sqlalchemy-code-review — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited sqlalchemy-code-review (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
| Issue Type | Reference |
|---|---|
| Session lifecycle, context managers, async sessions | references/sessions.md |
| relationship(), lazy loading, N+1, joinedload | references/relationships.md |
| select() vs query(), ORM overhead, bulk ops | references/queries.md |
| Alembic patterns, reversible migrations, data migrations | references/migrations.md |
with, async with)relationship() uses appropriate lazy strategyjoinedload/selectinload to avoid N+1select() syntax, not legacy query()downgrade()op.execute() not ORM modelsRun once per SQLAlchemy-related finding, after you can anchor `file:line` (see review-verification-protocol) and before the finding ships. If a step’s pass condition is not met, do not assert the finding as written—gather evidence, withdraw, downgrade severity, or rephrase as a question.
| Step | Action | Pass condition |
|---|---|---|
| 1a | Open the module where the session is created or injected (not from memory). | `file:line` for Session, sessionmaker, async_session, or the factory/Depends() that yields a session. |
| 1b | If claiming leak, cross-request sharing, or missing cleanup: trace the session’s scope (context manager, try/finally, middleware). | Scoped region cited with a `file:line` range, or withdraw if scope is correct after the read. |
| Step | Action | Pass condition |
|---|---|---|
| 2a | Identify the loop or repeated call site (ORM attribute access, execute in a loop). | `file:line` for the loop or hot path. |
| 2b | If claiming N+1: name the relationship or query pattern emitted per iteration. | Relationship or per-iteration SQL pattern with `file:line`, or rephrase as a question if unclear. |
| Step | Action | Pass condition |
|---|---|---|
| 3a | Open the revision file (e.g. under versions/, or the project’s Alembic layout). | Repo-relative path + `file:line` for revision / upgrade / downgrade. |
| 3b | If claiming broken downgrade() or risky data migration: point at the op.* / op.execute() involved. | Snippet or line range in that file for each claimed op, or withdraw. |
select() syntax?~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.