行代码结构分析GetDiagnostics 获取编译诊断信息根据P3C规范对代码进行逐项检查。本技能是聚合技能,会调用以下子技能进行详细检查:
p3c-coding-style - 代码风格规范
p3c-exception-logging - 异常与日志规范
p3c-advanced-coding - 高级编程规范
p3c-mysql-database - MySQL数据库规范
p3c-oop-standards - OOP编程规范
p3c-security-rules - 安全规约
p3c-unit-testing - 单元测试规范
使用 Grep 工具配合正则表达式匹配代码中的P3C规范违规:
将检查到的问题按严重程度分类:
使用 Write 工具生成详细的测试报告,包含:
执行测试时需要提供以下参数:
测试报告将生成到以下路径:
doc/{业务名称}/测试报告/{测试内容}/{测试接口名称}_{时间戳}.md报告包含以下内容:
按P3C规范类别统计问题分布
每个问题包含:
输入:
- 代码路径:src/main/java/com/example/UserService.java
- 业务名称:用户管理
- 测试内容:代码质量检查
- 测试接口名称:UserService
输出:
- 报告路径:doc/用户管理/测试报告/代码质量检查/UserService_20250103143025.md输入:
- 代码路径:src/main/java/com/example/order/
- 业务名称:订单系统
- 测试内容:代码质量检查
- 测试接口名称:OrderModule
输出:
- 报告路径:doc/订单系统/测试报告/代码质量检查/OrderModule_20250103143025.md# P3C 代码质量检查报告
## 基本信息
- 测试时间:2026-03-11 14:30:25
- 测试人员:AI Assistant
- 测试范围:src/main/java/com/bgyfw/parking/
- P3C 版本:《阿里巴巴 Java 开发手册》2022 版
## 问题统计
- 问题总数:15
- 致命问题:2
- 严重问题:5
- 一般问题:6
- 轻微问题:2
## 问题详情
### 致命问题
【问题编号】P3C-001
【严重程度】致命
【规范类别】p3c-security-rules
【规则描述】SQL 注入防护 - 禁止使用字符串拼接 SQL
【代码位置】RefundOrderController.java:45
【问题说明】发现使用字符串拼接 SQL 语句,存在 SQL 注入风险
【修改建议】使用参数化查询或 MyBatis 的#{param} 方式
### 严重问题
【问题编号】P3C-002
【严重程度】严重
【规范类别】p3c-exception-logging
【规则描述】异常处理 - 禁止捕获 Exception 后不做任何处理
【代码位置】RefundOrderServiceImpl.java:78
【问题说明】catch 块中仅打印日志,未进行异常传播或返回错误状态
【修改建议】抛出运行时异常或返回明确的错误响应
### 一般问题
【问题编号】P3C-003
【严重程度】一般
【规范类别】p3c-coding-style
【规则描述】命名风格 - 方法名应使用动词 + 名词形式
【代码位置】RefundOrder.java:23
【问题说明】方法名"status"不够清晰,无法表达是获取状态还是设置状态
【修改建议】修改为 getStatus() 或 setStatus()
### 轻微问题
【问题编号】P3C-004
【严重程度】轻微
【规范类别】p3c-coding-style
【规则描述】注释规约 - 公共方法应有 Javadoc 注释
【代码位置】RefundOrderMapper.java:15
【问题说明】selectById 方法缺少 Javadoc 注释
【修改建议】添加/** */格式的 Javadoc 注释// ❌ 错误示例
if (status == 1) {
// ...
}
// ✅ 正确示例
public static final int STATUS_ACTIVE = 1;
if (status == STATUS_ACTIVE) {
// ...
}// ❌ 错误示例
String name = user.getName();
if (name.equals("admin")) {
// ...
}
// ✅ 正确示例
if ("admin".equals(user.getName())) {
// ...
}// ❌ 错误示例
ExecutorService executor = Executors.newCachedThreadPool();
// ✅ 正确示例
ExecutorService executor = new ThreadPoolExecutor(
corePoolSize,
maximumPoolSize,
keepAliveTime,
TimeUnit.SECONDS,
new LinkedBlockingQueue<>(capacity),
new ThreadFactoryBuilder().setNameFormat("custom-%d").build(),
new ThreadPoolExecutor.CallerRunsPolicy()
);以下规范违反将导致致命或严重问题:
以下规范违反将导致一般问题:
以下规范违反将导致轻微问题:
以下情况可以申请豁免检查:
// 方式 1:使用@SuppressNullWarning 注解(针对 NPE 检查)
@SuppressNullWarning
public String getUserInfo() { ... }
// 方式 2:使用注释标注(针对特定规则)
// CHECKSTYLE:OFF - 遗留代码,待后续重构
public void legacyMethod() { ... }
// CHECKSTYLE:ON
// 方式 3:TODO 标记(针对临时豁免)
// TODO [P3C-EXC-001] 待改进:需要完善异常处理
public void needImprove() { ... }对于存量代码,建议采用以下策略:
target/、build/等构建输出目录.git/、.svn/等版本控制目录vendor/、lib/等第三方库目录generated/等代码生成目录# GitLab CI 示例
p3c_check:
stage: test
script:
- mvn checkstyle:check
- mvn spotbugs:check现在,请提供以下信息开始测试:
© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/p3c-code-quality of LeoYeAI/openclaw-master-skills.
Open the folder on GitHubat commit e5199b5
P3c Code Quality next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| P3c Code Quality this skillLeoYeAI/openclaw-master-skills | 2.2k | — | ~2.8k | Automated safety check: Pass | MIT | |
| SQL Code Reviewgithub/awesome-copilot | 40k | 1 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Flycms Devsunkaifei/FlyCms | 656 | — | ~827 | Automated safety check: Pass | MIT | |
| Alibaba Java Coding Guidelines Skillaiskillstore/marketplace | 430 | — | ~503 | Automated safety check: Pass | Apache-2.0 | |
| Code Review Skillawesome-skills/code-review-skill | 2.1k | — | ~2.8k | Automated safety check: Notes | MIT | |
| Code Nest Project Specxiaou61/Code-Nest | 770 | — | ~1.3k | Automated safety check: Pass | MIT |
github/awesome-copilot
Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across all SQL databases (MySQL, PostgreSQL, SQL Server, Oracle).
sunkaifei/FlyCms
FlyCms 项目(backend/ Spring Boot 4.1.1 + frontend/ vue-vben-admin v5)的架构地图与开发规范总纲。凡在本仓库做任何开发——写后端接口、新增/修改模块、管理页面、数据库变更、修 bug、重构——都要先加载本 skill 再动手,即使用户只说"改一下""加个功能";前端登录/菜单/权限专项另见…
aiskillstore/marketplace
A skill your agent uses when 需要按 Alibaba Java Coding Guidelines(阿里巴巴 Java 编码规范)审查、生成或重构 Java、Spring、MyBatis、Maven、MySQL、SQL、日志、异常、安全或数据库相关代码。
awesome-skills/code-review-skill
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…
xiaou61/Code-Nest
Code-Nest 多模块全栈项目协作规范与落点导航。Use when modifying this repository for feature development, bug fixing, refactor, API change, SQL migration, or frontend-backend联调 so changes land in the correct module…
SonarSource/sonar-java
Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change.
LeoYeAI/openclaw-master-skills
Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.
LeoYeAI/openclaw-master-skills
Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.
LeoYeAI/openclaw-master-skills
Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.
LeoYeAI/openclaw-master-skills
Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.
LeoYeAI/openclaw-master-skills
Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.
LeoYeAI/openclaw-master-skills
Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.
Categories
执行代码质量检查测试,基于阿里巴巴 P3C 规范对代码进行全面检查,包括命名规范、异常处理、并发安全、数据库规范、OOP 规范、安全规约和单元测试规范。Invoke when user needs to verify code quality against P3C standards. P3c Code Quality is an agent skill from LeoYeAI/openclaw-master-skills. 执行代码质量检查测试,基于阿里巴巴 P3C 规范对代码进行全面检查,包括命名规范、异常处理、并发安全、数据库规范、OOP 规范、安全规约和单元测试规范。Invoke when user needs to verify code quality against P3C standards.
P3c Code Quality fits situations like: needs to verify code quality against P3C standards; tasks that involve Code quality.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill p3c-code-quality -a claude-code`. Or copy the skill folder (skills/p3c-code-quality in LeoYeAI/openclaw-master-skills) into .claude/skills/p3c-code-quality in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill p3c-code-quality -a codex`. Or copy the skill folder (skills/p3c-code-quality in LeoYeAI/openclaw-master-skills) into .agents/skills/p3c-code-quality in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill p3c-code-quality -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/p3c-code-quality, .gemini/skills/p3c-code-quality, .github/skills/p3c-code-quality and .opencode/skills/p3c-code-quality in your project.
SKILL.md names no scripts, command-line tools or credentials: P3c Code Quality is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
P3c Code Quality is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with P3c Code Quality: SQL Code Review (github/awesome-copilot, 40k stars), Flycms Dev (sunkaifei/FlyCms, 656 stars), Alibaba Java Coding Guidelines Skill (aiskillstore/marketplace, 430 stars) and Code Review Skill (awesome-skills/code-review-skill, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,158 GitHub stars. The repository holds 1,215 skills in this directory. The repository was last updated on July 20, 2026.
Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.