Agent skill

Migration Risk Analyzer

by Mathews-Tom in Mathews-Tom/armory

Analyzes database migration scripts for lock contention, downtime, rollback strategy, and deployment risk.

MITAuto-check passedDatabases

Install Migration Risk Analyzer

skills CLI
$ npx skills add Mathews-Tom/armory --skill migration-risk-analyzer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Mathews-Tom/armory migration-risk-analyzer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Mathews-Tom/armory.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/migration-risk-analyzer .claude/skills/migration-risk-analyzer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
migration-risk-analyzer
GitHub stars
328
Token cost
~2.5k tokens
SKILL.md length
429 words
Files
6 (incl. references)
Skills in repo
80
Repo updated
First seen
Licence
MIT

At a glance

Analyzes database migration scripts for lock contention, downtime, rollback strategy, and deployment risk.

  • Works in 5 steps: Parse Migration → Assess Lock Risk → Estimate Duration → …
  • : analyze this migration
  • SKILL.md covers Reference Files, Prerequisites, Workflow and Output Format
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Migration Risk Analyzer is an agent skill from Mathews-Tom/armory. Analyzes database migration scripts for lock contention, downtime, rollback strategy, and deployment risk. Triggers on: "analyze this migration", "migration risk", "is this migration safe", "schema change risk", "DDL risk", "rollback strategy", "migration review".

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `evals/cases.yaml`, `references/lock-matrix.md` and `references/rollback-templates.md`).

It sits in Databases, covering Database migrations and Deployment. The repository describes itself as: Curated, production-grade skills for AI coding agents. Battle-tested workflows for developers who use AI seriously. The licence is MIT.

When your agent uses it

  • : analyze this migration
  • Is this migration safe
  • Schema change risk
  • Rollback strategy

Example prompts

  • “analyze this migration”
  • “migration risk”
  • “is this migration safe”
  • “/migration-risk-analyzer”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Parse Migration
  2. Assess Lock Risk
  3. Estimate Duration
  4. Design Rollback
  5. Generate Report

What it can do on your machine

Read from SKILL.md and the folder at commit 4594fb7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are sql).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Migration Risk Analyzer loads about 2.5k tokens when it runs, and up to ~7.9k if it reads all its reference files. Until then it costs about 72 tokens; SKILL.md has 429 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Mathews-Tom/armory at commit 4594fb7, republished under its MIT licence (© Mathews-Tom). 429 words, ~2,520 tokens.

Download SKILL.mdSave it as .claude/skills/migration-risk-analyzer/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
migration-risk-analyzer
description
Analyzes database migration scripts for lock contention, downtime, rollback strategy, and deployment risk. Triggers on: "analyze this migration", "migration risk", "is this migration safe", "schema change risk", "DDL risk", "rollback strategy", "migration review".
metadata.version
1.1.1
metadata.category
review
metadata.tags
database, migration, ddl, rollback
metadata.difficulty
advanced
metadata.phase
review

Migration Risk Analyzer

Systematic risk assessment for database migrations: parse DDL/DML operations, classify lock types and durations, estimate downtime, design rollback strategies, identify irreversible changes, and produce deployment recommendations with pre/post validation queries.

Reference Files

FileContentsLoad When
references/lock-matrix.mdOperation-to-lock-type mapping for PostgreSQL, MySQLAlways
references/safe-patterns.mdOnline DDL patterns, zero-downtime migration techniquesRisk mitigation needed
references/rollback-templates.mdRollback scripts for common DDL operationsRollback strategy requested
references/validation-queries.mdPre/post migration validation SQL templatesAlways

Prerequisites

  • The migration SQL or migration file (Alembic, Django, Flyway, etc.)
  • Target database engine (PostgreSQL, MySQL)
  • Approximate table sizes for affected tables (for duration estimation)

Workflow

Phase 1: Parse Migration

Extract all operations from the migration script:

  1. DDL operations — CREATE TABLE, ALTER TABLE (ADD/DROP/MODIFY COLUMN, ADD/DROP INDEX), DROP TABLE, RENAME TABLE
  2. DML operations — UPDATE, INSERT, DELETE on existing data
  3. Index operations — CREATE INDEX, DROP INDEX, REINDEX
  4. Constraint operations — ADD/DROP FOREIGN KEY, ADD/DROP CHECK, ADD/DROP NOT NULL
Phase 2: Assess Lock Risk

For each operation, determine the lock type and impact:

Lock LevelImpactExamples
No lockZero impactCREATE TABLE, CREATE INDEX CONCURRENTLY (PG)
Share lockBlocks writes, allows readsCREATE INDEX (non-concurrent)
Exclusive lockBlocks all accessALTER TABLE ADD COLUMN (MySQL < 8.0), DROP TABLE
Row-level lockBlocks affected rows onlyUPDATE with WHERE clause

Consider:

  • Table size (locks on 10-row tables are negligible; locks on 100M-row tables are critical)
  • Concurrent query patterns (OLTP with high write rates vs. OLAP with batch queries)
  • Lock timeout settings
Show full SKILL.md (191 more words)Show less
Phase 3: Estimate Duration

Estimate based on operation type and table size:

OperationSmall Table (<100K)Medium (100K-10M)Large (>10M)
ADD COLUMN (nullable)< 1s< 1s< 1s (PG) / minutes (MySQL)
ADD COLUMN (with default)< 1ssecondsminutes (table rewrite)
CREATE INDEX< 1ssecondsminutes-hours
ADD NOT NULLsecondsminuteshours (full scan)
Backfill UPDATEsecondsminuteshours
Phase 4: Design Rollback

For each operation, determine reversibility:

OperationReversibleRollback
ADD COLUMNYesDROP COLUMN
DROP COLUMNNoData is lost
ADD INDEXYesDROP INDEX
DROP TABLENoData is lost
RENAME COLUMNYesRENAME back
ALTER TYPESometimesMay lose precision
UPDATE dataSometimesOnly if old values preserved

For irreversible operations, recommend backup strategies.

Phase 5: Generate Report

Produce a risk assessment with deployment recommendation.

Output Format

## Migration Risk Analysis

### Summary
- **Operations:** {N} DDL, {M} DML
- **Tables affected:** {list with row counts}
- **Overall risk:** {High | Medium | Low}
- **Estimated duration:** {range}
- **Requires downtime:** {Yes | No}

### Operation Risk Table

| # | Operation | Risk | Lock Type | Est. Duration | Reversible |
|---|-----------|------|-----------|---------------|------------|
| 1 | {SQL operation} | {High/Med/Low} | {lock type} | {time} | {Yes/No} |

### Lock Analysis
- **Exclusive locks:** {list of operations that block all access}
- **Maximum lock duration:** {estimated time}
- **Affected queries:** {types of queries that will be blocked}

### Rollback Strategy

#### Reversible Operations
```sql
-- Rollback for operation 1: {description}
{rollback SQL}
Irreversible Operations
  • {operation} — IRREVERSIBLE. Mitigation:
    sql
    -- Backup before migration
    {backup SQL}
Pre-Migration Checklist
  • Database backup completed
  • Rollback scripts tested in staging
  • Traffic reduction confirmed (if needed)
  • Monitoring and alerting configured
  • Stakeholders notified
  • Connection pool sized for lock wait
Post-Migration Validation
sql
-- Verify structural changes
{validation queries}

-- Verify data integrity
{integrity checks}
Deployment Recommendation

Strategy: {Online | Low-Traffic Window | Maintenance Window} Estimated downtime: {time or "None with proper execution"} Rollback time: {time} Risk mitigation: {specific recommendations}

text

## Calibration Rules

1. **Assume large tables.** If table size is unknown, assume it's large enough for
   locks to matter. Overestimating risk is safer than underestimating.
2. **Engine-specific analysis.** PostgreSQL and MySQL handle DDL very differently.
   PostgreSQL can add nullable columns without table rewrite; MySQL often cannot.
   Always target the specific engine.
3. **Irreversible means irreversible.** DROP COLUMN destroys data. No amount of
   rollback scripting recovers it. Flag every irreversible operation prominently.
4. **Test the rollback.** Rollback scripts must be tested in staging before the
   migration runs in production. Untested rollback is no rollback.
5. **Sequence matters.** The order of operations affects lock duration. Adding a
   column then backfilling then adding NOT NULL is safer than adding a NOT NULL
   column with a default.

## Error Handling

| Problem | Resolution |
|---------|------------|
| Database engine not specified | Ask. Lock behavior differs significantly between engines. |
| Table sizes unknown | Analyze without duration estimates. Flag that estimates require row counts. |
| ORM migration format (not raw SQL) | Parse the ORM migration file. Translate operations to SQL equivalents for analysis. |
| Migration has data-dependent logic | Flag conditional operations. Risk depends on data state at migration time. |
| Multiple migrations in sequence | Analyze each independently and as a group. Cross-migration lock accumulation is a risk. |

## When NOT to Analyze

Push back if:
- The migration is for a development/staging database — risk analysis is for production
- The migration only creates new tables (no ALTER, no existing data) — low risk by definition
- The user wants migration execution, not analysis — this skill assesses risk, it doesn't run migrations

## Rationalizations

| Rationalization | Reality |
|---|---|
| "It's backwards compatible" | Backwards compatible at the schema level doesn't mean backwards compatible at the application level — query plans, ORM mappings, and application code all interact |
| "We can roll back" | Rollback is not free — data written after migration may not survive rollback; DROP COLUMN has no rollback without backup |
| "It's a small table" | Table size is one factor — lock duration, concurrent write rate, and replication lag matter more than row count |
| "We've run this migration type before" | Past success doesn't predict future success — different data distribution, different load, different constraints |
| "Downtime window is long enough" | Estimate based on dev data, not production — migration on 10k rows takes seconds; on 50M rows with indexes, it takes hours |
| "The ORM handles it" | ORMs generate SQL, they don't guarantee safety — `ALTER TABLE` locking behavior is engine-specific and ORM-opaque |

## Red Flags

- No estimate of migration duration based on production data volume
- No rollback plan or rollback plan that doesn't account for data written post-migration
- Analyzing migration SQL without checking the current table size and write rate
- No consideration of replication lag in multi-replica setups
- Assuming zero downtime without verifying lock behavior for the specific DDL operation
- Skipping index analysis — adding an index on a large table can lock writes for minutes to hours

## Verification

- [ ] Production table sizes and row counts documented for all affected tables
- [ ] Lock behavior identified for each DDL statement (exclusive lock, no lock, etc.)
- [ ] Migration duration estimated using production-scale data, not dev fixtures
- [ ] Rollback plan documented with specific steps and data preservation guarantees
- [ ] Concurrent write impact assessed — what happens to in-flight transactions during migration
- [ ] Replication lag impact assessed for multi-replica configurations

© Mathews-Tom, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/migration-risk-analyzer of Mathews-Tom/armory.

  • SKILL.md
  • evals/cases.yaml
  • references/lock-matrix.md
  • references/rollback-templates.md
  • references/safe-patterns.md
  • references/validation-queries.md

Open the folder on GitHubat commit 4594fb7

Compare with similar skills

Migration Risk Analyzer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Migration Risk Analyzer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Migration Risk Analyzer this skillMathews-Tom/armory328—~2.5kAutomated safety check: PassMIT
Lovableaiskillstore/marketplace4301 repos~2.7kAutomated safety check: NotesNone
Migration Patternssoftspark/ai-toolkit179—~2.2kAutomated safety check: PassApache-2.0
Wtfnoobnooc/agent1.4k—~2.1kAutomated safety check: NotesNone
ClawHub Convex Conventionsopenclaw/clawhub9.5k—~1.4kAutomated safety check: NotesMIT
Database Migrationdavila7/claude-code-templates32k11 repos~2.8kAutomated safety check: PassMIT

Similar skills

  • Lovable

    aiskillstore/marketplace

    Integration skill for Lovable.dev projects. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~2.7k tokens
    DatabasesAuto-check: notes
  • Migration Patterns

    softspark/ai-toolkit

    Zero-downtime DB migrations: expand-contract, double-write, backfill, blue-green.

    179 GitHub stars~2.2k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Wtf

    noobnooc/agent

    Pre-launch and pre-commit audit for vibe coding projects. An agent skill from noobnooc/agent.

    1.4k GitHub stars~2.1k tokensUpdated 1 mo ago
    DatabasesAuto-check: notes
  • Applies ClawHub's repository-specific Convex rules and routes work to the right managed Convex skill for performance, migrations, retention and deployments.

    9.5k GitHub stars~1.4k tokensUpdated today
    DatabasesAuto-check: notes
  • Database Migration

    davila7/claude-code-templates

    Master database schema and data migrations across ORMs (Sequelize, TypeORM, Prisma), including rollback strategies and zero-downtime deployments.

    32k GitHub starsUsed in 11 repos~2.8k tokens
    DatabasesAuto-check passed
  • Deployment Rollback Interviewer

    PrepLabsAI/InterviewMentor

    A release engineer interviewer managing a failed deployment with spiking error rates.

    112 GitHub stars~3.1k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from Mathews-Tom/armory

All 80 skills in this repo
  • Architecture Reviewer

    Mathews-Tom/armory

    Architecture reviews across 7 dimensions (structural, scalability, enterprise readiness, performance, security, ops, data) with scored reports.

    328 GitHub stars~4.6k tokensUpdated 3 days ago
    Auto-check passed
  • Concept To Image

    Mathews-Tom/armory

    Turn concepts into static HTML visuals exported as PNG or SVG files via HTML/CSS/SVG.

    328 GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed
  • Watch

    Mathews-Tom/armory

    A skill your agent uses when analyzing an existing video URL or local recording: "watch this video", "analyze youtube video", "summarize this video", "youtube transcript", "find this moment", "what…

    328 GitHub stars~2.8k tokensUpdated 3 days ago
    Auto-check passed
  • Code Refiner

    Mathews-Tom/armory

    Deep code simplification and refactoring preserving behavior across Python, Go, TypeScript, Rust.

    328 GitHub stars~3.1k tokensUpdated 3 days ago
    Auto-check passed
  • Concept To Video

    Mathews-Tom/armory

    Turn concepts into animated explainer videos using Manim (Python) with MP4/GIF output, audio overlay, multi-scene composition.

    328 GitHub stars~4.9k tokensUpdated 3 days ago
    Auto-check passed
  • Decision Map

    Mathews-Tom/armory

    Maps the unresolved architecture, policy, and scope decisions that must be answered before planning can start: one durable decision ticket per question on the issue tracker, typed and blocker-linked…

    328 GitHub stars~2.7k tokensUpdated 3 days ago
    Auto-check passed

Questions about Migration Risk Analyzer

What does Migration Risk Analyzer do?

Analyzes database migration scripts for lock contention, downtime, rollback strategy, and deployment risk. Migration Risk Analyzer is an agent skill from Mathews-Tom/armory. Analyzes database migration scripts for lock contention, downtime, rollback strategy, and deployment risk.

When should I use Migration Risk Analyzer?

Migration Risk Analyzer fits situations like: : analyze this migration; is this migration safe; schema change risk; rollback strategy.

How do I install Migration Risk Analyzer in Claude Code?

Run `npx skills add Mathews-Tom/armory --skill migration-risk-analyzer -a claude-code`. Or copy the skill folder (skills/migration-risk-analyzer in Mathews-Tom/armory) into .claude/skills/migration-risk-analyzer in your project. Claude Code loads it when a task matches its description.

How do I install Migration Risk Analyzer in Codex?

Run `npx skills add Mathews-Tom/armory --skill migration-risk-analyzer -a codex`. Or copy the skill folder (skills/migration-risk-analyzer in Mathews-Tom/armory) into .agents/skills/migration-risk-analyzer in your project. Codex loads it when a task matches its description.

Can I use Migration Risk Analyzer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Mathews-Tom/armory --skill migration-risk-analyzer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/migration-risk-analyzer, .gemini/skills/migration-risk-analyzer, .github/skills/migration-risk-analyzer and .opencode/skills/migration-risk-analyzer in your project.

What does Migration Risk Analyzer need to run?

SKILL.md names no scripts, command-line tools or credentials: Migration Risk Analyzer is instructions for the agent only.

Does Migration Risk Analyzer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Migration Risk Analyzer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Migration Risk Analyzer use?

Migration Risk Analyzer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Migration Risk Analyzer use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.4k tokens, read only when the agent opens those files.

What are the alternatives to Migration Risk Analyzer?

Skills that share tags, products or a category with Migration Risk Analyzer: Lovable (aiskillstore/marketplace, 430 stars), Migration Patterns (softspark/ai-toolkit, 179 stars), Wtf (noobnooc/agent, 1.4k stars) and ClawHub Convex Conventions (openclaw/clawhub, 9.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Migration Risk Analyzer?

Mathews-Tom (a GitHub user) maintains it in Mathews-Tom/armory, which has 328 GitHub stars. The repository holds 80 skills in this directory. The repository was last updated on October 6, 2026.

Source: Mathews-Tom/armory on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.