Install
$ agentstack add skill-nicholashidalgo-claude-skillforge-sql-join-risk-reviewer ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Runtime Configuration
version: "1.0.0"
gotcha_pack: "sql-data-gotcha-pack"
gotcha_pack_version: "1.0.0"
gotcha_enforcement: "block_on_high"
Purpose
Review data logic before it breaks reporting.
Check for
- unclear base grain
- one-to-many or many-to-many joins
- double counting risk
- filter placement issues
- late aggregation
- unsafe distinct usage
- date-table mismatches
- left join versus inner join consequences
Output format
- Primary risks
- Why each risk matters
- Safer rewrite guidance
- Residual assumptions
Gotcha Enforcement
Every review must explicitly check each rule below. Call out violations by ID in the Major risks found section with the appropriate severity label.
| ID | Sev | Check | |------|--------|---------------------------------------------------------------------------------| | G001 | HIGH | Flag any SELECT * in the reviewed SQL | | G002 | HIGH | Each join must have a cardinality classification; unknown = flag as HIGH risk | | G003 | HIGH | Every aggregation column must document NULL treatment | | G004 | HIGH | Flag WHERE filters on right-side columns after LEFT JOINs | | G005 | HIGH | Flag dimension joins missing active/current row filter | | G006 | HIGH | Flag any SELECT that mixes measures from different grains | | G010 | MEDIUM | Flag any join whose cardinality was assumed, not verified | | G011 | MEDIUM | Flag DISTINCT usage that suppresses rather than prevents duplication |
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: nicholashidalgo
- Source: nicholashidalgo/claude-skillforge
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.