Agent skill

Database Migration Patterns with RLS

by bybren-llc in bybren-llc/safe-agentic-workflow

“Database migration creation with mandatory RLS policies and ARCHitect approval workflow. Use when creating migrations, adding tables with RLS, updating ORM schema, adding GRANT…”

— description from SKILL.md by bybren-llc
MITAuto-check passedDatabases

Install Database Migration Patterns with RLS

skills CLI
$ npx skills add bybren-llc/safe-agentic-workflow --skill migration-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bybren-llc/safe-agentic-workflow migration-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bybren-llc/safe-agentic-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/migration-patterns .claude/skills/migration-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
migration-patterns
GitHub stars
421
Token cost
~1.3k tokens
SKILL.md length
244 words
Files
4 (incl. scripts, references, assets)
Skills in repo
42
Repo updated
First seen
Licence
MIT

At a glance

  • Works in 5 steps: Get ARCHitect Approval → Create Migration → Add RLS to Migration → …
  • SKILL.md covers Purpose, When This Skill Applies, Stop-the-Line Conditions and Migration Workflow (MANDATORY), plus 4 more sections
  • Calls npx and psql

About this skill

“Database migration creation with mandatory RLS policies and ARCHitect approval workflow. Use when creating migrations, adding tables with RLS, updating ORM schema, adding GRANT statements, or planning data migrations. Do NOT use for application code changes without schema impact.”

— description from SKILL.md by bybren-llc

Database Migration Patterns with RLS is a skill in bybren-llc/safe-agentic-workflow (421 stars). Its SKILL.md is about 1.3k tokens, with 3 other files in the folder (scripts, references, assets). Licence: MIT.

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Get ARCHitect Approval
  2. Create Migration
  3. Add RLS to Migration
  4. Verify Locally
  5. Update Documentation

What it can do on your machine

Read from SKILL.md and the folder at commit 26ca58b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • npx
    • psql

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Database Migration Patterns with RLS loads about 1.3k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 244 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from bybren-llc/safe-agentic-workflow at commit 26ca58b, republished under its MIT licence (© bybren-llc). 244 words, ~1,273 tokens.

Download SKILL.mdSave it as .claude/skills/migration-patterns/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
migration-patterns
description
Database migration creation with mandatory RLS policies and ARCHitect approval workflow. Use when creating migrations, adding tables with RLS, updating ORM schema, adding GRANT statements, or planning data migrations. Do NOT use for application code changes without schema impact.

Migration Patterns Skill

TEMPLATE: This skill uses {{PLACEHOLDER}} tokens. Replace with your project values before use.

Purpose

Guide database migration creation with mandatory RLS policies, following security-first architecture and approval workflow.

When This Skill Applies

  • Creating database migrations
  • Adding new tables (all tables need RLS)
  • Updating ORM schema
  • Adding GRANT statements
  • Schema impact analysis
  • Data migration planning

Stop-the-Line Conditions

FORBIDDEN Patterns
sql
-- FORBIDDEN: RLS policies in separate file
-- RLS MUST be in the same migration file as the table creation

-- FORBIDDEN: Table without RLS
CREATE TABLE user_data (...);
-- Missing: ALTER TABLE user_data ENABLE ROW LEVEL SECURITY;

-- FORBIDDEN: Resolve applied migrations (bypasses verification)
-- npx prisma migrate resolve --applied "migration_name"
-- alembic stamp head

-- FORBIDDEN: Missing user_id index
CREATE TABLE payments (...);
-- Missing: CREATE INDEX idx_payments_user_id ON payments(user_id);

-- FORBIDDEN: Schema changes without ARCHitect approval
-- All migrations require approval before PR
CORRECT Patterns
sql
-- CORRECT: Complete migration with RLS in same file
CREATE TABLE user_data (
  id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
  user_id TEXT NOT NULL,
  data JSONB,
  created_at TIMESTAMPTZ DEFAULT NOW()
);

-- Enable RLS (SAME FILE - MANDATORY)
ALTER TABLE user_data ENABLE ROW LEVEL SECURITY;

-- User policy
CREATE POLICY user_data_user_select ON user_data
  FOR SELECT TO {{PROJECT}}_app_user
  USING (user_id = current_setting('app.current_user_id', true));

-- Index for RLS performance (MANDATORY)
CREATE INDEX idx_user_data_user_id ON user_data(user_id);

-- Grant permissions
GRANT SELECT, INSERT, UPDATE ON user_data TO {{PROJECT}}_app_user;

Migration Workflow (MANDATORY)

Step 1: Get ARCHitect Approval

Before ANY schema change:

text
1. Document proposed changes
2. Get ARCHitect approval (create issue or discussion)
3. Only proceed after explicit approval
Step 2: Create Migration
bash
# For Prisma
npx prisma migrate dev --name descriptive_name

# For Alembic
alembic revision --autogenerate -m "descriptive_name"

# Verify migration file created
ls {{MIGRATIONS_DIR}}/
Step 3: Add RLS to Migration

Edit the generated migration to include:

  • ALTER TABLE ... ENABLE ROW LEVEL SECURITY
  • User SELECT policy
  • User INSERT policy (if applicable)
  • User UPDATE policy (if applicable)
  • Admin policies (if needed)
  • System policies (for background jobs)
  • Index on user_id column
  • GRANT statements
Step 4: Verify Locally
bash
# Test migration
{{MIGRATION_RUN_COMMAND}}

# Verify RLS is enabled
psql -c "SELECT tablename, rowsecurity FROM pg_tables WHERE schemaname = 'public';"
Step 5: Update Documentation

After successful migration:

  • Update docs/database/DATA_DICTIONARY.md (MANDATORY)
  • Update RLS policy catalog if new policies added
  • Document in ticket

RLS Policy Templates

User Read Policy
sql
CREATE POLICY {table}_user_select ON {table}
  FOR SELECT TO {{PROJECT}}_app_user
  USING (user_id = current_setting('app.current_user_id', true));
User Write Policy
sql
CREATE POLICY {table}_user_insert ON {table}
  FOR INSERT TO {{PROJECT}}_app_user
  WITH CHECK (user_id = current_setting('app.current_user_id', true));
Admin Policy
sql
CREATE POLICY {table}_admin_all ON {table}
  FOR ALL TO {{PROJECT}}_app_user
  USING (current_setting('app.user_role', true) = 'admin');
System Policy (Background Jobs)
sql
CREATE POLICY {table}_system_all ON {table}
  FOR ALL TO {{PROJECT}}_app_user
  USING (current_setting('app.context_type', true) = 'system');

Migration Checklist

Before PR:

  • ARCHitect approval obtained
  • RLS policies in same migration file
  • User policies created
  • user_id index created
  • GRANT statements added
  • Local migration test passed
  • DATA_DICTIONARY.md updated
  • Evidence attached to ticket

Production Migration Requirements

For production migrations:

  • POPM/lead must be present (MANDATORY)
  • Backup taken before migration
  • Rollback plan documented
  • Post-migration validation steps defined
  • Data integrity checks planned

Authoritative References

  • Migration SOP: docs/database/RLS_DATABASE_MIGRATION_SOP.md (MANDATORY)
  • Data Dictionary: docs/database/DATA_DICTIONARY.md (update after changes)
  • RLS Implementation: docs/database/RLS_IMPLEMENTATION_GUIDE.md
  • RLS Policies: docs/database/RLS_POLICY_CATALOG.md
  • Security First: docs/guides/SECURITY_FIRST_ARCHITECTURE.md

© bybren-llc, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references, assets) in .agents/skills/migration-patterns of bybren-llc/safe-agentic-workflow.

  • SKILL.md
  • assets/.gitkeep
  • references/.gitkeep
  • scripts/.gitkeep

Open the folder on GitHubat commit 26ca58b

Compare with similar skills

Database Migration Patterns with RLS next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Database Migration Patterns with RLS compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Database Migration Patterns with RLS this skillbybren-llc/safe-agentic-workflow421—~1.3kAutomated safety check: PassMIT
Prisma 8 Contract-First ORMprisma/orm48k—~3.8kAutomated safety check: NotesApache-2.0
Database Migrationsaffaan-m/ECC275k4 repos~3kAutomated safety check: PassMIT
Database Migrationdavila7/claude-code-templates32k11 repos~2.8kAutomated safety check: PassMIT
Prisma CLIcurvenote/curvenote169—~1.6kAutomated safety check: PassMIT
Database Migrationsaffaan-m/ECC275k3 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Official

    Routes Prisma 8 tasks such as contracts, migrations, queries and upgrades to the right reference files for projects on the contract-first @prisma/orm packages.

    48k GitHub stars~3.8k tokensUpdated today
    DatabasesAuto-check: notes
  • Safe, reversible database migration patterns: forward-only production changes, expand-contract zero-downtime renames, concurrent indexes, batched backfills, and per-tool workflows for PostgreSQL…

    275k GitHub starsUsed in 4 repos~3k tokens
    DatabasesAuto-check passed
  • Database Migration

    davila7/claude-code-templates

    Master database schema and data migrations across ORMs (Sequelize, TypeORM, Prisma), including rollback strategies and zero-downtime deployments.

    32k GitHub starsUsed in 11 repos~2.8k tokens
    DatabasesAuto-check passed
  • Prisma CLI

    curvenote/curvenote

    Prisma CLI commands reference covering all available commands, options, and usage patterns.

    169 GitHub stars~1.6k tokensUpdated 9 days ago
    DatabasesAuto-check passed
  • 数据库迁移最佳实践,涵盖模式变更、数据迁移、回滚以及零停机部署,适用于PostgreSQL、MySQL及常用ORM(Prisma、Drizzle、Django、TypeORM、golang-migrate)。

    275k GitHub starsUsed in 3 repos~1.9k tokens
    DatabasesAuto-check passed
  • Şema değişiklikleri, veri migration'ları, rollback'ler ve PostgreSQL, MySQL ve yaygın ORM'ler (Prisma, Drizzle, Django, TypeORM, golang-migrate) arasında sıfır kesinti deployment'ları için…

    275k GitHub starsUsed in 1 repo~2.4k tokens
    DatabasesAuto-check passed

More from bybren-llc/safe-agentic-workflow

All 42 skills in this repo
  • Multi-Agent Coordination Template

    bybren-llc/safe-agentic-workflow

    Agent assignment matrix, blocker escalation, and TDM coordination patterns. Use when assigning work to specialist agents, managing blockers across agents…

    421 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • API Route Patterns

    bybren-llc/safe-agentic-workflow

    API route implementation patterns with RLS, validation, and error handling. Use when creating API routes, implementing CRUD endpoints, adding server-side…

    421 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Technical Documentation Templates

    bybren-llc/safe-agentic-workflow

    Documentation templates for ADRs, runbooks, architecture docs, and knowledge transfer documents. Use when creating Architecture Decision Records, writing…

    421 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Deployment SOP Checklist

    bybren-llc/safe-agentic-workflow

    Deployment workflows, pre-deploy validation, smoke testing, and rollback procedures. Use when deploying to staging or production, running smoke tests…

    421 GitHub stars~950 tokensUpdated 2 mo ago
    Auto-check passed
  • Frontend Patterns Template

    bybren-llc/safe-agentic-workflow

    Frontend patterns for modern web frameworks, component libraries, auth flows, and analytics. Use when building UI components, creating pages, implementing…

    421 GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Advanced Git Operations

    bybren-llc/safe-agentic-workflow

    Advanced git operations including rebase, bisect, cherry-pick, and conflict resolution. Use when rebasing feature branches, debugging with bisect…

    421 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Questions about Database Migration Patterns with RLS

How do I install Database Migration Patterns with RLS in Claude Code?

Run `npx skills add bybren-llc/safe-agentic-workflow --skill migration-patterns -a claude-code`. Or copy the skill folder (.agents/skills/migration-patterns in bybren-llc/safe-agentic-workflow) into .claude/skills/migration-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Database Migration Patterns with RLS in Codex?

Run `npx skills add bybren-llc/safe-agentic-workflow --skill migration-patterns -a codex`. Or copy the skill folder (.agents/skills/migration-patterns in bybren-llc/safe-agentic-workflow) into .agents/skills/migration-patterns in your project. Codex loads it when a task matches its description.

Can I use Database Migration Patterns with RLS in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bybren-llc/safe-agentic-workflow --skill migration-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/migration-patterns, .gemini/skills/migration-patterns, .github/skills/migration-patterns and .opencode/skills/migration-patterns in your project.

What does Database Migration Patterns with RLS need to run?

Going by SKILL.md and its folder, Database Migration Patterns with RLS needs the command-line tools its instructions call (npx and psql).

Does Database Migration Patterns with RLS access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Database Migration Patterns with RLS safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Database Migration Patterns with RLS use?

Database Migration Patterns with RLS is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Database Migration Patterns with RLS use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Database Migration Patterns with RLS?

Skills that share tags, products or a category with Database Migration Patterns with RLS: Prisma 8 Contract-First ORM (prisma/orm, 48k stars), Database Migrations (affaan-m/ECC, 275k stars), Database Migration (davila7/claude-code-templates, 32k stars) and Prisma CLI (curvenote/curvenote, 169 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Database Migration Patterns with RLS?

bybren-llc (a GitHub organization) maintains it in bybren-llc/safe-agentic-workflow, which has 421 GitHub stars. The repository holds 42 skills in this directory. The repository was last updated on July 20, 2026.

Source: bybren-llc/safe-agentic-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.