Skip to content
Back to skills

Soql Authoring

ASecurity

Write selective, bulk-safe SOQL that binds its variables and avoids non-selective-query errors on large objects. Use when authoring or fixing a SOQL query, especially against high-volume objects.

  • 7 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 23, 2026
ai-agentsapisecurity

Works with

  • api

Security analysis

A100/100

Scanned September 23, 2026

npx -y skills add mcorbett51090/RavenClaude --skill soql-authoring --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Soql Authoring?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Soql Authoring
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/mcorbett51090-soql-authoring/badge)](https://www.skillsdirectory.com/skills/mcorbett51090-soql-authoring)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: soql-authoring
description: Write selective, bulk-safe SOQL that binds its variables and avoids non-selective-query errors on large objects. Use when authoring or fixing a SOQL query, especially against high-volume objects.
---

# SOQL Authoring

Produce a SOQL query that is selective (index-friendly), bulk-safe, and injection-safe.

## When to use

Authoring a new query, fixing a non-selective-query error, or hardening dynamic SOQL.

## Steps

1. **Filter on an indexed field.** Prefer Id, Name, audit fields, lookups, external IDs, unique fields, or a custom index. Reject leading-`%` wildcards and negative operators on large objects. See `knowledge/large-data-volume-design.md`.
2. **Make the filter selective.** Confirm the predicate clears the optimizer threshold; add a bounded date/status filter if it doesn't.
3. **Bind every variable.** Use `:var` bind syntax — never string-concatenate user input. For dynamic SOQL, bind or `String.escapeSingleQuotes`. (House opinion #8; escalate injection findings to `ravenclaude-core/security-reviewer`.)
4. **Enforce FLS.** Add `WITH USER_MODE` for user-context queries. **At API v67.0+ (Summer '26) `WITH SECURITY_ENFORCED` is removed and does not compile** — use `WITH USER_MODE` (also supports polymorphic fields and returns the full set of access errors); on older API versions `WITH SECURITY_ENFORCED` still works. `[verify-at-build]`
5. **Stay bulk-safe.** Query once with `WHERE Id IN :ids`; never put the query in a loop.
6. **Limit the result.** Add `LIMIT` and select only the fields you use.

## Output

The query, the index it relies on, the bind variables, and a one-line note on selectivity and FLS.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…