Agent skill

SQL Code Review

by totvs in totvs/engpro-advpl-tlpp-skills

Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across SQL databases (PostgreSQL, SQL Server, Oracle).

MITAuto-check passedDatabases

Install SQL Code Review

skills CLI
$ npx skills add totvs/engpro-advpl-tlpp-skills --skill sql-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install totvs/engpro-advpl-tlpp-skills sql-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/totvs/engpro-advpl-tlpp-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/advpl-tlpp/sql-code-review .claude/skills/sql-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sql-code-review
GitHub stars
141
Token cost
~3.5k tokens
SKILL.md length
1,044 words
Files
4 (incl. references)
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across SQL databases (PostgreSQL, SQL Server, Oracle).

  • Works in 4 steps: Identify Scope and Database → Load Relevant References → Analyze Code Against Checklist → …
  • User says review SQL
  • SKILL.md covers Review Categories, Bundled Reference Files, Review Workflow and SQL Review Checklist, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

SQL Code Review is an agent skill from totvs/engpro-advpl-tlpp-skills. Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across SQL databases (PostgreSQL, SQL Server, Oracle). Focuses on SQL injection prevention, access control, code standards, and anti-pattern detection. Complements SQL optimization prompt for complete development coverage. Use when user says "review SQL", "SQL security audit", "SQL anti-patterns", "check SQL quality".

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/database-specific-best-practices.md`, `references/sql-performance-and-quality-patterns.md` and `references/sql-security-patterns.md`).

It sits in Databases, covering SQL, Code review and Code quality. It works with SQL, Microsoft SQL Server and PostgreSQL. The repository describes itself as: Repositório contendo skills para orientar desenvolvimento ADVPL/TLPP com agentes de IA. The licence is MIT.

When your agent uses it

  • User says review SQL
  • SQL security audit
  • SQL anti-patterns
  • Check SQL quality

Example prompts

  • “review SQL”
  • “SQL security audit”
  • “SQL anti-patterns”
  • “/sql-code-review”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Identify Scope and Database
  2. Load Relevant References
  3. Analyze Code Against Checklist
  4. Generate Report

What it can do on your machine

Read from SKILL.md and the folder at commit 3908e4e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are advpl and sql).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

SQL Code Review loads about 3.5k tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 1,044 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from totvs/engpro-advpl-tlpp-skills at commit 3908e4e, republished under its MIT licence (© totvs). 1,044 words, ~3,520 tokens.

Download SKILL.mdSave it as .claude/skills/sql-code-review/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
sql-code-review
description
Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across SQL databases (PostgreSQL, SQL Server, Oracle). Focuses on SQL injection prevention, access control, code standards, and anti-pattern detection. Complements SQL optimization prompt for complete development coverage. Use when user says "review SQL", "SQL security audit", "SQL anti-patterns", "check SQL quality".
license
MIT
metadata.domain
Protheus
metadata.maintainer
Customizações ADVPL/TLPP
metadata.author
Thalion Starforge
metadata.version
4.2.0
metadata.category
Code Quality and Review

SQL Code Review

Perform a thorough SQL code review of ${selection} (or entire project if no selection) focusing on security, performance, maintainability, and database best practices.

Review Categories

🔒 Security
  • SQL Injection Prevention — all user inputs must be parameterized; no string concatenation in queries
  • Access Control — principle of least privilege, role-based permissions, schema security
  • Data Protection — avoid SELECT * on sensitive tables, enforce audit logging and data masking
⚡ Performance
  • Query Structure — eliminate SELECT DISTINCT *, prefer explicit JOINs over comma-separated FROM
  • Index Strategy — verify indexes for WHERE/JOIN columns, flag over-indexing and unused indexes
  • Join Optimization — correct join types, optimal join order, no accidental Cartesian products
  • Aggregation — replace correlated subqueries with JOIN/GROUP BY when possible
🛠️ Code Quality
  • Formatting — consistent uppercase keywords, aligned columns, proper indentation
  • Naming — descriptive table/column names, no reserved words as identifiers, consistent casing
  • Schema Design — appropriate normalization, optimal data types, proper constraints and defaults
🗄️ Database Compatibility
  • ANSI SQL first — use COALESCE, CASE WHEN, ANSI JOINs, FETCH FIRST for portability
  • Database-specific idioms — leverage engine-specific features (JSONB, COLUMNSTORE, sequences) where appropriate

Protheus note: Use ChangeQuery() to automatically translate SQL syntax to the active database dialect. BeginSQL/EndSQL calls ChangeQuery() automatically.


Bundled Reference Files

This skill uses progressive disclosure. The SKILL.md body covers the review workflow, category definitions, checklist, and output format. Detailed code examples, anti-patterns, and database-specific best practices are in the references/ directory — read them on demand based on the scenario:

Reference FileWhen to ReadContent
references/sql-security-patterns.mdReviewing security concerns — SQL injection, access control, data protection, or dynamic SQLInjection examples, parameterization patterns, access control checklist, data masking examples
references/sql-performance-and-quality-patterns.mdReviewing query performance, code style, anti-patterns, or testing strategiesQuery optimization examples, JOIN/aggregation patterns, N+1 and DISTINCT anti-patterns, formatting standards, data integrity checks
references/database-specific-best-practices.mdReviewing SQL targeting a specific database (PostgreSQL, SQL Server, Oracle) or cross-database portabilityANSI SQL cross-database patterns, PostgreSQL (JSONB, GIN), SQL Server (NVARCHAR, COLUMNSTORE), Oracle (sequences, VARCHAR2)

Also refer to references/sonarqube-rules-reference.md for the complete SonarQube rules reference shared across skills.


Review Workflow

Step 1: Identify Scope and Database

Determine from the user's request:

  • Which SQL files or queries to review
  • Target database engine (PostgreSQL, SQL Server, Oracle, or multi-database)
  • Review focus (security, performance, quality, or full review)
Step 2: Load Relevant References

Based on the review focus and database, read the appropriate reference files:

Step 3: Analyze Code Against Checklist

Walk through each category in the checklist below. For each finding, classify priority as CRITICAL, HIGH, MEDIUM, or LOW.

Step 4: Generate Report

Use the Issue Template (below) for each finding. Group findings by category and sort by priority.


SQL Review Checklist

Security
  • All user inputs are parameterized
  • No dynamic SQL construction with string concatenation
  • Appropriate access controls and permissions
  • Sensitive data is properly protected
  • SQL injection attack vectors are eliminated
Performance
  • Indexes exist for frequently queried columns
  • No unnecessary SELECT * statements
  • JOINs are optimized and use appropriate types
  • WHERE clauses are selective and use indexes
  • Subqueries are optimized or converted to JOINs
Code Quality
  • Consistent naming conventions
  • Proper formatting and indentation
  • Meaningful comments for complex logic
  • Appropriate data types are used
  • Error handling is implemented
Schema Design
  • Tables are properly normalized
  • Constraints enforce data integrity
  • Indexes support query patterns
  • Foreign key relationships are defined
  • Default values are appropriate

Review Output Format

Issue Template
## [PRIORITY] [CATEGORY]: [Brief Description]

**Location**: [Table/View/Procedure name and line number if applicable]
**Issue**: [Detailed explanation of the problem]
**Security Risk**: [If applicable - injection risk, data exposure, etc.]
**Performance Impact**: [Query cost, execution time impact]
**Recommendation**: [Specific fix with code example]

**Before**:
```sql
-- Problematic SQL

After:

sql
-- Improved SQL

Expected Improvement: [Performance gain, security benefit]


### Summary Assessment
- **Security Score**: [1-10] - SQL injection protection, access controls
- **Performance Score**: [1-10] - Query efficiency, index usage
- **Maintainability Score**: [1-10] - Code quality, documentation
- **Schema Quality Score**: [1-10] - Design patterns, normalization

### Top 3 Priority Actions
1. **[Critical Security Fix]**: Address SQL injection vulnerabilities
2. **[Performance Optimization]**: Add missing indexes or optimize queries
3. **[Code Quality]**: Improve naming conventions and documentation

Focus on providing actionable, database-agnostic recommendations while highlighting platform-specific optimizations and best practices.

> **Cross-Database Review Tip:** When reviewing Protheus SQL, verify the query is compatible with all three supported databases (PostgreSQL, MSSQL, Oracle). Use `ChangeQuery()` for automatic SQL dialect translation, or `TCGetDB()` for runtime DB detection when DB-specific logic is unavoidable.

---

## Protheus SQL Patterns

When reviewing SQL in the TOTVS Protheus ecosystem — whether embedded SQL (preferring `FWExecStatement`, with legacy `TCQuery` / `TCSqlExec` calls), Workarea-based access, or standalone queries — apply the following additional checks.

### Table and Field Naming Conventions

Protheus uses standardized short-name tables and fields managed through the data dictionary:

| Alias | Module | Description |
|-------|--------|-------------|
| SA1 | All | Customers |
| SA2 | All | Suppliers |
| SB1 | SIGAEST | Products |
| SC5 | SIGAFAT | Sales Orders (header) |
| SC6 | SIGAFAT | Sales Orders (items) |
| SD1 | SIGACOM | Purchase document items |
| SD2 | SIGAFAT | Sales document items |
| SE1 | SIGAFIN | Accounts Receivable |
| SE2 | SIGAFIN | Accounts Payable |
| SF1 | SIGACOM | Incoming invoices (header) |
| SF2 | SIGAFAT | Outgoing invoices (header) |
| SX2 | System | Table dictionary |
| SX3 | System | Field dictionary |
| SIX | System | Index dictionary |

Fields follow the pattern `<prefix>_<name>`, e.g., `A1_COD` (customer code), `A1_NOME` (customer name), `D1_DOC` (document number).

### Mandatory Filters for Protheus Tables

Every query against a Protheus table **must** include these filters unless there is an explicit reason to omit them:

```sql
-- BAD: Missing mandatory filters — returns deleted records and all branches
SELECT A1_COD, A1_NOME FROM SA1010

-- GOOD: Proper Protheus query with mandatory filters
SELECT A1_COD, A1_NOME
FROM SA1010
WHERE D_E_L_E_T_ = ' '
  AND A1_FILIAL  = '01'
FilterPurpose
D_E_L_E_T_ = ' 'Excludes logically deleted records (soft delete). Always required.
<prefix>_FILIAL = cFilAntMulti-branch filter (tenant isolation). Required unless deliberately querying across branches.
Workarea vs. Embedded SQL Decision Matrix
ScenarioRecommended Approach
Single-record lookup by index keyWorkarea (DbSelectArea / DbSetOrder / DbSeek)
Sequential processing of a filtered setWorkarea with While loop
Complex joins across multiple tablesEmbedded SQL via FWExecStatement
Aggregate queries (SUM, COUNT, AVG)Embedded SQL via FWExecStatement (use :ExecScalar() for single values)
Bulk INSERT/UPDATE/DELETE operationsFWExecStatement + TCSqlExec(oStatement:GetFixQuery())
Reports with heavy filteringEmbedded SQL via FWExecStatement, or temporary tables via TCSqlExec
Show full SKILL.md (389 more words)Show less
Workarea Access Review Checklist
advpl
// GOOD: Complete workarea access pattern
DbSelectArea("SA1")
DbSetOrder(1)           // Set the index defined in SIX
If DbSeek(FWxFilial("SA1") + cCodCli)
  // process record...
EndIf
  • DbSelectArea() called before any workarea operation
  • DbSetOrder() set to the correct SIX index
  • DbSeek() includes branch prefix via FWxFilial()
  • Write operations wrapped with RecLock() / MsUnlock()
  • While loops include !Eof() and SA1->(DbSkip()) pattern
Embedded SQL Review Checklist
advpl
// GOOD: Parameterized embedded SQL via FWExecStatement (DB-side bind, cacheable)
Local cQuery as Character
Local oExec  as Object
Local cAlias as Character

cQuery := "SELECT A1_COD, A1_NOME "
cQuery += "FROM " + RetSqlName("SA1") + " SA1 "
cQuery += "WHERE D_E_L_E_T_ = ? "
cQuery += "AND A1_FILIAL = ? "
cQuery += "AND A1_COD = ? "

oExec := FWExecStatement():New(ChangeQuery(cQuery))
oExec:SetString(1, ' ')
oExec:SetString(2, FWxFilial("SA1"))
oExec:SetString(3, cCodCli)

cAlias := oExec:OpenAlias("QRY_CLI")
// ... consume (cAlias)->A1_COD / A1_NOME ...
(cAlias)->(DbCloseArea())
oExec:Destroy()
  • Uses RetSqlName() to get the physical table name (handles company suffix)
  • Includes D_E_L_E_T_ = ' ' filter
  • Includes branch filter via FWxFilial()
  • Temporary alias is closed after use (QRY_CLI->(DbCloseArea()))
  • String values are sanitized to prevent SQL injection (use FWExecStatement — no raw user input concatenated)
Common Protheus SQL Anti-Patterns
Anti-PatternProblemFix
Missing D_E_L_E_T_ filterReturns deleted recordsAlways add D_E_L_E_T_ = ' '
SELECT * on Protheus tablesProtheus tables have many system fields; wastes bandwidthSelect only needed columns
Full table scan on SD1/SD2/SE1/SE2These transactional tables can have millions of rowsUse indexed columns in WHERE clause
Missing %nolock% on SQL ServerCauses lock escalation on read queriesAdd %nolock% hint: FROM SA1010 WITH (%nolock%) — the %nolock% DBAccess macro translates to WITH (NOLOCK) on MSSQL and is silently ignored on PostgreSQL/Oracle (MVCC)
Concatenating user input into SQLSQL injection vulnerabilityUse FWExecStatement or TcGenQry2 to parameterize queries
Not closing temporary aliasesResource leak, workarea pollutionAlways QRY->(DbCloseArea()) after use
Hardcoding table suffix (e.g., SA1010)Breaks in multi-company environmentsUse RetSqlName("SA1")
Creating procedures directly in sourceProhibited — violates SonarQube rulesUse SPManager for procedure management
Direct queries without evaluation (Cloud)Queries may not be Cloud-compatibleEvaluate Cloud impact; prefer framework APIs where available
Using SE5 table directlySE5 is deprecatedUse FKx family functions + ExecAuto
Using IIF in SQL or AdvPL expressionsProhibited for clean codeReplace with CASE WHEN (SQL) or If/Else/EndIf (AdvPL)
SIX Index Dictionary Awareness

Protheus indexes are defined in the SIX dictionary. When writing queries or using workareas:

  • Check available indexes before choosing DbSetOrder() — using the wrong order leads to full scans
  • Index 1 is typically: branch + primary key (e.g., A1_FILIAL + A1_COD + A1_LOJA)
  • Composite indexes should be leveraged in WHERE clauses matching left-to-right column order
  • Never create ad-hoc indexes in production without SIX registration
Protheus SQL Security
  • Never concatenate raw user input into SQL strings — use FWExecStatement or TcGenQry2 for parameterized queries
  • Never expose table structure in error messages returned to the client
  • Validate input length against SX3 field size before inserting/updating
  • Use FWExecView for user-facing queries when possible (respects field-level security)

Refer to references/sonarqube-rules-reference.md for the complete SonarQube rules reference.

© totvs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/advpl-tlpp/sql-code-review of totvs/engpro-advpl-tlpp-skills.

  • SKILL.md
  • references/database-specific-best-practices.md
  • references/sql-performance-and-quality-patterns.md
  • references/sql-security-patterns.md

Open the folder on GitHubat commit 3908e4e

Compare with similar skills

SQL Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

SQL Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
SQL Code Review this skilltotvs/engpro-advpl-tlpp-skills141—~3.5kAutomated safety check: PassMIT
SQL Code Reviewgithub/awesome-copilot40k1 repos~2.2kAutomated safety check: PassMIT
Query Builderthalysjuvenal/advpl-specialist185—~594Automated safety check: PassMIT
Azure MigrateMicrosoftDocs/Agent-Skills775—~5.2kAutomated safety check: PassCC-BY-4.0
Database Migrations SQL Migrationsrmyndharis/antigravity-skills1.7k2 repos~577Automated safety check: NotesMIT
Ron Databasebionic-gpt/bionic-gpt2.4k—~721Automated safety check: PassApache-2.0

Similar skills

  • SQL Code Review

    github/awesome-copilot

    Official

    Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across all SQL databases (MySQL, PostgreSQL, SQL Server, Oracle).

    40k GitHub starsUsed in 1 repo~2.2k tokens
    DatabasesAuto-check passed
  • Query Builder

    thalysjuvenal/advpl-specialist

    A skill your agent uses when the user needs to build, choose the pattern for, or optimize a SQL query against Protheus ERP tables -- covering Workarea (DbSelectArea/DbSeek) vs Embedded SQL vs…

    185 GitHub stars~594 tokensUpdated 23 days ago
    DatabasesAuto-check passed
  • Azure Migrate

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Migrate development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations &…

    775 GitHub stars~5.2k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Database Migrations SQL Migrations

    rmyndharis/antigravity-skills

    SQL database migrations with zero-downtime strategies for PostgreSQL, MySQL, SQL Server

    1.7k GitHub starsUsed in 2 repos~577 tokens
    DatabasesAuto-check: notes
  • Ron Database

    bionic-gpt/bionic-gpt

    Manage PostgreSQL migrations, typed SQL queries, generated Rust bindings, and database authorization in Rust on Nails applications.

    2.4k GitHub stars~721 tokensUpdated today
    DatabasesAuto-check passed
  • SQL Pro

    Jeffallan/claude-skills

    Optimizes SQL queries and designs schemas using CTEs, window functions, covering indexes and EXPLAIN ANALYZE, with notes on dialect differences between major databases.

    12k GitHub stars~1.3k tokensUpdated 4 days ago
    DatabasesAuto-check passed

More from totvs/engpro-advpl-tlpp-skills

All 19 skills in this repo
  • AdvPL UTF-8 to CP1252 Converter

    totvs/engpro-advpl-tlpp-skills

    Converts AdvPL and TLPP source files from UTF-8 to Windows-1252 in place after code generation, because the Protheus compiler accepts only CP1252 files.

    141 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed
  • AdvPL/TLPP Compile in VS Code

    totvs/engpro-advpl-tlpp-skills

    Compiles AdvPL and TLPP sources from VS Code with the TOTVS Developer Studio extension, handling server setup, connection and compile result reporting.

    141 GitHub stars~3.7k tokensUpdated 2 days ago
    Auto-check passed
  • Protheus Spec-Driven Development

    totvs/engpro-advpl-tlpp-skills

    Plans and builds Protheus AdvPL/TLPP features through Specify, Design, Tasks and Execute phases whose depth scales with the size of the change.

    141 GitHub stars~3.6k tokensUpdated 2 days ago
    Auto-check passed
  • AdvPL and TLPP Code Review

    totvs/engpro-advpl-tlpp-skills

    Reviews AdvPL and TLPP source against SonarQube rules, ProtheusDOC requirements, security, performance and Protheus conventions, and reports findings by severity.

    141 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Protheus Data Dictionary Lookup

    totvs/engpro-advpl-tlpp-skills

    Queries the TOTVS Protheus ERP data dictionary for tables, fields, indexes, parameters, triggers and lookups, including impact checks during refactoring.

    141 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Protheus MVC Generator

    totvs/engpro-advpl-tlpp-skills

    Generates Protheus MVC screens in ADVPL/TLPP, with ModelDef, ViewDef, MenuDef and Browse functions for single-entity and master-detail layouts.

    141 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed

Questions about SQL Code Review

What does SQL Code Review do?

Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across SQL databases (PostgreSQL, SQL Server, Oracle). SQL Code Review is an agent skill from totvs/engpro-advpl-tlpp-skills. Universal SQL code review assistant that performs comprehensive security, maintainability, and code quality analysis across SQL databases (PostgreSQL, SQL Server, Oracle).

When should I use SQL Code Review?

SQL Code Review fits situations like: user says review SQL; SQL security audit; SQL anti-patterns; check SQL quality.

How do I install SQL Code Review in Claude Code?

Run `npx skills add totvs/engpro-advpl-tlpp-skills --skill sql-code-review -a claude-code`. Or copy the skill folder (skills/advpl-tlpp/sql-code-review in totvs/engpro-advpl-tlpp-skills) into .claude/skills/sql-code-review in your project. Claude Code loads it when a task matches its description.

How do I install SQL Code Review in Codex?

Run `npx skills add totvs/engpro-advpl-tlpp-skills --skill sql-code-review -a codex`. Or copy the skill folder (skills/advpl-tlpp/sql-code-review in totvs/engpro-advpl-tlpp-skills) into .agents/skills/sql-code-review in your project. Codex loads it when a task matches its description.

Can I use SQL Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add totvs/engpro-advpl-tlpp-skills --skill sql-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sql-code-review, .gemini/skills/sql-code-review, .github/skills/sql-code-review and .opencode/skills/sql-code-review in your project.

What does SQL Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: SQL Code Review is instructions for the agent only.

Does SQL Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is SQL Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does SQL Code Review use?

SQL Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does SQL Code Review use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3k tokens, read only when the agent opens those files.

What are the alternatives to SQL Code Review?

Skills that share tags, products or a category with SQL Code Review: SQL Code Review (github/awesome-copilot, 40k stars), Query Builder (thalysjuvenal/advpl-specialist, 185 stars), Azure Migrate (MicrosoftDocs/Agent-Skills, 775 stars) and Database Migrations SQL Migrations (rmyndharis/antigravity-skills, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains SQL Code Review?

totvs (a GitHub organization) maintains it in totvs/engpro-advpl-tlpp-skills, which has 141 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 5, 2026.

Source: totvs/engpro-advpl-tlpp-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.