Structured Code Review
FareedKhan-dev/claude-code-from-scratch
Gives the agent a five-step review routine that reads the full file first, labels each finding as bug, security, performance, style or suggestion, and ends with a summary.
Reviews AdvPL and TLPP source against SonarQube rules, ProtheusDOC requirements, security, performance and Protheus conventions, and reports findings by severity.
$ npx skills add totvs/engpro-advpl-tlpp-skills --skill code-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install totvs/engpro-advpl-tlpp-skills code-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/totvs/engpro-advpl-tlpp-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/advpl-tlpp/code-review .claude/skills/code-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "code-review" agent skill from https://github.com/totvs/engpro-advpl-tlpp-skills/tree/main/skills/advpl-tlpp/code-review into .claude/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/totvs/engpro-advpl-tlpp-skills/tree/main/skills/advpl-tlpp/code-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add totvs/engpro-advpl-tlpp-skills --skill code-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install totvs/engpro-advpl-tlpp-skills code-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/totvs/engpro-advpl-tlpp-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/advpl-tlpp/code-review .agents/skills/code-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "code-review" agent skill from https://github.com/totvs/engpro-advpl-tlpp-skills/tree/main/skills/advpl-tlpp/code-review into .agents/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add totvs/engpro-advpl-tlpp-skills --skill code-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install totvs/engpro-advpl-tlpp-skills code-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/totvs/engpro-advpl-tlpp-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/advpl-tlpp/code-review .cursor/skills/code-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "code-review" agent skill from https://github.com/totvs/engpro-advpl-tlpp-skills/tree/main/skills/advpl-tlpp/code-review into .cursor/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/totvs/engpro-advpl-tlpp-skills.git --path skills/advpl-tlpp/code-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add totvs/engpro-advpl-tlpp-skills --skill code-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install totvs/engpro-advpl-tlpp-skills code-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/totvs/engpro-advpl-tlpp-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/advpl-tlpp/code-review .gemini/skills/code-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/totvs/engpro-advpl-tlpp-skills/tree/main/skills/advpl-tlpp/code-review into .gemini/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install totvs/engpro-advpl-tlpp-skills code-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add totvs/engpro-advpl-tlpp-skills --skill code-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/totvs/engpro-advpl-tlpp-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/advpl-tlpp/code-review .github/skills/code-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/totvs/engpro-advpl-tlpp-skills/tree/main/skills/advpl-tlpp/code-review into .github/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add totvs/engpro-advpl-tlpp-skills --skill code-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install totvs/engpro-advpl-tlpp-skills code-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/totvs/engpro-advpl-tlpp-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/advpl-tlpp/code-review .opencode/skills/code-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/totvs/engpro-advpl-tlpp-skills/tree/main/skills/advpl-tlpp/code-review into .opencode/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
code-reviewReviews AdvPL and TLPP source against SonarQube rules, ProtheusDOC requirements, security, performance and Protheus conventions, and reports findings by severity.
Source files with the .prw, .tlpp or .prx extension are reviewed against TOTVS engineering standards, SonarQube static-analysis rules, ProtheusDOC documentation requirements and clean-code principles. The output is a categorized report with severity levels, rule references and fix suggestions that include code examples.
Typical uses are checking new or changed files, a pre-commit quality gate for pull requests, auditing legacy code for SonarQube compliance, confirming that ProtheusDOC blocks are complete, checking security posture such as SQL injection, hardcoded credentials and access control, and judging readiness for Cloud and SmartERP environments.
The skill loads detail on demand. Separate reference files cover security patterns, code quality and performance patterns including legacy code and metadata access, and documentation and naming conventions including TLPP specifics, while a shared SonarQube rules reference sits one level up in the repository.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 3908e4e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
AdvPL and TLPP Code Review loads about 2.5k tokens when it runs, and up to ~6.8k if it reads all its reference files. Until then it costs about 90 tokens; SKILL.md has 832 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from totvs/engpro-advpl-tlpp-skills at commit 3908e4e, republished under its MIT licence (© totvs). 832 words, ~2,530 tokens.
.claude/skills/code-review/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.You are an expert AdvPL/TLPP code reviewer. Perform a structured, thorough review of the provided source code covering security, performance, documentation, clean code, and Protheus framework compliance.
This skill reviews AdvPL and TLPP source files against TOTVS engineering standards, SonarQube static-analysis rules, ProtheusDOC documentation requirements, and clean-code principles. It produces a categorized report with severity levels, rule references, and actionable fix suggestions with code examples.
.prw, .tlpp, or .prx source filesThis skill uses progressive disclosure. The SKILL.md body covers the review workflow, category definitions, checklist, and output format. Detailed code examples, anti-patterns, and rule-specific fixes are in the references/ directory — read them on demand based on the review scenario:
| Reference File | When to Read | Content |
|---|---|---|
| references/security-review-patterns.md | Reviewing security concerns — SQL injection, hardcoded credentials, restricted APIs, environment context | SQL injection examples, FWExecStatement patterns, restricted functions table, REST/SOAP environment rules |
| references/code-quality-patterns.md | Reviewing performance, legacy code, metadata access, or compilation issues | Loop/transaction anti-patterns, ISAM migration, deprecated API replacements, SX* metadata access table, encoding rules |
| references/documentation-and-conventions.md | Reviewing ProtheusDOC, naming conventions, clean code, or TLPP-specific patterns | ProtheusDOC tag reference, common documentation mistakes, variable naming/scope conventions, TLPP type annotations, namespace, Try-Catch |
Also refer to references/sonarqube-rules-reference.md for the complete SonarQube rules reference shared across skills.
Before reviewing:
.prw (AdvPL), .tlpp (TLPP), .prx (legacy)totvs.ch, tlpp-core.th, custom .ch/.th filesBased on the code under review, read the appropriate reference files:
Apply each review category below in order. For every finding, record:
Output findings as a structured report grouped by category, ordered by severity (CRITICAL first). End with a summary and overall assessment.
Check for vulnerabilities that expose the application to attacks or data leaks. Key rules:
FWExecStatement (CRITICAL)RpcSetEnv/RpcSetType in REST/SOAP services → configure PrepareIn (MAJOR)ErrorBlock override → migrate to Try-Catch in TLPP (INFO)Detect patterns that degrade runtime performance:
GetMV, SuperGetMV, ExistBlock, AllUsers, Type, Pergunte) → cache before loop (MAJOR)MsgAlert, MsgYesNo, etc.) → move UI after transaction (MAJOR)ChangeQuery()/BeginSQL (MAJOR)Identify deprecated APIs and legacy patterns:
MSCREATE, DBCREATE) → FWTemporaryTable (MAJOR)LockByName() (MAJOR)ConOut) → FWLogMsg() (MINOR)IIF inline → explicit If/Else/EndIf (INFO)#INCLUDE → lowercase #include (MINOR)Obsolete Include Directives — Flag any of these legacy includes and recommend replacement:
| Obsolete Include | Replacement Include | Modern Class/API |
|---|---|---|
Ap5Mail.ch | totvs.ch | TMailMessage() |
ApWizard.ch | totvs.ch | FWWizardControl() |
FileIO.ch | totvs.ch | FWFileWriter() / FWFileReader() |
Font.ch | totvs.ch | TFont() |
ParmType.ch | totvs.ch | Default prefix for parameter handling |
protheus.ch | totvs.ch | — |
RWMake.ch | totvs.ch | — |
Direct DbSelectArea on Protheus system tables (SX*) is prohibited. All SX* tables (SM0, SIX, SX1–SXG, SXD, SE5, SPF) must be accessed through framework APIs. Key rules: CA2000–CA2013, CA2017–CA2019, CA2021 (CRITICAL/MAJOR).
Every public element must have a complete /*/{Protheus.doc} block with mandatory tags: @type, @author, @since, @param (per parameter), @return. Static Functions should also be documented.
Check variable naming prefixes (c=Character, n=Numeric, l=Logical, etc.), Local vs Private scope, function size (< 50 lines), magic numbers, and dead code.
For .tlpp files: verify file extension consistency, type annotations on variables and functions, namespace usage, and Try-Catch error handling instead of ErrorBlock.
Check syntax errors (CA0000), file encoding (Windows-1252), INI references (CA1005), and I18N compliance (CA2016).
Output the review as follows:
# Code Review: <filename>
## Summary
- **Total Findings:** <count>
- **Critical:** <count> | **Major:** <count> | **Minor:** <count> | **Info:** <count>
- **Overall Assessment:** <PASS | PASS WITH OBSERVATIONS | NEEDS REVISION | FAIL>
## Critical Findings
### [CA####] <Title>
- **Location:** `FunctionName` (line ~NN)
- **Finding:** <description>
- **Fix:** <how to fix>
```advpl
// suggested fix code
```(same structure)
(same structure)
(same structure)
| Category | Status | Notes |
|---|---|---|
| Security (G1) | ✅/⚠️/❌ | |
| Performance (G2) | ✅/⚠️/❌ | |
| Legacy/Deprecated (G3) | ✅/⚠️/❌ | |
| Metadata Access (G4) | ✅/⚠️/❌ | |
| Documentation | ✅/⚠️/❌ | |
| Clean Code | ✅/⚠️/❌ | |
| TLPP Compliance | ✅/⚠️/❌ | (if .tlpp file) |
| Compilation (G5) | ✅/⚠️/❌ |
### Overall Assessment Criteria
| Assessment | Condition |
|------------|-----------|
| **PASS** | Zero CRITICAL, zero MAJOR findings |
| **PASS WITH OBSERVATIONS** | Zero CRITICAL, ≤ 3 MAJOR findings |
| **NEEDS REVISION** | Zero CRITICAL, > 3 MAJOR findings |
| **FAIL** | Any CRITICAL finding |
---
## Quick Reference: All SonarQube Rules
For the complete rule definitions, severity levels, prohibited patterns, and required alternatives, consult [references/sonarqube-rules-reference.md](../references/sonarqube-rules-reference.md).
| Group | Rules | Focus |
|-------|-------|-------|
| G1 — Security | BG1000, CA2022–CA2053, BG1200 | Injection, credentials, restricted APIs |
| G2 — Performance | CA1002, CA1003, CS1000 | Loops, transactions, queries |
| G3 — Legacy | CA1000–CA1006, CA2014–CA2020, CA3001–CA3002, CA4000, BG1100 | Deprecated APIs, ISAM, console |
| G4 — Metadata | CA2000–CA2013, CA2021 | Direct SX* table access |
| G5 — Compilation | CA0000, CA1005, CA2016 | Syntax, encoding, I18N |
© totvs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/advpl-tlpp/code-review of totvs/engpro-advpl-tlpp-skills.
Open the folder on GitHubat commit 3908e4e
AdvPL and TLPP Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| AdvPL and TLPP Code Review this skilltotvs/engpro-advpl-tlpp-skills | 141 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Structured Code ReviewFareedKhan-dev/claude-code-from-scratch | 298 | — | ~809 | Automated safety check: Pass | MIT | |
| WooCommerce Code Reviewwoocommerce/woocommerce | 11k | 3 repos | ~1.1k | Automated safety check: Pass | Custom licence | |
| Skill Doli Code ReviewDolibarr/dolibarr | 7.7k | 1 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Dignified Python Standardsdocling-project/docling | 68k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Clean Code GuardamElnagdy/guard-skills | 1.3k | 2 repos | ~4.3k | Automated safety check: Pass | MIT |
FareedKhan-dev/claude-code-from-scratch
Gives the agent a five-step review routine that reads the full file first, labels each finding as bug, security, performance, style or suggestion, and ends with a summary.
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
Dolibarr/dolibarr
Reviews Dolibarr PHP code for compliance with coding standards and security best practices, and fixes identified issues.
docling-project/docling
Applies opinionated production Python conventions chosen by the project's Python version: modern type syntax, pathlib, explicit checks and interface guidance.
amElnagdy/guard-skills
Reviews generated or changed production code against Clean Code, SOLID, DRY, KISS, YAGNI and LLM-specific failure modes before it ships, in any language.
tt-a1i/archify
Review Archify issues, PRs, or code through value, cost, and impact to support evidence-based maintenance decisions. Use for issue triage, change reviews, and…
totvs/engpro-advpl-tlpp-skills
Converts AdvPL and TLPP source files from UTF-8 to Windows-1252 in place after code generation, because the Protheus compiler accepts only CP1252 files.
totvs/engpro-advpl-tlpp-skills
Compiles AdvPL and TLPP sources from VS Code with the TOTVS Developer Studio extension, handling server setup, connection and compile result reporting.
totvs/engpro-advpl-tlpp-skills
Plans and builds Protheus AdvPL/TLPP features through Specify, Design, Tasks and Execute phases whose depth scales with the size of the change.
totvs/engpro-advpl-tlpp-skills
Queries the TOTVS Protheus ERP data dictionary for tables, fields, indexes, parameters, triggers and lookups, including impact checks during refactoring.
totvs/engpro-advpl-tlpp-skills
Generates Protheus MVC screens in ADVPL/TLPP, with ModelDef, ViewDef, MenuDef and Browse functions for single-entity and master-detail layouts.
totvs/engpro-advpl-tlpp-skills
Build optimized and safe SQL queries for Protheus tables. An agent skill from totvs/engpro-advpl-tlpp-skills.
Categories
Reviews AdvPL and TLPP source against SonarQube rules, ProtheusDOC requirements, security, performance and Protheus conventions, and reports findings by severity. prx extension are reviewed against TOTVS engineering standards, SonarQube static-analysis rules, ProtheusDOC documentation requirements and clean-code principles. The output is a categorized report with severity levels, rule references and fix suggestions that include code examples.
AdvPL and TLPP Code Review fits situations like: reviewing new or modified .prw, .tlpp or .prx files before merge; auditing legacy AdvPL code for SonarQube compliance; checking that ProtheusDOC blocks are complete and correct; looking for SQL injection or hardcoded credentials in Protheus code.
Run `npx skills add totvs/engpro-advpl-tlpp-skills --skill code-review -a claude-code`. Or copy the skill folder (skills/advpl-tlpp/code-review in totvs/engpro-advpl-tlpp-skills) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add totvs/engpro-advpl-tlpp-skills --skill code-review -a codex`. Or copy the skill folder (skills/advpl-tlpp/code-review in totvs/engpro-advpl-tlpp-skills) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add totvs/engpro-advpl-tlpp-skills --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.
SKILL.md names no scripts, command-line tools or credentials: AdvPL and TLPP Code Review is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
AdvPL and TLPP Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with AdvPL and TLPP Code Review: Structured Code Review (FareedKhan-dev/claude-code-from-scratch, 298 stars), WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Skill Doli Code Review (Dolibarr/dolibarr, 7.7k stars) and Dignified Python Standards (docling-project/docling, 68k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
totvs (a GitHub organization) maintains it in totvs/engpro-advpl-tlpp-skills, which has 141 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 5, 2026.
Source: totvs/engpro-advpl-tlpp-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.