Skip to content
Back to skills

Python Database

ASecurity

Implement Python database access with parameterized SQL, transaction scope, connection helpers, and repository seams. Use when editing Postgres queries, repositories, transactions, pooling, or persistence boundaries in Python.

  • 549 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 5, 2026
developmentpythonsqldatabase

Works with

  • cursor

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill python-database --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Python Database?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Python Database
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-python-database-ff69f86b/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-python-database-ff69f86b)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: python-database
description: Implement Python database access with parameterized SQL, transaction scope, connection helpers, and repository seams. Use when editing Postgres queries, repositories, transactions, pooling, or persistence boundaries in Python.
metadata:
  triggers:
    files:
      - "**/repository/**/*.py"
      - "**/repositories/**/*.py"
      - "alembic.ini"
    keywords:
      - postgres
      - psycopg2
      - sqlalchemy
      - transaction
      - repository
      - sql
---

# Python Database

## **Priority: P1 (HIGH)**

## Rules

- Parameterize every query; never interpolate user or runtime data into SQL strings.
- Keep connection and transaction ownership explicit.
- Hide storage shape behind repository or query helpers when business logic depends on it.
- Normalize JSON and null handling at the persistence boundary.

## Recipe

1. **Open connections through one helper or pool abstraction**.
2. **Use context managers** for connection and transaction lifetime.
3. **Keep one business action in one transaction**.
4. **Return typed rows or normalized dicts**, not raw cursor tuples leaking everywhere.
5. **Test malformed/null metadata paths** when patching JSON payloads.

## Anti-Patterns

- **No f-string SQL**.
- **No transaction split-brain** across handler, service, and repo.
- **No unbounded connection churn** in loops.
- **No DB truth hidden behind report formatting code**.

## References

- [Framework Map](../references/framework-map.md)
- [DB Boundaries](references/db-boundaries.md)

Files in this skill

  • SKILL.md1.5 KB
  • evals/evals.json1.2 KB
  • references/db-boundaries.md348 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…