sqlx-code-review
Installation
SKILL.md
sqlx Code Review
Review Workflow
- Check Cargo.toml — Note sqlx features (
runtime-tokio,tls-rustls/tls-native-tls,postgres/mysql/sqlite,uuid,chrono,json,migrate) and Rust edition (2024 changes RPIT lifetime capture and removes need forasync-trait) - Check query patterns — Compile-time checked (
query!,query_as!) vs runtime (query,query_as) - Check pool configuration — Connection limits, timeouts, idle settings
- Check migrations — File naming, reversibility, data migration safety
- Check type mappings — Rust types align with SQL column types
Gates (evidence before severity)
Complete in order; do not assign Critical / Major until the gate for that claim is passed.
- Scope — Identify the crate under review (
Cargo.tomlpath) and the.rsfiles (or directory) you opened. Pass: At least one concrete path you inspected is named. - sqlx / compile claims — Before asserting issues about
query!/query_as!, offline mode,sqlx.toml,DATABASE_URL, or Cargo features: open the relevantCargo.tomland, if applicable,sqlx.tomlor documented env. Pass: The finding cites a line or you state that those files were absent / out of scope. - Finding anchors — Each reported issue includes
[FILE:LINE]per Output Format. Pass: No Critical or Major without a line reference. - Protocol — Load and complete the review-verification-protocol skill after gates 1–3 and before final severity labels. Pass: Protocol steps satisfied for each retained finding.