Agent skill

Dynamodb

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when modeling or operating a DynamoDB table: deriving partition/sort keys from access patterns, single-table vs table-per-entity, adding a GSI/LSI, on-demand vs provisioned…

MITAuto-check passedDatabases

Install Dynamodb

skills CLI
$ npx skills add ericrisco/rsc-harness --skill dynamodb -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness dynamodb --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dynamodb .claude/skills/dynamodb && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dynamodb
GitHub stars
156
Token cost
~3k tokens
SKILL.md length
1,563 words
Files
6 (incl. scripts, references)
Skills in repo
229
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when modeling or operating a DynamoDB table: deriving partition/sort keys from access patterns, single-table vs table-per-entity, adding a GSI/LSI, on-demand vs provisioned…

  • Works in 5 steps: Enumerate access patterns → Key design + single-table decision → GSIs (only when the base table can't… → …
  • Operating a DynamoDB table: deriving partition/sort keys from access patterns
  • SKILL.md covers What you produce / what you…, Step 1 — Enumerate access…, Step 2 — Key design +… and Step 3 — GSIs (only when the…, plus 4 more sections
  • Runs Shell scripts from its folder; calls aws; needs LAST_EVALUATED_KEY

What it does

Dynamodb is an agent skill from ericrisco/rsc-harness. Use when modeling or operating a DynamoDB table: deriving partition/sort keys from access patterns, single-table vs table-per-entity, adding a GSI/LSI, on-demand vs provisioned capacity, or diagnosing hot-partition throttling. NOT relational schema/SQL/EXPLAIN (that is postgresdb), NOT aggregation-pipeline document modeling (that is mongodb).

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/access-patterns.md`).

It sits in Databases, covering NoSQL databases. It works with Amazon DynamoDB, SQL and MongoDB. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Operating a DynamoDB table: deriving partition/sort keys from access patterns
  • Single-table vs table-per-entity
  • Adding a GSI/LSI
  • On-demand vs provisioned capacity

Example prompts

  • “/dynamodb”

Requirements

  • A Bash shell
  • A credential in LAST_EVALUATED_KEY

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Enumerate access patterns
  2. Key design + single-table decision
  3. GSIs (only when the base table can't serve it)
  4. Capacity & cost
  5. Operational guardrails

What it can do on your machine

Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • LAST_EVALUATED_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dynamodb loads about 3k tokens when it runs, and up to ~5.3k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 1,563 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,563 words, ~3,033 tokens.

Download SKILL.mdSave it as .claude/skills/dynamodb/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
dynamodb
description
Use when modeling or operating a DynamoDB table: deriving partition/sort keys from access patterns, single-table vs table-per-entity, adding a GSI/LSI, on-demand vs provisioned capacity, or diagnosing hot-partition throttling. NOT relational schema/SQL/EXPLAIN (that is `postgresdb`), NOT aggregation-pipeline document modeling (that is `mongodb`).
tags
dynamodb, nosql, single-table-design, aws, data-modeling
recommends
postgresdb, mongodb, redis, vector-db, aws-essentials, deployment, secure-coding
origin
risco

DynamoDB — access-pattern-first modeling and capacity

DynamoDB is not a relational database with a different syntax. It has no joins, no ad-hoc queries, no server-side aggregation, and it punishes schema changes after launch. So the modeling discipline IS the work: enumerate every read and write the app must perform, THEN design keys so each one is a single GetItem or Query. Add an index only when the base table physically cannot serve a pattern. Decide capacity last.

Your job here is to stop the user from treating DynamoDB like SQL.

What you produce / what you refuse

You deliver three artifacts, in this order:

  1. An access-pattern list — a table of every query and write, with key condition, read/write, frequency, and what serves it. This is the contract the keys must satisfy.
  2. A key-design document — entity → PK/SK encoding → which table or named GSI serves each pattern.
  3. A capacity + cost recommendation — on-demand vs provisioned vs reserved, and the hot-partition risk.

You refuse to: click through the AWS console, wire the IaC/CI provisioning pipeline (that is ../deployment/SKILL.md), or model the data as normalized tables you then "join" in application code. You emit DDL, IaC snippets, and example SDK calls — you do not provision the infrastructure.

The steps below run in sequence — access patterns, then keys, then indexes, then capacity. Reordering them is the single most common DynamoDB mistake.

Step 1 — Enumerate access patterns

You cannot query what your keys do not express, and there is no WHERE over arbitrary columns, so produce this table before you name a single attribute. It is also exactly what scripts/verify.sh checks: run scripts/verify.sh <path-to-key-design.{md,json}> and every row must carry a key target (pk/sk or a named gsi) and a query_type. It FAILS on any pattern served by Scan, WARNS on FilterExpression, and asserts ≤20 GSIs / ≤5 LSIs. Read-only; exits 0 on an empty or clean target.

patternentitykey conditionread/writeest. freqserved by
Get a user by idUserPK=USER#<id>readhighbase table GetItem
Get a user's orders, newest firstOrderPK=USER#<id>, SK begins_with ORDER#readhighbase table Query
Look up a user by emailUserGSI1PK=EMAIL#<email>readmediumGSI1 Query
List open orders across all usersOrdersparse GSI2PK=OPENreadlowGSI2 (sparse) Query

Bad → Good. The whole game is moving from vague to executable:

  • Bad: "store users and orders." (No key condition is derivable from this.)
  • Good: "get all orders for a user, newest first, page size 25." (PK + SK range + sort direction fall out.)

Rule: if a pattern needs a FilterExpression over more than ~10% of the items it scans, that is a modeling smell — redesign the key, do not patch it with a filter.

Step 2 — Key design + single-table decision

Get this wrong and you pay for it forever: changing a table's key schema after launch means a full migration (new table + backfill + dual-write).

Composite-key encoding. Use prefixed, sortable strings so one partition holds an entity and its children — items read together are co-located, so one Query returns them — and so a sort-key range query slices them:

text
PK = USER#123
SK = USER#123                      <- the user item itself
SK = ORDER#2026-06-02T10:15#A91    <- an order, ISO-8601 timestamp sorts lexically = chronologically
SK = ORDER#2026-06-02T11:40#B07
json
{ "PK": "USER#123", "SK": "ORDER#2026-06-02T10:15#A91",
  "Type": "Order", "Total": 4200, "Status": "OPEN" }

One Query with PK = USER#123 AND SK begins_with("ORDER#") returns all of that user's orders, already sorted. That is a one-to-many relationship with no join.

Many-to-many uses an adjacency list: store the edge twice (or use an inverted GSI, see Step 3) so you can traverse it from either side. Worked end-to-end in references/access-patterns.md — a multi-tenant SaaS / e-commerce model (pattern table → PK/SK map → GSI map → AWS SDK v3 @aws-sdk/lib-dynamodb calls), adjacency-list many-to-many, time-series and leaderboard patterns.

Single-table vs table-per-entity — decide honestly, do not cargo-cult:

signalsingle-tabletable-per-entity
Many entities read together in one requestyesno
Many access patterns over related entitiesyesno
Entities are independent, patterns are few/simplenoyes (simpler, fine)
Team unfamiliar with overloaded keysweigh the costyes
Need clean per-entity IAM / TTL / capacity isolationnoyes

Single-table design earns its complexity when many related entities share access patterns. When entities are independent and the queries are few, separate tables are simpler and perfectly correct — say so.

Step 3 — GSIs (only when the base table can't serve it)

Three named patterns, each with a one-line why:

  • Inverted index — swap PK and SK on the GSI so you can read the relationship from the other side (GSI1PK = SK_value, GSI1SK = PK_value). Serves "given an order, who owns it" / many-to-many reverse.
  • Sparse index — only items that carry the GSI's key attribute are indexed. Write the attribute only on the few items you want to find ("OPEN" orders, flagged accounts) so the index is tiny and the query is "find the few" instead of "scan the many."
  • Overloaded GSI — reuse generic GSI1PK/GSI1SK attributes across multiple entity types so one index serves several patterns. Keeps you under the index quota.

Rule: add a GSI only when the base table physically cannot answer the pattern. Every GSI is a standing cost.

Warnings that bite people:

  • GSIs are always eventually consistent — you cannot read-your-own-write through a GSI. If a pattern needs strong consistency, it must hit the base table.
  • Each write to the base table replicates to every GSI whose keys changed, each consuming its own write capacity. More indexes = multiplied write cost.
  • Project only the attributes each pattern needs. Blanket ProjectionType: ALL doubles storage and write cost; use KEYS_ONLY or INCLUDE when you can.

Quotas (default, adjustable for GSIs): up to 20 GSIs and 5 LSIs per table. LSIs must be defined at table creation, share the base partition key, and impose a 10 GB item-collection cap (all items under one partition key). GSI-only tables have no such cap — a real reason to prefer GSIs over LSIs.

Show full SKILL.md (629 more words)Show less

Step 4 — Capacity & cost

Capacity mode is a billing decision, not a modeling one — it changes nothing about the keys, so pick it after the model is stable. Decision table:

traffic shaperecommendationwhy
Spiky / unpredictable, or < ~10M req/monthOn-demand (the AWS default)Nov-2024 ~50% price cut made it cheapest for most workloads; no capacity planning
Sustained utilization > ~40%Provisioned + auto-scalingprovisioned writes (~$0.047/M) are far cheaper than on-demand at high utilization
Predictable, long-running, > ~70% utilProvisioned + reserved capacity3-year reserved (~$0.013/M write) is dramatically cheaper still

On-demand request unit pricing (us-east-1, standard table class): RRU $0.125 / million, WRU $0.625 / million. Warm throughput (the instantaneous read/write a table can serve) is shown by default at no cost and rises automatically as you scale; you pay only if you proactively pre-warm ahead of a known spike.

Hot partitions. Each physical partition has a hard ceiling of 3,000 RCU and 1,000 WCU per second, regardless of the table's total capacity. Drive one partition key past that and you are throttled even while well under your table limit — this is why "writes throttled but I'm under capacity" means a hot key. Fix with high-cardinality keys or write-sharding: append a suffix bucket to the PK.

text
# Hot: every write lands on one partition
PK = METRIC#daily_total

# Sharded: spread writes across N buckets, scatter-gather on read
PK = METRIC#daily_total#<0..9>

Capacity math, full pricing detail (including the Nov-2024 cut), warm throughput, the full quota table, and hot-partition diagnosis + the sharding recipe live in references/capacity-and-limits.md.

Step 5 — Operational guardrails

  • Item size is hard-capped at 400 KB (attribute names + values). Offload large blobs to S3 and store the S3 key in the item.
  • Query/Scan return at most 1 MB per request. That is why a Query "only returns some rows" — loop on LastEvaluatedKey until it is absent.
bash
aws dynamodb query --table-name App \
  --key-condition-expression 'PK = :pk' \
  --expression-attribute-values '{":pk":{"S":"USER#123"}}' \
  --starting-token "$LAST_EVALUATED_KEY"   # paginate; absent => done
  • TransactWriteItems / TransactGetItems group up to 100 unique items; a transactional write consumes 2× WCU.
  • BatchWriteItem takes up to 25 put/delete requests per call.
  • FilterExpression runs AFTER the read consumes capacity — it saves bandwidth, not RCU. Never use a filter as a substitute for a key condition.
  • TTL for automatic expiry (set an epoch-seconds attribute); deletion is best-effort, not instant.
  • DynamoDB Streams for change capture / building derived & denormalized views.

Anti-patterns

Anti-patternWhy it failsDo instead
Designing keys before listing access patternsThe keys won't express the queries; post-launch fix is a full migrationList every read/write first; derive keys from them
Scan + FilterExpression as your "query"Scan reads (and bills) the whole table; the filter only trims the responseMake the pattern a Query on a key or GSI
One GSI per attribute "just in case"Each GSI multiplies write cost and counts against the 20-GSI quotaAdd a GSI only when the base table can't serve a real pattern
Normalizing into separate tables joined in app codeDynamoDB has no joins; app-side joins are N round-trips and racesCo-locate related items under one PK; query once
Low-cardinality PK (e.g. status, tenant)All traffic funnels to one partition → throttling at 3000 RCU / 1000 WCUHigh-cardinality PK; write-shard hot keys
Expecting strong consistency from a GSIGSIs are always eventually consistent — stale readsRead consistency-critical patterns from the base table
ProjectionType: ALL on every GSIDoubles storage and write cost on each indexed writeProject KEYS_ONLY / INCLUDE only what the pattern needs
Storing > 400 KB inline (images, docs, logs)Hits the 400 KB item cap; bloats every readPut the blob in S3, store the pointer in the item
Picking capacity mode before the model is doneMode is billing, not modeling — premature and often wrongStabilize keys/GSIs first, then choose on-demand vs provisioned

Route elsewhere when the engine is different

Relational schema / SQL / EXPLAIN / indexing → ../postgresdb/SKILL.md; MySQL-engine schema → mysql; document modeling + aggregation pipeline → mongodb; cache / queue / rate-limiter → redis; vector store / semantic search → vector-db; AWS account / IAM / VPC setup → aws-essentials; provisioning the table in CI/CD → ../deployment/SKILL.md; API-layer auth/secrets in front of the table → ../secure-coding/SKILL.md.

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/dynamodb of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/access-patterns.md
  • references/capacity-and-limits.md
  • scripts/verify.sh

Open the folder on GitHubat commit 92fde8f

Compare with similar skills

Dynamodb next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dynamodb compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dynamodb this skillericrisco/rsc-harness156—~3kAutomated safety check: PassMIT
DB SculptorEliasOulkadi/shokunin114—~3.1kAutomated safety check: NotesMIT
Rhctlsaidake/rhctl106—~4kAutomated safety check: NotesApache-2.0
Database FundamentalsDanielPodolsky/ownyourcode2901 repos~1.6kAutomated safety check: PassMIT
Mongodb Schema Designmongodb/agent-skills1902 repos~3.4kAutomated safety check: PassApache-2.0
Mongodb Natural Language Queryingmongodb/agent-skills1901 repos~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • DB Sculptor

    EliasOulkadi/shokunin

    Design database schemas with Prisma/Drizzle, PostgreSQL index strategy (B-tree, GIN, GiST, BRIN, Hash), query optimization (EXPLAIN ANALYZE), migration safety (expand/contract, zero-downtime), and…

    114 GitHub stars~3.1k tokensUpdated 2 days ago
    DatabasesAuto-check: notes
  • Rhctl

    saidake/rhctl

    Run and author rhctl CLI workflows and remote environment scripts under scripts/ (PostgreSQL, JetStream, Docker, Redis, MongoDB, AWS LocalStack, execute/upload/patch).

    106 GitHub stars~4k tokensUpdated yesterday
    DatabasesAuto-check: notes
  • Database Fundamentals

    DanielPodolsky/ownyourcode

    Reviews schema design, SQL queries, ORM patterns. An agent skill from DanielPodolsky/ownyourcode.

    290 GitHub starsUsed in 1 repo~1.6k tokens
    DatabasesAuto-check passed
  • Mongodb Schema Design

    mongodb/agent-skills

    Official

    MongoDB schema design patterns and anti-patterns. An agent skill from mongodb/agent-skills.

    190 GitHub starsUsed in 2 repos~3.4k tokens
    DatabasesAuto-check passed
  • Official

    Generate read-only MongoDB queries (find) or aggregation pipelines using natural language, with collection schema context and sample documents.

    190 GitHub starsUsed in 1 repo~2.4k tokens
    DatabasesAuto-check passed
  • Discover Database

    rand/cc-polymath

    Automatically discover database skills when working with SQL, PostgreSQL, MongoDB, Redis, database schema design, query optimization, migrations, connection pooling, ORMs, or database selection.

    181 GitHub stars~2k tokensUpdated 7 mo ago
    DatabasesAuto-check passed

More from ericrisco/rsc-harness

All 229 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    156 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    156 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    156 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    156 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    156 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    156 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Categories

Questions about Dynamodb

What does Dynamodb do?

A skill your agent uses when modeling or operating a DynamoDB table: deriving partition/sort keys from access patterns, single-table vs table-per-entity, adding a GSI/LSI, on-demand vs provisioned…. Dynamodb is an agent skill from ericrisco/rsc-harness. Use when modeling or operating a DynamoDB table: deriving partition/sort keys from access patterns, single-table vs table-per-entity, adding a GSI/LSI, on-demand vs provisioned capacity, or diagnosing hot-partition throttling.

When should I use Dynamodb?

Dynamodb fits situations like: operating a DynamoDB table: deriving partition/sort keys from access patterns; single-table vs table-per-entity; adding a GSI/LSI; on-demand vs provisioned capacity.

How do I install Dynamodb in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill dynamodb -a claude-code`. Or copy the skill folder (skills/dynamodb in ericrisco/rsc-harness) into .claude/skills/dynamodb in your project. Claude Code loads it when a task matches its description.

How do I install Dynamodb in Codex?

Run `npx skills add ericrisco/rsc-harness --skill dynamodb -a codex`. Or copy the skill folder (skills/dynamodb in ericrisco/rsc-harness) into .agents/skills/dynamodb in your project. Codex loads it when a task matches its description.

Can I use Dynamodb in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill dynamodb -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dynamodb, .gemini/skills/dynamodb, .github/skills/dynamodb and .opencode/skills/dynamodb in your project.

What does Dynamodb need to run?

Going by SKILL.md and its folder, Dynamodb needs a shell for the scripts in its folder, the command-line tools its instructions call (aws) and credentials named LAST_EVALUATED_KEY. Our summary lists: A Bash shell; A credential in LAST_EVALUATED_KEY.

Does Dynamodb access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dynamodb safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Dynamodb use?

Dynamodb is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dynamodb use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Dynamodb?

Skills that share tags, products or a category with Dynamodb: DB Sculptor (EliasOulkadi/shokunin, 114 stars), Rhctl (saidake/rhctl, 106 stars), Database Fundamentals (DanielPodolsky/ownyourcode, 290 stars) and Mongodb Schema Design (mongodb/agent-skills, 190 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dynamodb?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.