Agent skill

Advpl Code Review

by thalysjuvenal in thalysjuvenal/advpl-specialist

A skill your agent uses when the user asks to review, audit, or check the quality of ADVPL/TLPP code for TOTVS Protheus before merge or deploy -- covering best practices (RecLock/MsUnlock pairing…

MITAuto-check passedDevelopment

Install Advpl Code Review

skills CLI
$ npx skills add thalysjuvenal/advpl-specialist --skill advpl-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install thalysjuvenal/advpl-specialist advpl-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/thalysjuvenal/advpl-specialist.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/advpl-code-review .claude/skills/advpl-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
advpl-code-review
GitHub stars
186
Token cost
~604 tokens
SKILL.md length
211 words
Files
7
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when the user asks to review, audit, or check the quality of ADVPL/TLPP code for TOTVS Protheus before merge or deploy -- covering best practices (RecLock/MsUnlock pairing…

  • The user asks to review
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Check the quality of ADVPL/TLPP code for TOTVS Protheus before merge
  • Deploy -- covering best practices (RecLock/MsUnlock pairing

What it does

Advpl Code Review is an agent skill from thalysjuvenal/advpl-specialist. Use when the user asks to review, audit, or check the quality of ADVPL/TLPP code for TOTVS Protheus before merge or deploy -- covering best practices (RecLock/MsUnlock pairing, variable scope, area management, error handling), performance bottlenecks, security vulnerabilities (SQL injection, credential exposure), and modernization opportunities (TLPP migration readiness). Also triggers on Portuguese phrasing like "revisar codigo", "revisar fonte", "auditar rotina", "checar boas praticas", "code review advpl", or…

Its SKILL.md is about 600 tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files (for example `reference.md`, `rules-best-practices.md` and `rules-modernization.md`).

It sits in Development, covering Code review, Legacy modernization and Web application vulnerabilities. The repository describes itself as: Plugin para Claude Code especializado em ADVPL e TLPP para desenvolvimento TOTVS Protheus. The licence is MIT.

When your agent uses it

  • The user asks to review
  • Check the quality of ADVPL/TLPP code for TOTVS Protheus before merge
  • Deploy -- covering best practices (RecLock/MsUnlock pairing
  • Area management

Example prompts

  • “revisar codigo”
  • “revisar fonte”
  • “auditar rotina”
  • “/advpl-code-review”

What it can do on your machine

Read from SKILL.md and the folder at commit d80599b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Advpl Code Review loads about 604 tokens when it runs. Until then it costs about 152 tokens; SKILL.md has 211 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~152
When it runs · the whole SKILL.md, loaded when a task matches
~604

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from thalysjuvenal/advpl-specialist at commit d80599b, republished under its MIT licence (© thalysjuvenal). 211 words, ~604 tokens.

Download SKILL.mdSave it as .claude/skills/advpl-code-review/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
advpl-code-review
description
Use when the user asks to review, audit, or check the quality of ADVPL/TLPP code for TOTVS Protheus before merge or deploy -- covering best practices (RecLock/MsUnlock pairing, variable scope, area management, error handling), performance bottlenecks, security vulnerabilities (SQL injection, credential exposure), and modernization opportunities (TLPP migration readiness). Also triggers on Portuguese phrasing like "revisar codigo", "revisar fonte", "auditar rotina", "checar boas praticas", "code review advpl", or requests to apply the official TOTVS SonarQube ruleset (CA/BG/CS codes).

ADVPL/TLPP Code Review

This skill provides a systematic code review methodology for existing ADVPL/TLPP code, producing findings tagged with a rule ID (BP-*, PERF-*, SEC-*, MOD-*), a severity (CRITICAL/WARNING/INFO), the file/line, the issue, and the fix. It covers four review categories: best practices, performance, security, and modernization, and can map findings to the official TOTVS SonarQube quality gate.

Activate this skill when the user wants existing code inspected for quality, compliance, security, or performance issues -- e.g. before a merge, before a deploy, during an onboarding audit, or when assessing migration readiness from .prw to .tlpp. It does not cover generating new code (see advpl-code-generation), diagnosing a specific runtime/compilation error (see advpl-debugging), restructuring code without adding features (see advpl-refactoring), or performing the actual .prw to .tlpp conversion (see advpl-to-tlpp-migration).

Reference fileRead when
reference.mdAlways -- review categories, output format, severity levels, review process, rule ID prefixes
rules-best-practices.mdChecking RecLock/MsUnlock pairing, variable scope, area management, error handling, documentation (BP-* rules)
rules-performance.mdChecking Embedded SQL efficiency, loop efficiency, string operations, index usage (PERF-* rules)
rules-security.mdChecking SQL injection, input validation, credential exposure, sensitive data logging (SEC-* rules)
rules-modernization.mdChecking TLPP migration candidates, namespace usage, OOP patterns, modern UI frameworks (MOD-* rules)
sonarqube-rules-catalog.mdAligning findings with the official TOTVS SonarQube ruleset (groups G1-G5, CA/BG/CS codes)

© thalysjuvenal, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files in skills/advpl-code-review of thalysjuvenal/advpl-specialist.

  • SKILL.md
  • reference.md
  • rules-best-practices.md
  • rules-modernization.md
  • rules-performance.md
  • rules-security.md
  • sonarqube-rules-catalog.md

Open the folder on GitHubat commit d80599b

Compare with similar skills

Advpl Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Advpl Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Advpl Code Review this skillthalysjuvenal/advpl-specialist186—~604Automated safety check: PassMIT
Code ReviewerYikai-Liao/symusic1891 repos~1.3kAutomated safety check: PassMIT
Code Reviewmaiobarbero/my-ai-workflow140—~1.2kAutomated safety check: PassNone
Cwe Code ReviewSpecterOps/skills704—~2.4kAutomated safety check: PassApache-2.0
Sendou Code Reviewsendou-ink/sendou.ink297—~5.2kAutomated safety check: PassAGPL-3.0
Suede Code ReviewJasonColapietro/suede-creator-skills127—~7.1kAutomated safety check: PassMIT

Similar skills

  • Code Reviewer

    Yikai-Liao/symusic

    Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then…

    189 GitHub starsUsed in 1 repo~1.3k tokens
    DevelopmentAuto-check passed
  • Code Review

    maiobarbero/my-ai-workflow

    Perform a language-agnostic first-pass code review covering logic errors, bad practices, operation ordering, magic strings, pattern improvements, strict type checking, and SQL injection.

    140 GitHub stars~1.2k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • Cwe Code Review

    SpecterOps/skills

    Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…

    704 GitHub stars~2.4k tokensUpdated 16 days ago
    DevelopmentAuto-check passed
  • Sendou Code Review

    sendou-ink/sendou.ink

    Multi-agent code review that checks the current diff from multiple angles (spec compliance, bugs from two lenses, conventions/modernization, abstraction reuse, security, DB query performance, test…

    297 GitHub stars~5.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Suede Code Review

    JasonColapietro/suede-creator-skills

    Suede AI findings-only code review with full context: changed files, callers, contracts, and deploy surface.

    127 GitHub stars~7.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Code Review Security

    OWASP/secure-agent-playbook

    Security-focused code review mapped to OWASP Top 10 and ASVS.

    187 GitHub stars~549 tokensUpdated 14 days ago
    DevelopmentAuto-check passed

More from thalysjuvenal/advpl-specialist

All 19 skills in this repo
  • Advpl Code Generation

    thalysjuvenal/advpl-specialist

    A skill your agent uses when the user asks to generate, create, or scaffold ADVPL/TLPP code for TOTVS Protheus -- User Functions, Static Functions, TLPP classes, MVC (Model/View/Controller), REST…

    186 GitHub stars~749 tokensUpdated 25 days ago
    Auto-check passed
  • Advpl To Tlpp Migration

    thalysjuvenal/advpl-specialist

    A skill your agent uses when the user asks to migrate, convert, compatibilize, or modernize legacy ADVPL procedural code to TLPP object-oriented classes on TOTVS Protheus -- turning User…

    186 GitHub stars~592 tokensUpdated 25 days ago
    Auto-check passed
  • Advpr Test Automation

    thalysjuvenal/advpl-specialist

    A skill your agent uses when the user wants to write, run, or troubleshoot automated regression tests for Protheus routines with ADVPR (Advanced Protheus Robot) -- covering FWTestHelper API…

    186 GitHub stars~835 tokensUpdated 25 days ago
    Auto-check passed
  • Protheus Business

    thalysjuvenal/advpl-specialist

    A skill your agent uses when the user needs to understand a TOTVS Protheus ERP business process, module workflow, or cross-module integration -- covering Compras (COM), Estoque (EST), Faturamento…

    186 GitHub stars~671 tokensUpdated 25 days ago
    Auto-check passed
  • Protheus Locks Deadlocks

    thalysjuvenal/advpl-specialist

    A skill your agent uses when the user needs to understand, diagnose, or prevent Protheus record locks and deadlocks -- covering RecLock/MsUnlock/SoftLock/LockByName semantics, BeginTran/EndTran…

    186 GitHub stars~553 tokensUpdated 25 days ago
    Auto-check passed
  • Protheus Reference

    thalysjuvenal/advpl-specialist

    A skill your agent uses when the user needs to look up a TOTVS Protheus native function's syntax/parameters/return value, the SX data dictionary structure (SX1-SX9, SIX), REST API endpoint patterns…

    186 GitHub stars~621 tokensUpdated 25 days ago
    Auto-check passed

Categories

Questions about Advpl Code Review

What does Advpl Code Review do?

A skill your agent uses when the user asks to review, audit, or check the quality of ADVPL/TLPP code for TOTVS Protheus before merge or deploy -- covering best practices (RecLock/MsUnlock pairing…. Advpl Code Review is an agent skill from thalysjuvenal/advpl-specialist. Use when the user asks to review, audit, or check the quality of ADVPL/TLPP code for TOTVS Protheus before merge or deploy -- covering best practices (RecLock/MsUnlock pairing, variable scope, area management, error handling), performance bottlenecks, security vulnerabilities (SQL injection, credential exposure), and modernization opportunities (TLPP migration readiness).

When should I use Advpl Code Review?

Advpl Code Review fits situations like: the user asks to review; check the quality of ADVPL/TLPP code for TOTVS Protheus before merge; deploy -- covering best practices (RecLock/MsUnlock pairing; area management.

How do I install Advpl Code Review in Claude Code?

Run `npx skills add thalysjuvenal/advpl-specialist --skill advpl-code-review -a claude-code`. Or copy the skill folder (skills/advpl-code-review in thalysjuvenal/advpl-specialist) into .claude/skills/advpl-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Advpl Code Review in Codex?

Run `npx skills add thalysjuvenal/advpl-specialist --skill advpl-code-review -a codex`. Or copy the skill folder (skills/advpl-code-review in thalysjuvenal/advpl-specialist) into .agents/skills/advpl-code-review in your project. Codex loads it when a task matches its description.

Can I use Advpl Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add thalysjuvenal/advpl-specialist --skill advpl-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/advpl-code-review, .gemini/skills/advpl-code-review, .github/skills/advpl-code-review and .opencode/skills/advpl-code-review in your project.

What does Advpl Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Advpl Code Review is instructions for the agent only.

Does Advpl Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Advpl Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Advpl Code Review use?

Advpl Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Advpl Code Review use?

About 604 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Advpl Code Review?

Skills that share tags, products or a category with Advpl Code Review: Code Reviewer (Yikai-Liao/symusic, 189 stars), Code Review (maiobarbero/my-ai-workflow, 140 stars), Cwe Code Review (SpecterOps/skills, 704 stars) and Sendou Code Review (sendou-ink/sendou.ink, 297 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Advpl Code Review?

thalysjuvenal (a GitHub user) maintains it in thalysjuvenal/advpl-specialist, which has 186 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on September 14, 2026.

Source: thalysjuvenal/advpl-specialist on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.