Agent skill

AdvPL and TLPP Code Review

by totvs in totvs/engpro-advpl-tlpp-skills

Reviews AdvPL and TLPP source against SonarQube rules, ProtheusDOC requirements, security, performance and Protheus conventions, and reports findings by severity.

MITAuto-check passedDevelopment

Install AdvPL and TLPP Code Review

skills CLI
$ npx skills add totvs/engpro-advpl-tlpp-skills --skill code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install totvs/engpro-advpl-tlpp-skills code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/totvs/engpro-advpl-tlpp-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/advpl-tlpp/code-review .claude/skills/code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-review
GitHub stars
141
Token cost
~2.5k tokens
SKILL.md length
832 words
Files
4 (incl. references)
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Reviews AdvPL and TLPP source against SonarQube rules, ProtheusDOC requirements, security, performance and Protheus conventions, and reports findings by severity.

  • Works in 12 steps: Understand the Code → Load Relevant References → Run Review Categories → …
  • Reviewing new or modified .prw, .tlpp or .prx files before merge
  • SKILL.md covers Overview, When to Use, Bundled Reference Files and Review Process, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Source files with the .prw, .tlpp or .prx extension are reviewed against TOTVS engineering standards, SonarQube static-analysis rules, ProtheusDOC documentation requirements and clean-code principles. The output is a categorized report with severity levels, rule references and fix suggestions that include code examples.

Typical uses are checking new or changed files, a pre-commit quality gate for pull requests, auditing legacy code for SonarQube compliance, confirming that ProtheusDOC blocks are complete, checking security posture such as SQL injection, hardcoded credentials and access control, and judging readiness for Cloud and SmartERP environments.

The skill loads detail on demand. Separate reference files cover security patterns, code quality and performance patterns including legacy code and metadata access, and documentation and naming conventions including TLPP specifics, while a shared SonarQube rules reference sits one level up in the repository.

When your agent uses it

  • Reviewing new or modified .prw, .tlpp or .prx files before merge
  • Auditing legacy AdvPL code for SonarQube compliance
  • Checking that ProtheusDOC blocks are complete and correct
  • Looking for SQL injection or hardcoded credentials in Protheus code

Example prompts

  • “Review src/FATA050.prw for security problems and missing ProtheusDOC blocks.”
  • “Audit this TLPP class against the SonarQube rules and list findings by severity.”
  • “Code review the changed .tlpp files in this pull request before I merge.”

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Understand the Code
  2. Load Relevant References
  3. Run Review Categories
  4. Produce the Report
  5. Security (SonarQube G1)
  6. Performance and Loops (SonarQube G2)
  7. Legacy and Deprecated Code (SonarQube G3)
  8. Metadata Access (SonarQube G4)
  9. ProtheusDOC Documentation
  10. Clean Code and Naming Conventions
  11. TLPP-Specific Checks
  12. Compilation and Encoding (SonarQube G5)

What it can do on your machine

Read from SKILL.md and the folder at commit 3908e4e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AdvPL and TLPP Code Review loads about 2.5k tokens when it runs, and up to ~6.8k if it reads all its reference files. Until then it costs about 90 tokens; SKILL.md has 832 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from totvs/engpro-advpl-tlpp-skills at commit 3908e4e, republished under its MIT licence (© totvs). 832 words, ~2,530 tokens.

Download SKILL.mdSave it as .claude/skills/code-review/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
code-review
description
Perform comprehensive AdvPL/TLPP code review covering SonarQube rules, Protheus.doc documentation, security, performance, clean code, and TOTVS Protheus framework best practices. Use when a user says "review this code", "code review", "check this source", "audit this AdvPL/TLPP", or needs a structured quality assessment of .prw/.tlpp/.prx files.
license
MIT
metadata.domain
Protheus
metadata.maintainer
Customizações ADVPL/TLPP
metadata.author
Thalion Starforge
metadata.version
4.2.0
metadata.category
Code Quality and Review

AdvPL/TLPP Code Review

You are an expert AdvPL/TLPP code reviewer. Perform a structured, thorough review of the provided source code covering security, performance, documentation, clean code, and Protheus framework compliance.

Overview

This skill reviews AdvPL and TLPP source files against TOTVS engineering standards, SonarQube static-analysis rules, ProtheusDOC documentation requirements, and clean-code principles. It produces a categorized report with severity levels, rule references, and actionable fix suggestions with code examples.

When to Use

  • Reviewing new or modified .prw, .tlpp, or .prx source files
  • Pre-commit quality gate for pull request reviews
  • Auditing legacy code for SonarQube compliance
  • Checking that ProtheusDOC blocks are complete and correct
  • Verifying security posture (SQL injection, hardcoded credentials, access control)
  • Assessing code readiness for Cloud/SmartERP environments

Bundled Reference Files

This skill uses progressive disclosure. The SKILL.md body covers the review workflow, category definitions, checklist, and output format. Detailed code examples, anti-patterns, and rule-specific fixes are in the references/ directory — read them on demand based on the review scenario:

Reference FileWhen to ReadContent
references/security-review-patterns.mdReviewing security concerns — SQL injection, hardcoded credentials, restricted APIs, environment contextSQL injection examples, FWExecStatement patterns, restricted functions table, REST/SOAP environment rules
references/code-quality-patterns.mdReviewing performance, legacy code, metadata access, or compilation issuesLoop/transaction anti-patterns, ISAM migration, deprecated API replacements, SX* metadata access table, encoding rules
references/documentation-and-conventions.mdReviewing ProtheusDOC, naming conventions, clean code, or TLPP-specific patternsProtheusDOC tag reference, common documentation mistakes, variable naming/scope conventions, TLPP type annotations, namespace, Try-Catch

Also refer to references/sonarqube-rules-reference.md for the complete SonarQube rules reference shared across skills.


Review Process

Step 1 — Understand the Code

Before reviewing:

  1. Read the entire file to understand purpose, scope, and dependencies
  2. Identify the element types (Functions, Static Functions, Classes, Methods)
  3. Note the file extension — .prw (AdvPL), .tlpp (TLPP), .prx (legacy)
  4. Check the includes — totvs.ch, tlpp-core.th, custom .ch/.th files
Step 2 — Load Relevant References

Based on the code under review, read the appropriate reference files:

Step 3 — Run Review Categories

Apply each review category below in order. For every finding, record:

  • Category (Security, Performance, Documentation, Clean Code, Framework)
  • Severity (CRITICAL, MAJOR, MINOR, INFO)
  • Rule ID (SonarQube rule when applicable, e.g., CA2050)
  • Location (function/method name and approximate line)
  • Finding (what is wrong)
  • Fix (how to correct it, with code example when helpful)
Step 4 — Produce the Report

Output findings as a structured report grouped by category, ordered by severity (CRITICAL first). End with a summary and overall assessment.


Review Categories

1. Security (SonarQube G1)

Check for vulnerabilities that expose the application to attacks or data leaks. Key rules:

  • CA2050 / CA2051 — SQL Injection: concatenating user input in SQL strings → use FWExecStatement (CRITICAL)
  • CA2052 — Hardcoded credentials in source → use environment configuration (CRITICAL)
  • BG1000 — RpcSetEnv/RpcSetType in REST/SOAP services → configure PrepareIn (MAJOR)
  • CA2022–CA2025, CA2053 — Restricted/prohibited functions and assignments (CRITICAL)
  • BG1200 — ErrorBlock override → migrate to Try-Catch in TLPP (INFO)
Show full SKILL.md (345 more words)Show less
2. Performance and Loops (SonarQube G2)

Detect patterns that degrade runtime performance:

  • CA1003 — Prohibited APIs inside loops (GetMV, SuperGetMV, ExistBlock, AllUsers, Type, Pergunte) → cache before loop (MAJOR)
  • CA1002 — UI APIs inside transactions (MsgAlert, MsgYesNo, etc.) → move UI after transaction (MAJOR)
  • CS1000 — Direct SQL without evaluation → prefer framework APIs or ChangeQuery()/BeginSQL (MAJOR)
3. Legacy and Deprecated Code (SonarQube G3)

Identify deprecated APIs and legacy patterns:

  • CA1000 — ISAM driver access (MSCREATE, DBCREATE) → FWTemporaryTable (MAJOR)
  • CA1001 — File-based semaphores → LockByName() (MAJOR)
  • CA1004 — Console output (ConOut) → FWLogMsg() (MINOR)
  • CA4000 — IIF inline → explicit If/Else/EndIf (INFO)
  • CA3001 — Uppercase #INCLUDE → lowercase #include (MINOR)

Obsolete Include Directives — Flag any of these legacy includes and recommend replacement:

Obsolete IncludeReplacement IncludeModern Class/API
Ap5Mail.chtotvs.chTMailMessage()
ApWizard.chtotvs.chFWWizardControl()
FileIO.chtotvs.chFWFileWriter() / FWFileReader()
Font.chtotvs.chTFont()
ParmType.chtotvs.chDefault prefix for parameter handling
protheus.chtotvs.ch—
RWMake.chtotvs.ch—
4. Metadata Access (SonarQube G4)

Direct DbSelectArea on Protheus system tables (SX*) is prohibited. All SX* tables (SM0, SIX, SX1–SXG, SXD, SE5, SPF) must be accessed through framework APIs. Key rules: CA2000–CA2013, CA2017–CA2019, CA2021 (CRITICAL/MAJOR).

5. ProtheusDOC Documentation

Every public element must have a complete /*/{Protheus.doc} block with mandatory tags: @type, @author, @since, @param (per parameter), @return. Static Functions should also be documented.

6. Clean Code and Naming Conventions

Check variable naming prefixes (c=Character, n=Numeric, l=Logical, etc.), Local vs Private scope, function size (< 50 lines), magic numbers, and dead code.

7. TLPP-Specific Checks

For .tlpp files: verify file extension consistency, type annotations on variables and functions, namespace usage, and Try-Catch error handling instead of ErrorBlock.

8. Compilation and Encoding (SonarQube G5)

Check syntax errors (CA0000), file encoding (Windows-1252), INI references (CA1005), and I18N compliance (CA2016).


Report Format

Output the review as follows:

markdown
# Code Review: <filename>

## Summary

- **Total Findings:** <count>
- **Critical:** <count> | **Major:** <count> | **Minor:** <count> | **Info:** <count>
- **Overall Assessment:** <PASS | PASS WITH OBSERVATIONS | NEEDS REVISION | FAIL>

## Critical Findings

### [CA####] <Title>

- **Location:** `FunctionName` (line ~NN)
- **Finding:** <description>
- **Fix:** <how to fix>

```advpl
// suggested fix code
```

Major Findings

(same structure)

Minor Findings

(same structure)

Info / Recommendations

(same structure)

Documentation Review

  • All public elements documented with ProtheusDOC
  • @type, @author, @since present on all blocks
  • @param tags match function signatures
  • @return documented for non-void functions
  • Identifiers match element names exactly

Assessment Criteria

CategoryStatusNotes
Security (G1)✅/⚠️/❌
Performance (G2)✅/⚠️/❌
Legacy/Deprecated (G3)✅/⚠️/❌
Metadata Access (G4)✅/⚠️/❌
Documentation✅/⚠️/❌
Clean Code✅/⚠️/❌
TLPP Compliance✅/⚠️/❌(if .tlpp file)
Compilation (G5)✅/⚠️/❌

### Overall Assessment Criteria

| Assessment | Condition |
|------------|-----------|
| **PASS** | Zero CRITICAL, zero MAJOR findings |
| **PASS WITH OBSERVATIONS** | Zero CRITICAL, ≤ 3 MAJOR findings |
| **NEEDS REVISION** | Zero CRITICAL, > 3 MAJOR findings |
| **FAIL** | Any CRITICAL finding |

---

## Quick Reference: All SonarQube Rules

For the complete rule definitions, severity levels, prohibited patterns, and required alternatives, consult [references/sonarqube-rules-reference.md](../references/sonarqube-rules-reference.md).

| Group | Rules | Focus |
|-------|-------|-------|
| G1 — Security | BG1000, CA2022–CA2053, BG1200 | Injection, credentials, restricted APIs |
| G2 — Performance | CA1002, CA1003, CS1000 | Loops, transactions, queries |
| G3 — Legacy | CA1000–CA1006, CA2014–CA2020, CA3001–CA3002, CA4000, BG1100 | Deprecated APIs, ISAM, console |
| G4 — Metadata | CA2000–CA2013, CA2021 | Direct SX* table access |
| G5 — Compilation | CA0000, CA1005, CA2016 | Syntax, encoding, I18N |

© totvs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/advpl-tlpp/code-review of totvs/engpro-advpl-tlpp-skills.

  • SKILL.md
  • references/code-quality-patterns.md
  • references/documentation-and-conventions.md
  • references/security-review-patterns.md

Open the folder on GitHubat commit 3908e4e

Compare with similar skills

AdvPL and TLPP Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AdvPL and TLPP Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AdvPL and TLPP Code Review this skilltotvs/engpro-advpl-tlpp-skills141—~2.5kAutomated safety check: PassMIT
Structured Code ReviewFareedKhan-dev/claude-code-from-scratch298—~809Automated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
Skill Doli Code ReviewDolibarr/dolibarr7.7k1 repos~1.1kAutomated safety check: PassMIT
Dignified Python Standardsdocling-project/docling68k—~1.5kAutomated safety check: PassApache-2.0
Clean Code GuardamElnagdy/guard-skills1.3k2 repos~4.3kAutomated safety check: PassMIT

Similar skills

  • Structured Code Review

    FareedKhan-dev/claude-code-from-scratch

    Gives the agent a five-step review routine that reads the full file first, labels each finding as bug, security, performance, style or suggestion, and ends with a summary.

    298 GitHub stars~809 tokensUpdated 6 mo ago
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Skill Doli Code Review

    Dolibarr/dolibarr

    Reviews Dolibarr PHP code for compliance with coding standards and security best practices, and fixes identified issues.

    7.7k GitHub starsUsed in 1 repo~1.1k tokens
    DevelopmentAuto-check passed
  • Dignified Python Standards

    docling-project/docling

    Applies opinionated production Python conventions chosen by the project's Python version: modern type syntax, pathlib, explicit checks and interface guidance.

    68k GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Clean Code Guard

    amElnagdy/guard-skills

    Reviews generated or changed production code against Clean Code, SOLID, DRY, KISS, YAGNI and LLM-specific failure modes before it ships, in any language.

    1.3k GitHub starsUsed in 2 repos~4.3k tokens
    DevelopmentAuto-check passed
  • Archify Review

    tt-a1i/archify

    Review Archify issues, PRs, or code through value, cost, and impact to support evidence-based maintenance decisions. Use for issue triage, change reviews, and…

    79k GitHub stars~415 tokensUpdated today
    DevelopmentAuto-check passed

More from totvs/engpro-advpl-tlpp-skills

All 19 skills in this repo
  • AdvPL UTF-8 to CP1252 Converter

    totvs/engpro-advpl-tlpp-skills

    Converts AdvPL and TLPP source files from UTF-8 to Windows-1252 in place after code generation, because the Protheus compiler accepts only CP1252 files.

    141 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed
  • AdvPL/TLPP Compile in VS Code

    totvs/engpro-advpl-tlpp-skills

    Compiles AdvPL and TLPP sources from VS Code with the TOTVS Developer Studio extension, handling server setup, connection and compile result reporting.

    141 GitHub stars~3.7k tokensUpdated 2 days ago
    Auto-check passed
  • Protheus Spec-Driven Development

    totvs/engpro-advpl-tlpp-skills

    Plans and builds Protheus AdvPL/TLPP features through Specify, Design, Tasks and Execute phases whose depth scales with the size of the change.

    141 GitHub stars~3.6k tokensUpdated 2 days ago
    Auto-check passed
  • Protheus Data Dictionary Lookup

    totvs/engpro-advpl-tlpp-skills

    Queries the TOTVS Protheus ERP data dictionary for tables, fields, indexes, parameters, triggers and lookups, including impact checks during refactoring.

    141 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Protheus MVC Generator

    totvs/engpro-advpl-tlpp-skills

    Generates Protheus MVC screens in ADVPL/TLPP, with ModelDef, ViewDef, MenuDef and Browse functions for single-entity and master-detail layouts.

    141 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed
  • Query Builder

    totvs/engpro-advpl-tlpp-skills

    Build optimized and safe SQL queries for Protheus tables. An agent skill from totvs/engpro-advpl-tlpp-skills.

    141 GitHub stars~4.7k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about AdvPL and TLPP Code Review

What does AdvPL and TLPP Code Review do?

Reviews AdvPL and TLPP source against SonarQube rules, ProtheusDOC requirements, security, performance and Protheus conventions, and reports findings by severity. prx extension are reviewed against TOTVS engineering standards, SonarQube static-analysis rules, ProtheusDOC documentation requirements and clean-code principles. The output is a categorized report with severity levels, rule references and fix suggestions that include code examples.

When should I use AdvPL and TLPP Code Review?

AdvPL and TLPP Code Review fits situations like: reviewing new or modified .prw, .tlpp or .prx files before merge; auditing legacy AdvPL code for SonarQube compliance; checking that ProtheusDOC blocks are complete and correct; looking for SQL injection or hardcoded credentials in Protheus code.

How do I install AdvPL and TLPP Code Review in Claude Code?

Run `npx skills add totvs/engpro-advpl-tlpp-skills --skill code-review -a claude-code`. Or copy the skill folder (skills/advpl-tlpp/code-review in totvs/engpro-advpl-tlpp-skills) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.

How do I install AdvPL and TLPP Code Review in Codex?

Run `npx skills add totvs/engpro-advpl-tlpp-skills --skill code-review -a codex`. Or copy the skill folder (skills/advpl-tlpp/code-review in totvs/engpro-advpl-tlpp-skills) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.

Can I use AdvPL and TLPP Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add totvs/engpro-advpl-tlpp-skills --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.

What does AdvPL and TLPP Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: AdvPL and TLPP Code Review is instructions for the agent only.

Does AdvPL and TLPP Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AdvPL and TLPP Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AdvPL and TLPP Code Review use?

AdvPL and TLPP Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AdvPL and TLPP Code Review use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.3k tokens, read only when the agent opens those files.

What are the alternatives to AdvPL and TLPP Code Review?

Skills that share tags, products or a category with AdvPL and TLPP Code Review: Structured Code Review (FareedKhan-dev/claude-code-from-scratch, 298 stars), WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Skill Doli Code Review (Dolibarr/dolibarr, 7.7k stars) and Dignified Python Standards (docling-project/docling, 68k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AdvPL and TLPP Code Review?

totvs (a GitHub organization) maintains it in totvs/engpro-advpl-tlpp-skills, which has 141 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 5, 2026.

Source: totvs/engpro-advpl-tlpp-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.