Agent skill

Implementing Database Audit Logging

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Process use when you need to track database changes for compliance and security monitoring.

MITAuto-check passedLegal & Compliance

Install Implementing Database Audit Logging

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill implementing-database-audit-logging -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace implementing-database-audit-logging --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/implementing-database-audit-logging .claude/skills/implementing-database-audit-logging && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-database-audit-logging
GitHub stars
2.8k
Token cost
~2.3k tokens
SKILL.md length
881 words
Files
8 (incl. scripts, references, assets)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Process use when you need to track database changes for compliance and security monitoring.

  • Works in 10 steps: Identify tables requiring audit logging… → Create the audit log table with… → Add indexes for common audit queries → …
  • You need to track database changes for compliance and security monitoring
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Runs Python and Shell scripts from its folder

What it does

Implementing Database Audit Logging is an agent skill from jeremylongshore/tons-of-skills-marketplace. Process use when you need to track database changes for compliance and security monitoring. This skill implements audit logging using triggers, application-level logging, CDC, or native logs. Trigger with phrases like "implement database audit logging", "add audit trails", "track database changes", or "monitor database activity for compliance".

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/README.md`, `references/README.md` and `scripts/README.md`). Compatibility notes: Designed for Claude Code

It sits in Legal & Compliance. It works with PostgreSQL. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • You need to track database changes for compliance and security monitoring
  • With phrases like implement database audit logging
  • Add audit trails
  • Track database changes

Example prompts

  • “implement database audit logging”
  • “add audit trails”
  • “track database changes”
  • “/implementing-database-audit-logging”

Requirements

  • Python 3
  • A Bash shell
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Glob, Bash(psql:*), Bash(mysql:*)

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Identify tables requiring audit logging based on compliance and business needs
  2. Create the audit log table with comprehensive metadata
  3. Add indexes for common audit queries
  4. Create the PostgreSQL audit trigger function
  5. Attach triggers to each audited table
  6. Pass application-level user context to the database session so audit logs capture the actual application user (not just the database role)
  7. Partition the audit_log table by month for efficient querying and archival
  8. Protect audit log integrity
  9. Create compliance report queries
  10. Set up audit log archival: move audit records older than the retention period to cold storage (S3, Azure Blob). Maintain the archive…

What it can do on your machine

Read from SKILL.md and the folder at commit 80f86df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Glob
    • Bash(psql:*)
    • Bash(mysql:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 5 files in scripts/ (Python and Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • postgresql.org
    • pgaudit.org
    • gdpr-info.eu

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Implementing Database Audit Logging loads about 2.3k tokens when it runs, and up to ~2.4k if it reads all its reference files. Until then it costs about 96 tokens; SKILL.md has 881 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit 80f86df, republished under its MIT licence (© jeremylongshore). 881 words, ~2,346 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-database-audit-logging/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
implementing-database-audit-logging
description
Process use when you need to track database changes for compliance and security monitoring. This skill implements audit logging using triggers, application-level logging, CDC, or native logs. Trigger with phrases like "implement database audit logging", "add audit trails", "track database changes", or "monitor database activity for compliance".
allowed-tools
Read, Write, Edit, Grep, Glob, Bash(psql:*), Bash(mysql:*)
compatibility
Designed for Claude Code
version
1.28.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
database, security, monitoring, logging

Database Audit Logger

Overview

Implement database audit logging to track all data modifications (INSERT, UPDATE, DELETE) with full before/after values, user identity, timestamps, and application context. This skill supports trigger-based auditing for PostgreSQL and MySQL, change data capture (CDC) patterns, and application-level audit logging.

Prerequisites

  • Database credentials with CREATE TABLE, CREATE FUNCTION, and CREATE TRIGGER permissions
  • psql or mysql CLI for executing audit setup DDL
  • Understanding of applicable compliance requirements (which tables, which operations, retention period)
  • Estimated storage for audit logs: plan for 10-30% of the audited table's data volume per year
  • Separate tablespace or storage volume for audit data to prevent audit growth from affecting application performance

Instructions

  1. Identify tables requiring audit logging based on compliance and business needs:

    • Tables containing PII (users, contacts, addresses) -- GDPR/HIPAA requirement
    • Tables containing financial data (transactions, payments, invoices) -- SOX/PCI-DSS requirement
    • Tables containing access control data (roles, permissions, API keys) -- security requirement
    • Determine which operations to audit per table: INSERT, UPDATE, DELETE, or all three
  2. Create the audit log table with comprehensive metadata:

    sql
    CREATE TABLE audit_log (
      id BIGSERIAL PRIMARY KEY,
      table_name VARCHAR(100) NOT NULL,
      record_id TEXT NOT NULL,
      action VARCHAR(10) NOT NULL CHECK (action IN ('INSERT', 'UPDATE', 'DELETE')),
      old_values JSONB,
      new_values JSONB,
      changed_columns TEXT[],
      changed_by VARCHAR(100),
      changed_at TIMESTAMPTZ NOT NULL DEFAULT NOW(),
      client_ip INET,
      application_name VARCHAR(100),
      transaction_id BIGINT
    );
  3. Add indexes for common audit queries:

    • CREATE INDEX idx_audit_table_record ON audit_log (table_name, record_id)
    • CREATE INDEX idx_audit_changed_at ON audit_log (changed_at)
    • CREATE INDEX idx_audit_changed_by ON audit_log (changed_by)
    • CREATE INDEX idx_audit_action ON audit_log (table_name, action)
  4. Create the PostgreSQL audit trigger function:

    sql
    CREATE OR REPLACE FUNCTION audit_trigger_func() RETURNS TRIGGER AS $$
    BEGIN
      IF TG_OP = 'INSERT' THEN
        INSERT INTO audit_log (table_name, record_id, action, new_values, changed_by, client_ip, application_name, transaction_id)
        VALUES (TG_TABLE_NAME, NEW.id::text, 'INSERT', to_jsonb(NEW), current_setting('app.user', true), inet_client_addr(), current_setting('application_name'), txid_current());
      ELSIF TG_OP = 'UPDATE' THEN
        INSERT INTO audit_log (table_name, record_id, action, old_values, new_values, changed_by, client_ip, application_name, transaction_id)
        VALUES (TG_TABLE_NAME, NEW.id::text, 'UPDATE', to_jsonb(OLD), to_jsonb(NEW), current_setting('app.user', true), inet_client_addr(), current_setting('application_name'), txid_current());
      ELSIF TG_OP = 'DELETE' THEN
        INSERT INTO audit_log (table_name, record_id, action, old_values, changed_by, client_ip, application_name, transaction_id)
        VALUES (TG_TABLE_NAME, OLD.id::text, 'DELETE', to_jsonb(OLD), current_setting('app.user', true), inet_client_addr(), current_setting('application_name'), txid_current());
      END IF;
      RETURN COALESCE(NEW, OLD);
    END;
    $$ LANGUAGE plpgsql;
  5. Attach triggers to each audited table:

    • CREATE TRIGGER audit_users AFTER INSERT OR UPDATE OR DELETE ON users FOR EACH ROW EXECUTE FUNCTION audit_trigger_func()
    • Repeat for each table requiring audit logging
  6. Pass application-level user context to the database session so audit logs capture the actual application user (not just the database role):

    • At the start of each request: SET LOCAL app.user = 'user@example.com'
    • For connection pools, set in the connection checkout hook
    • This value is captured by current_setting('app.user', true) in the trigger
  7. Partition the audit_log table by month for efficient querying and archival:

    • CREATE TABLE audit_log (...) PARTITION BY RANGE (changed_at)
    • Create monthly partitions: CREATE TABLE audit_log_2024_01 PARTITION OF audit_log FOR VALUES FROM ('2024-01-01') TO ('2024-02-01')
    • Automate partition creation for future months
  8. Protect audit log integrity:

    • Revoke UPDATE and DELETE permissions on audit_log from all application users
    • Grant only INSERT permission to the trigger execution context
    • Consider using pg_audit extension for additional tamper protection
    • Ship audit logs to an external system (SIEM, S3) for independent retention
  9. Create compliance report queries:

    • Change history for a record: SELECT * FROM audit_log WHERE table_name = 'users' AND record_id = '12345' ORDER BY changed_at
    • All changes by a user: SELECT * FROM audit_log WHERE changed_by = 'user@example.com' ORDER BY changed_at DESC
    • Bulk operations detection: SELECT changed_by, table_name, action, COUNT(*) FROM audit_log WHERE changed_at > NOW() - INTERVAL '1 hour' GROUP BY 1,2,3 HAVING COUNT(*) > 100
    • Off-hours activity: SELECT * FROM audit_log WHERE EXTRACT(HOUR FROM changed_at) NOT BETWEEN 8 AND 18
  10. Set up audit log archival: move audit records older than the retention period to cold storage (S3, Azure Blob). Maintain the archive manifest for retrieval. Typical retention: 1-3 years in database, 7+ years in cold storage for financial data.

Show full SKILL.md (390 more words)Show less

Output

  • Audit table DDL with proper columns, indexes, and partitioning
  • Audit trigger function capturing full before/after values with user context
  • Trigger attachment scripts for each audited table
  • Compliance report queries for common audit scenarios
  • Archival configuration for audit log lifecycle management

Error Handling

ErrorCauseSolution
Audit trigger slows INSERT/UPDATE operationsTrigger overhead on high-write tablesAudit only critical columns instead of full rows; use asynchronous audit with pg_notify and a listener process; batch audit writes
Audit table consuming excessive disk spaceHigh write volume tables generating millions of audit recordsPartition by month; archive old partitions to cold storage; audit only specific columns with WHEN clause on trigger
current_setting('app.user') returns NULLApplication not setting session variable before database operationsSet default in trigger: COALESCE(current_setting('app.user', true), current_user); add connection pool checkout hook
Audit log INSERT fails, blocking application operationAudit table full, permission error, or constraint violationUse BEGIN ... EXCEPTION WHEN OTHERS THEN NULL; END in trigger to prevent audit failures from blocking operations; alert on audit failures
Cannot determine which columns changed in UPDATEFull row stored as JSON, no column-level diffAdd changed_columns computation in trigger: compare OLD and NEW field by field; store only changed fields in new_values

Examples

HIPAA-compliant audit logging for a healthcare database: Audit triggers on patient_records, prescriptions, and lab_results tables capture all modifications with practitioner identity. Audit logs are immutable (no UPDATE/DELETE grants), partitioned monthly, and archived to encrypted S3 after 1 year. Quarterly compliance reports show access patterns per practitioner and flag unusual access (patient records accessed without an appointment).

Detecting unauthorized data modifications: Audit log query reveals 500 DELETE operations on the billing table by a service account at 3 AM, outside normal business hours. Alert triggers for bulk operations exceeding 100 rows. Investigation traces the operations to a misconfigured cleanup job. Audit log provides the complete list of deleted records for restoration.

GDPR data access request fulfillment: When a user requests their data access log under GDPR Article 15, the audit system provides a complete history of who accessed or modified their personal data: SELECT changed_by, action, changed_at, changed_columns FROM audit_log WHERE table_name = 'users' AND record_id = '12345' ORDER BY changed_at. The report is generated within the 30-day compliance window.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/.curated/implementing-database-audit-logging of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • assets/README.md
  • references/README.md
  • scripts/README.md
  • scripts/audit-archival.sh
  • scripts/audit_log_analyzer.py
  • scripts/audit_log_generator.py
  • scripts/audit_table_creator.py

Open the folder on GitHubat commit 80f86df

Compare with similar skills

Implementing Database Audit Logging next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Database Audit Logging compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Database Audit Logging this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.3kAutomated safety check: PassMIT
Payload Analyticstextura-agency/next16-claude-starter133—~1.4kAutomated safety check: PassUnlicense
Supabase Postgres Best Practicessupabase/agent-skills2.7k24 repos~808Automated safety check: PassMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Clickhouse Logs Queriessupabase/supabase111k—~2.4kAutomated safety check: PassApache-2.0
Senior Architect Toolkitmaslennikov-ig/claude-code-orchestrator-kit2608 repos~1.2kAutomated safety check: NotesCustom licence

Similar skills

  • Payload Analytics

    textura-agency/next16-claude-starter

    Light, consented, cookieless, self-hosted visitor analytics inside the Payload admin — a page-views collection in the CMS's own Postgres written by a same-origin /api/track beacon, an Analytics view…

    133 GitHub stars~1.4k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Official

    Gives the agent Postgres rules to consult before writing or changing tables, queries, indexes, RLS policies or migrations, and when diagnosing slow queries.

    2.7k GitHub starsUsed in 24 repos~808 tokens
    DatabasesAuto-check passed
  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Clickhouse Logs Queries

    supabase/supabase

    Official

    Write, review, and migrate Supabase logs queries against the ClickHouse-backed logs table (the logs.all.otel analytics endpoint).

    111k GitHub stars~2.4k tokensUpdated today
    DatabasesAuto-check passed
  • Senior Architect Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive software architecture skill for designing scalable, maintainable systems using ReactJS, NextJS, NodeJS, Express, React Native, Swift, Kotlin…

    260 GitHub starsUsed in 8 repos~1.2k tokens
    DevelopmentAuto-check: notes
  • cmux Backend Rules

    manaflow-ai/cmux

    Sets the backend TypeScript and Cloud VM rules for cmux: Effect-based services, thin route handlers, Postgres as source of truth, migrations and provider secrets.

    28k GitHub starsUsed in 1 repo~682 tokens
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Implementing Database Audit Logging

What does Implementing Database Audit Logging do?

Process use when you need to track database changes for compliance and security monitoring. Implementing Database Audit Logging is an agent skill from jeremylongshore/tons-of-skills-marketplace. Process use when you need to track database changes for compliance and security monitoring.

When should I use Implementing Database Audit Logging?

Implementing Database Audit Logging fits situations like: you need to track database changes for compliance and security monitoring; with phrases like implement database audit logging; add audit trails; track database changes.

How do I install Implementing Database Audit Logging in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill implementing-database-audit-logging -a claude-code`. Or copy the skill folder (skills/.curated/implementing-database-audit-logging in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/implementing-database-audit-logging in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Database Audit Logging in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill implementing-database-audit-logging -a codex`. Or copy the skill folder (skills/.curated/implementing-database-audit-logging in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/implementing-database-audit-logging in your project. Codex loads it when a task matches its description.

Can I use Implementing Database Audit Logging in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill implementing-database-audit-logging -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-database-audit-logging, .gemini/skills/implementing-database-audit-logging, .github/skills/implementing-database-audit-logging and .opencode/skills/implementing-database-audit-logging in your project.

What does Implementing Database Audit Logging need to run?

Going by SKILL.md and its folder, Implementing Database Audit Logging needs Python and a shell for the scripts in its folder. Our summary lists: Python 3; A Bash shell. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(psql:*), Bash(mysql:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Implementing Database Audit Logging access the network?

SKILL.md names 3 domains. As links in the text: postgresql.org, pgaudit.org and gdpr-info.eu. This is read from the text; nothing was executed.

Is Implementing Database Audit Logging safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Database Audit Logging use?

Implementing Database Audit Logging is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Database Audit Logging use?

About 2.3k tokens (SKILL.md is roughly 9.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16 tokens, read only when the agent opens those files.

What are the alternatives to Implementing Database Audit Logging?

Skills that share tags, products or a category with Implementing Database Audit Logging: Payload Analytics (textura-agency/next16-claude-starter, 133 stars), Supabase Postgres Best Practices (supabase/agent-skills, 2.7k stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars) and Clickhouse Logs Queries (supabase/supabase, 111k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Database Audit Logging?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,825 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 9, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.