Agent skill

Create Readonly DB Role

by davidondrej in davidondrej/skills

Set up read-only PostgreSQL access for agents. An agent skill from davidondrej/skills.

MITAuto-check passedDatabases

Install Create Readonly DB Role

skills CLI
$ npx skills add davidondrej/skills --skill create-readonly-db-role -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install davidondrej/skills create-readonly-db-role --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/davidondrej/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ops-and-setup/create-readonly-db-role .claude/skills/create-readonly-db-role && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
create-readonly-db-role
GitHub stars
4.1k
Token cost
~1.3k tokens
SKILL.md length
448 words
Files
2
Skills in repo
51
Repo updated
First seen
Licence
MIT

At a glance

Set up read-only PostgreSQL access for agents. An agent skill from davidondrej/skills.

  • Works in 3 steps: SELECT-only grants. Grant no write… → Current and future tables. Grant SELECT… → Soft guardrails. Set…
  • Explicitly invokes /create-readonly-db-role
  • SKILL.md covers Access model, Workflow, SQL template and Verification, plus 1 more section
  • Calls psql

What it does

Create Readonly DB Role is an agent skill from davidondrej/skills. Set up read-only PostgreSQL access for agents. Use only when the user explicitly invokes /create-readonly-db-role.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Databases. It works with PostgreSQL and SQL. The repository describes itself as: access to david ondrej's personal agent skills. The licence is MIT.

When your agent uses it

  • Explicitly invokes /create-readonly-db-role

Example prompts

  • “/create-readonly-db-role”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. SELECT-only grants. Grant no write permissions; use a denylist to exclude secrets and PII.
  2. Current and future tables. Grant SELECT on all tables in , including future tables through default privileges, then revoke denylisted…
  3. Soft guardrails. Set default_transaction_read_only = on and a short statement_timeout suited to the workload.

What it can do on your machine

Read from SKILL.md and the folder at commit 7874889. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • psql

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Create Readonly DB Role loads about 1.3k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 448 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from davidondrej/skills at commit 7874889, republished under its MIT licence (© davidondrej). 448 words, ~1,334 tokens.

Download SKILL.mdSave it as .claude/skills/create-readonly-db-role/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
create-readonly-db-role
description
Set up read-only PostgreSQL access for agents. Use only when the user explicitly invokes /create-readonly-db-role.
disable-model-invocation
true

Create a Read-Only DB Role for Agents

Prepare a SELECT-only role and protected connection. The SQL, role name, grants, denylist, RLS behavior, timeouts, and connection steps are examples to adapt to your system, not live production configuration.

Access model

  1. SELECT-only grants. Grant no write permissions; use a denylist to exclude secrets and PII.
  2. Current and future tables. Grant SELECT on all tables in <application_schema>, including future tables through default privileges, then revoke denylisted tables. Never grant the <restricted_schema> schema. New sensitive tables need a manual revoke.
  3. Soft guardrails. Set default_transaction_read_only = on and a short statement_timeout suited to the workload.

RLS: tables may return no rows when the role has no applicable policy. Review row-level policies with the database administrator to ensure the role sees only the intended rows.

Workflow

  1. Check the role: select rolname from pg_roles where rolname = '<reader_role>';. Use your chosen name; if it exists, update rather than recreate it.
  2. Agree on the denylist with the human. Identify secret or PII tables agents must never see, such as tables containing credentials, webhook payloads, and identity data.
  3. Save SQL in the repo, e.g. docs/<setup-file>.sql. Comment what changes, why, and how to apply, verify, and revert. Chat-only SQL is insufficient.
  4. The human applies it. Agents never run production DDL. In Supabase, paste the file into the SQL editor, then delete the query from its history because it contains the password. The human stores the password in a password manager.
  5. Wire the connection through a protected secret manager or local environment configuration; never commit it. Supabase session poolers typically use <role>.<project-ref> on port 5432. Install psql if missing (Homebrew libpq on macOS).
  6. Run every verification check below.
  7. Create a project-local usage skill covering key tables, query patterns, read-only access, and never pasting PII into commits or docs.
Show full SKILL.md (143 more words)Show less

SQL template

sql
-- Example only. Rename the role, schema, timeout, and denylist for your system.

-- 1. role + soft guardrails
create role <reader_role> with login password 'REPLACE_ME';
alter role <reader_role> set default_transaction_read_only = on;
alter role <reader_role> set statement_timeout = '10s';  -- example timeout; change as needed

-- 2. SELECT-only grants, denylist model
grant usage on schema <application_schema> to <reader_role>;
grant select on all tables in schema <application_schema> to <reader_role>;
alter default privileges for role <owner_role> in schema <application_schema>
  grant select on tables to <reader_role>;   -- future tables auto-readable

-- 3. denylist: keep secrets and PII invisible (replace with your own tables)
revoke select on table <application_schema>.<sensitive_table_1> from <reader_role>;
revoke select on table <application_schema>.<sensitive_table_2> from <reader_role>;

Revert: drop owned by <reader_role>; drop role <reader_role>;

Verification

All checks must pass before declaring done:

bash
# Load the connection URL from your secret manager or local environment configuration.
psql "<readonly-connection-url>" -X -c "select current_user;"                      # -> <reader_role>
psql "<readonly-connection-url>" -X -c "show statement_timeout;"                   # -> matches your chosen timeout
psql "<readonly-connection-url>" -X -c "select count(*) from <application_schema>.<readable_table>;"  # -> real number, NOT 0
psql "<readonly-connection-url>" -X -c "delete from <application_schema>.<any_table> where false;"
# -> ERROR: read-only transaction (soft guardrail)
psql "<readonly-connection-url>" -X -c "begin; set transaction read write; delete from <application_schema>.<any_table> where false; rollback;"
# -> ERROR: permission denied (the hard wall)
psql "<readonly-connection-url>" -X -c "select * from <application_schema>.<denylisted_table> limit 1;"  # -> ERROR: permission denied
psql "<readonly-connection-url>" -X -c "select * from <restricted_schema>.<identity_table> limit 1;"    # -> ERROR: permission denied

Verify both protections: writes fail under the read-only guardrail, and fail with permission denied when it is off. If any check fails, correct the configuration through the human and rerun all checks.

Troubleshooting and maintenance

  • No rows across tables: check RLS policies and consult the database administrator.
  • Write verification succeeds: stop. Have the human revoke the role's privileges and correct the setup, then rerun all checks.
  • Supabase authentication fails: check the pooler username, usually <role>.<project-ref>.
  • Legitimate query times out: add filters or limits before raising the timeout.
  • New sensitive table: add revoke select to the denylist.
  • Password rotation: have the human run alter role <reader_role> with password '...' and update the stored connection secret.
  • Never allow agents to write through this role. Production writes remain human-only.

© davidondrej, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/ops-and-setup/create-readonly-db-role of davidondrej/skills.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 7874889

Compare with similar skills

Create Readonly DB Role next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Create Readonly DB Role compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Create Readonly DB Role this skilldavidondrej/skills4.1k—~1.3kAutomated safety check: PassMIT
Clickhouse Logs Queriessupabase/supabase111k—~2.4kAutomated safety check: PassApache-2.0
Citus Check Style Reindentcitusdata/citus13k—~1.5kAutomated safety check: NotesAGPL-3.0
Safe SQL Executionsupabase/supabase111k—~4.2kAutomated safety check: PassApache-2.0
Citus Backportcitusdata/citus13k—~3.2kAutomated safety check: PassAGPL-3.0
SQL Database Support for pRESTprest/prest4.6k—~1.6kAutomated safety check: PassMIT

Similar skills

  • Clickhouse Logs Queries

    supabase/supabase

    Official

    Write, review, and migrate Supabase logs queries against the ClickHouse-backed logs table (the logs.all.otel analytics endpoint).

    111k GitHub stars~2.4k tokensUpdated today
    DatabasesAuto-check passed
  • Fix a failing citusdata/citus check-style job by running make reindent with the exact uncrustify/citusindent versions the currently checked-out branch pins (read from its own STYLEGUIDE.md and its…

    13k GitHub stars~1.5k tokensUpdated yesterday
    DatabasesAuto-check: notes
  • Safe SQL Execution

    supabase/supabase

    Official

    A skill your agent uses whenever code will build, return, fetch, or execute SQL that runs against a user's real Postgres database — even when the request reads like an ordinary feature or bug fix…

    111k GitHub stars~4.2k tokensUpdated today
    DatabasesAuto-check passed
  • Citus Backport

    citusdata/citus

    Backport one or more merged citusdata/citus main commits/PRs onto the active release branches.

    13k GitHub stars~3.2k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Guides classifying, gap-analyzing and scaffolding support for a new SQL database in pREST, from Postgres-compatible variants to entirely new dialects.

    4.6k GitHub stars~1.6k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Chdb SQL

    vemetric/vemetric

    A skill your agent uses when the user wants to run SQL — especially analytical SQL — on local files (parquet/csv/json), URLs, S3 paths, or remote databases (Postgres, MySQL, MongoDB, ClickHouse…

    395 GitHub starsUsed in 1 repo~1.2k tokens
    DatabasesAuto-check passed

More from davidondrej/skills

All 51 skills in this repo
  • Nagent

    davidondrej/skills

    Launch a new bb worker thread with the right project, model, worktree, and task brief.

    4.1k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check: notes
  • Browser Harness

    davidondrej/skills

    Direct browser control via CDP. An agent skill from davidondrej/skills.

    4.1k GitHub starsUsed in 2 repos~3k tokens
    Auto-check passed
  • Persistent Localhost

    davidondrej/skills

    Manage persistent dev servers, APIs, and other local processes on a port using macOS LaunchAgents.

    4.1k GitHub stars~618 tokensUpdated yesterday
    Auto-check passed
  • Reset Cursor Acp

    davidondrej/skills

    Reset a stuck Cursor ACP thread in <chat-system and reload its configuration.

    4.1k GitHub stars~728 tokensUpdated yesterday
    Auto-check passed
  • Anti Sleep

    davidondrej/skills

    Keep a Mac awake for a set duration or while a process runs.

    4.1k GitHub stars~640 tokensUpdated yesterday
    Auto-check: warnings
  • Bb CLI

    davidondrej/skills

    Use this when controlling bb. An agent skill from davidondrej/skills.

    4.1k GitHub stars~823 tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Create Readonly DB Role

What does Create Readonly DB Role do?

Set up read-only PostgreSQL access for agents. An agent skill from davidondrej/skills. Create Readonly DB Role is an agent skill from davidondrej/skills. Set up read-only PostgreSQL access for agents.

When should I use Create Readonly DB Role?

Create Readonly DB Role fits situations like: explicitly invokes /create-readonly-db-role.

How do I install Create Readonly DB Role in Claude Code?

Run `npx skills add davidondrej/skills --skill create-readonly-db-role -a claude-code`. Or copy the skill folder (skills/ops-and-setup/create-readonly-db-role in davidondrej/skills) into .claude/skills/create-readonly-db-role in your project. Claude Code loads it when a task matches its description.

How do I install Create Readonly DB Role in Codex?

Run `npx skills add davidondrej/skills --skill create-readonly-db-role -a codex`. Or copy the skill folder (skills/ops-and-setup/create-readonly-db-role in davidondrej/skills) into .agents/skills/create-readonly-db-role in your project. Codex loads it when a task matches its description.

Can I use Create Readonly DB Role in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davidondrej/skills --skill create-readonly-db-role -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/create-readonly-db-role, .gemini/skills/create-readonly-db-role, .github/skills/create-readonly-db-role and .opencode/skills/create-readonly-db-role in your project.

What does Create Readonly DB Role need to run?

Going by SKILL.md and its folder, Create Readonly DB Role needs the command-line tools its instructions call (psql).

Does Create Readonly DB Role access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Create Readonly DB Role safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Create Readonly DB Role use?

Create Readonly DB Role is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Create Readonly DB Role use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Create Readonly DB Role?

Skills that share tags, products or a category with Create Readonly DB Role: Clickhouse Logs Queries (supabase/supabase, 111k stars), Citus Check Style Reindent (citusdata/citus, 13k stars), Safe SQL Execution (supabase/supabase, 111k stars) and Citus Backport (citusdata/citus, 13k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Create Readonly DB Role?

davidondrej (a GitHub user) maintains it in davidondrej/skills, which has 4,112 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 8, 2026.

Source: davidondrej/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.