Skip to content
Back to skills

Database Hana

ASecurity

Apply SAP HANA database standards for SQL parameterization, in-memory engine optimization, dynamic IN query chunking, column aliasing on joins, and datatype casting. Use when writing SQL for SAP HANA, optimizing HANA queries, or diagnosing HANA driver errors.

  • 549 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 5, 2026
developmentrustgosqldatabase

Security analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned September 21, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill database-hana --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Database Hana?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Database Hana
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-database-hana/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-database-hana)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: database-hana
description: Apply SAP HANA database standards for SQL parameterization, in-memory engine optimization, dynamic IN query chunking, column aliasing on joins, and datatype casting. Use when writing SQL for SAP HANA, optimizing HANA queries, or diagnosing HANA driver errors.
metadata:
  triggers:
    files:
      - "**/*hana*.go"
      - "**/*sap*.go"
      - "**/hana/**"
      - "**/*hana*.sql"
    keywords:
      - HANA
      - SAP HANA
      - hdb
      - go-hdb
      - CalculationView
  upstream:
    - name: hana
      source: manual
      pinned: "2.0"
      reviewed: "2026-08-24"
---

# SAP HANA Database Standards

## **Priority: P0 (CRITICAL)**

## Rules

- **Strict Parameterization**: Always use `?` parameter placeholders for SAP HANA queries. Never use raw string concatenation, `fmt.Sprintf`, or untrusted interpolation for values.
- **Batching & Chunking Limits**: Chunk large `IN (...)` parameter lists into batches of at most 1,000 items to avoid HANA driver and engine parameter limits.
- **Explicit Column Aliasing**: Always explicitly alias columns in multi-table queries (e.g. `m.code AS code`, `m.name AS name`). SAP HANA and Go database drivers map scan columns by name; duplicate column names across joins silently collide or overwrite values. Never use `SELECT *`.
- **HANA Datatype Casting Gotchas**: SAP HANA functions (such as `COALESCE`, `SUBSTR`, `CONCAT`) require strictly compatible parameter types. Explicitly cast values when comparing or falling back (e.g. `COALESCE(col, 'default')`, `TO_VARCHAR(...)`, `CAST(? AS NVARCHAR)`).
- **Identifier Case-Sensitivity**: Unquoted SQL identifiers in SAP HANA default to UPPERCASE. Quoted identifiers (`"columnName"`) preserve case. Keep identifiers consistent with schema conventions.
- **Keyset & Streaming Pagination**: Avoid deep `LIMIT/OFFSET` on large columnar tables. Prefer keyset/seek pagination (`WHERE id > ? ORDER BY id ASC LIMIT ?`) and stream large result sets using `rows.Next()` directly into models to prevent memory spikes.
- **Transaction Scope**: Keep transactions short and focused on atomic write operations. Never perform slow external I/O or unbounded operations inside an open transaction. Always pair with `defer tx.Rollback()`.

## Verify

- [ ] Query uses `?` placeholders for all user-supplied or dynamic values.
- [ ] Large `IN (...)` queries chunk parameters into batches of ≤ 1,000 items.
- [ ] All joined queries use explicit, distinct column aliases without `SELECT *`.
- [ ] Built-in functions (`COALESCE`, `SUBSTR`) use matching datatypes or explicit `CAST`/`TO_VARCHAR`.
- [ ] Pagination enforces strict `LIMIT` caps and stable `ORDER BY`.
- [ ] Transactions are scoped to write paths with `defer tx.Rollback()`.

## Anti-Patterns

- **No SQL String Concatenation**: Never build dynamic `WHERE` clauses by concatenating unescaped strings. Build parameterized placeholder slices.
- **No Unbounded IN Clauses**: Passing thousands of IDs in a single `IN (?, ?, ...)` clause triggers HANA driver buffer overflow or query parsing degradation.
- **No SELECT \* on Joins**: Scanning duplicate column names across joined tables leads to silent bugs where one table's ID overwrites another.
- **No Incompatible COALESCE Arguments**: Providing mismatched types (e.g. integer column with string fallback) causes runtime HANA `inconsistent datatype` errors.
- **No Heavy Reads Inside Transactions**: Do not perform long calculation view aggregations or external network calls while holding an open transaction lock.

## References

- [SAP HANA Patterns & Query Builders](references/hana-patterns.md)
- [SAP HANA SQL Gotchas](references/sql-gotchas.md)

Files in this skill

  • SKILL.md3.5 KB
  • evals/evals.json2.1 KB
  • references/hana-patterns.md2.8 KB
  • references/sql-gotchas.md2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…