# Sql Join Risk Reviewer

> Review SQL or report logic for many-to-many joins, duplicate-grain risk, unsafe aggregation, and filter side effects.

- **Type:** Skill
- **Install:** `agentstack add skill-nicholashidalgo-claude-skillforge-sql-join-risk-reviewer`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [nicholashidalgo](https://agentstack.voostack.com/s/nicholashidalgo)
- **Installs:** 0
- **Category:** [Databases](https://agentstack.voostack.com/c/databases)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [nicholashidalgo](https://github.com/nicholashidalgo)
- **Source:** https://github.com/nicholashidalgo/claude-skillforge/tree/main/data-engineering/sql-join-risk-reviewer

## Install

```sh
agentstack add skill-nicholashidalgo-claude-skillforge-sql-join-risk-reviewer
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

## Runtime Configuration
```yaml
version: "1.0.0"
gotcha_pack: "sql-data-gotcha-pack"
gotcha_pack_version: "1.0.0"
gotcha_enforcement: "block_on_high"
```

# Purpose
Review data logic before it breaks reporting.

## Check for
- unclear base grain
- one-to-many or many-to-many joins
- double counting risk
- filter placement issues
- late aggregation
- unsafe distinct usage
- date-table mismatches
- left join versus inner join consequences

## Output format
1. Primary risks
2. Why each risk matters
3. Safer rewrite guidance
4. Residual assumptions

## Gotcha Enforcement

Every review must explicitly check each rule below. Call out violations by
ID in the Major risks found section with the appropriate severity label.

| ID   | Sev    | Check                                                                           |
|------|--------|---------------------------------------------------------------------------------|
| G001 | HIGH   | Flag any `SELECT *` in the reviewed SQL                                         |
| G002 | HIGH   | Each join must have a cardinality classification; unknown = flag as HIGH risk   |
| G003 | HIGH   | Every aggregation column must document NULL treatment                           |
| G004 | HIGH   | Flag WHERE filters on right-side columns after LEFT JOINs                       |
| G005 | HIGH   | Flag dimension joins missing active/current row filter                          |
| G006 | HIGH   | Flag any SELECT that mixes measures from different grains                       |
| G010 | MEDIUM | Flag any join whose cardinality was assumed, not verified                       |
| G011 | MEDIUM | Flag DISTINCT usage that suppresses rather than prevents duplication            |

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [nicholashidalgo](https://github.com/nicholashidalgo)
- **Source:** [nicholashidalgo/claude-skillforge](https://github.com/nicholashidalgo/claude-skillforge)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-nicholashidalgo-claude-skillforge-sql-join-risk-reviewer
- Seller: https://agentstack.voostack.com/s/nicholashidalgo
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
