Official agent skill

Planetscale Autonomous Execution Mode

by planetscale in planetscale/skills

Execute approved PlanetScale changes end-to-end without per-step approval when the operator has explicitly acknowledged the risk.

OfficialMITAuto-check passedDevOps & Cloud

Install Planetscale Autonomous Execution Mode

skills CLI
$ npx skills add planetscale/skills --skill planetscale-autonomous-execution-mode -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install planetscale/skills planetscale-autonomous-execution-mode --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/planetscale/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/planetscale-autonomous-execution-mode .claude/skills/planetscale-autonomous-execution-mode && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
planetscale-autonomous-execution-mode
GitHub stars
133
Token cost
~2.6k tokens
SKILL.md length
1,438 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Execute approved PlanetScale changes end-to-end without per-step approval when the operator has explicitly acknowledged the risk.

  • Works in 3 steps: Explicit risk acknowledgment. An… → A named scope. One of → A production statement. Whether…
  • DevOps & Cloud work in your project
  • SKILL.md covers Purpose, Activation contract, Sensible execution: the plan and Status protocol, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Planetscale Autonomous Execution Mode is an agent skill from planetscale/skills, published by the product's own GitHub organization. Execute approved PlanetScale changes end-to-end without per-step approval when the operator has explicitly acknowledged the risk. Defines the risk-acknowledgment contract, scoped autonomy levels, sensible execution ordering, continuous status reporting, halt conditions, and rollback discipline. Extremely safe, very enabling.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with PlanetScale. The repository describes itself as: Skills that help you configure and get the most out of PlanetScale. The licence is MIT.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/planetscale-autonomous-execution-mode”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Explicit risk acknowledgment. An unambiguous statement such as "I understand the risk", "I accept the risk", "I know this can affect…
  2. A named scope. One of
  3. A production statement. Whether production-affecting (Class D) changes are included. If the operator does not say, ask once; if still…

What it can do on your machine

Read from SKILL.md and the folder at commit 999045c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Planetscale Autonomous Execution Mode loads about 2.6k tokens when it runs. Until then it costs about 91 tokens; SKILL.md has 1,438 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from planetscale/skills at commit 999045c, republished under its MIT licence (© planetscale). 1,438 words, ~2,634 tokens.

Download SKILL.mdSave it as .claude/skills/planetscale-autonomous-execution-mode/SKILL.md (or your agent's skills folder).
name
planetscale-autonomous-execution-mode
description
Execute approved PlanetScale changes end-to-end without per-step approval when the operator has explicitly acknowledged the risk. Defines the risk-acknowledgment contract, scoped autonomy levels, sensible execution ordering, continuous status reporting, halt conditions, and rollback discipline. Extremely safe, very enabling.

Autonomous execution mode

Purpose

Let an operator who has explicitly accepted the risk hand the whole job to the agent: plan, execute, verify, and report — with live status the entire way — instead of approving each change one by one. This mode removes the per-step approval friction. It does not remove any verification, ordering, rollback, or halt discipline. Autonomy changes who clicks "go", never how carefully the work is done.

Activation contract

Autonomous mode activates only when the operator's message contains all three:

  1. Explicit risk acknowledgment. An unambiguous statement such as "I understand the risk", "I accept the risk", "I know this can affect production". Softer phrasings — "go ahead", "sounds good", "do it" — do NOT activate autonomous mode; they remain per-change approvals under the change-gates skill.
  2. A named scope. One of:
    • Named change IDs ("VIT-1, VIT-3, WEB-1"), or
    • A named database or org with a change-class ceiling ("everything in the report for storefront-demo"), or
    • "All recommendations in the report" — valid in this mode only, because the report already names every change.
  3. A production statement. Whether production-affecting (Class D) changes are included. If the operator does not say, ask once; if still unstated, run at auto-safe (Class D excluded).

Record the acknowledgment verbatim in the run log before executing anything.

Autonomy levels
LevelUnlocksRequires
auto-safeClass B + Class C within scopeRisk acknowledgment + scope
auto-productionAdds Class D within scopeRisk acknowledgment + scope + explicit production statement
—Class ENever available. No phrasing unlocks it.

Class E operations (dropping production databases/tables, disabling all safety mechanisms simultaneously, exposing secrets, removing private-only network posture) are refused in every mode. If a requested change set contains a Class E item, execute the rest and report the exclusion — do not silently skip and do not ask the operator to "confirm harder".

Acknowledgment lifetime
  • Applies to this run only. A new session, a new report, or a materially changed database state requires re-acknowledgment.
  • Applies to the named scope only. Discovering a new problem mid-run does not authorize fixing it — add it to the report and continue.
  • The operator can say "stop" at any time; halt after the current atomic step and produce the partial-run report.
Standing authorization (scheduled automation)

Interactive acknowledgment is single-run. Scheduled agents (cron, Cursor Automations, webhook-triggered runs) instead operate under a standing authorization: a written artifact, committed where the agent reads its instructions (an AGENTS.md section or a dedicated authorization file), containing:

  • Automation name and owner.
  • Scope: organization, database, branches.
  • Class ceiling: B, C, or D. Class E is not authorizable.
  • Operation allowlist, stated as bounded operations, not intents. Valid: "open deploy requests for additive DDL from open schema recommendations; deploy with revert window; additive only (ADD INDEX, ADD COLUMN NULL)". Invalid: "keep the schema optimized".
  • Numeric bounds where applicable: max changes per run, max branch age for deletion, budget modes permitted (warn only vs enforce).
  • Expiry date. Expired authorization = report-only mode. Recommended review interval: 90 days.

Per-run rules for standing authorization:

  • The agent re-reads the authorization at the start of every run; execution is bounded by the artifact as written, not by memory of it.
  • Everything outside the allowlist is report-only for that run.
  • All halt conditions apply unchanged. A halted scheduled run does not self-resume; it reports and waits for the owner.
  • Status streams to a configured delivery channel (webhook, Slack, issue tracker) since no operator is watching an interactive session. A scheduled run with no delivery channel must not execute mutations — status with no reader is not status.
  • The run log is persisted per run and referenced in the delivery channel message.

Sensible execution: the plan

Before the first mutation, produce and show an execution plan:

  1. Order by dependency, then by risk. Prerequisites first (e.g. stop the app's boot-time DDL before enabling safe migrations, add an index before dropping the one it replaces). Among independent changes, lowest-risk first so early failures cost the least.
  2. Pre-flight each change. Re-read the live state immediately before mutating (branch flags, recommendation state, webhook config). If the state no longer matches the report evidence, the change is stale: skip it, mark it BLOCKED — state drift, and continue with independent changes.
  3. Safety prerequisites are steps, not assumptions. Before any Class D DDL: confirm a backup completed within the retention window, confirm safe migrations or a deploy request is the vehicle where the engine supports it, and prefer revertible mechanisms (deploy requests with revert window, warn-mode before enforce-mode for Traffic Control).
  4. One atomic change at a time. Never batch unrelated mutations into one command. Never parallelize Class D steps.
  5. Verify after each step. Read the state back and confirm the expected effect before moving on. A change is not "done" when the command exits 0; it is done when the read-back matches the expected state.
Show full SKILL.md (643 more words)Show less

Status protocol

The operator handed over control; visibility is what they get in return. Emit status at every stage:

  • Plan announcement — numbered steps, each with target, exact command/interface, expected effect, rollback mechanism, and class. This is the last thing shown before execution begins.
  • Per-step, before: [step 3/7] STARTING VIT-3a — deploy request: add idx_orders_on_user_id to storefront-demo/main (Class D, revert window available)
  • Per-step, after: [step 3/7] DONE — deploy request #4 deployed, index visible in schema read-back (took 2m 10s)
  • Long-running operations (deploy requests, migrations, restores): poll and report progress at a sensible cadence, not just at completion. Include queue position/state transitions.
  • Skips and blocks: report immediately with the reason (BLOCKED — state drift, EXCLUDED — Class E, SKIPPED — prerequisite failed), never silently.
  • Run summary — the post-execution report from the change-gates skill: what changed, when, evidence of success, warnings, rollback state, follow-up monitoring. Plus the acknowledgment quote and the autonomy level used.

Status lines must be specific enough that an operator reading only the status stream could reconstruct the run: name the change ID, the target, and the mechanism every time.

Status is plain text, emitted in the agent's normal output stream as each step happens. It must not depend on any host-specific rendering surface (canvas, HTML, TUI widgets) — those may supplement the stream, never replace it. The plain-text stream and the run log are the record of the run in every agent.

Halt conditions

Stop-the-line rules. When any of these fires, finish or safely abort the current atomic step, execute the pre-staged rollback if the step half-applied, and report:

  1. Any Class D step fails or verifies incorrectly → halt the entire run.
  2. A Class B/C step fails → halt that change's dependency chain; independent changes may continue; say so in status.
  3. An anomaly begins firing on a target database mid-run → pause the run, report the anomaly, wait for the operator.
  4. State drift on a production target (someone else changed it mid-run) → halt the run.
  5. Scope pressure — anything needed that is outside the acknowledged scope → do not do it; report it.
  6. Error on a destructive step → never auto-retry. Retries are permitted only for idempotent reads and transient network failures on non-destructive calls.

After a halt: report state of every step (done / rolled back / blocked / not started), current database state, and what re-acknowledgment would be needed to resume. Never resume a halted run on the original acknowledgment.

Rollback discipline

  • Before each step, stage the concrete rollback: the exact command or mechanism (deploy request revert, budget back to warn, webhook disable, restore point).
  • Auto-rollback without asking when a step half-applies and the rollback is itself non-destructive and pre-declared in the plan.
  • Never auto-rollback with a destructive operation (e.g. never auto-restore over data); report and wait instead.

Run log

Maintain an append-only run log for the whole session: timestamp, step ID, command, result, read-back evidence. Include it (or its path) in the run summary. The log is the audit trail that makes "the agent did it autonomously" reviewable.

Interaction with other skills

  • ../planetscale-change-gates-and-approval-contract/SKILL.md — the class definitions and pre/post-execution checklists still apply verbatim; a valid risk acknowledgment substitutes for per-change approval within scope. Class E rules are unchanged.
  • ../planetscale-safe-orchestrator/SKILL.md — when a valid acknowledgment accompanies the assessment request ("run the audit and fix what you find, I accept the risk"), run the full assessment first, present the report and execution plan, then proceed directly into execution under this skill without stopping for approval.
  • ../planetscale-schema-recommendations-agent-loop/SKILL.md — in autonomous mode the loop may carry recommendations all the way through branch, deploy request, and deploy, using gated deployments where cutover timing matters.

Required refusal behavior

If the operator asks for full autonomy without the acknowledgment elements, do not negotiate ambiguity. Reply:

"Autonomous mode needs an explicit risk acknowledgment, a named scope, and whether production changes are included. For example: 'I accept the risk — apply all report recommendations to storefront-demo, production included.'"

Then wait.

© planetscale, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in planetscale-autonomous-execution-mode of planetscale/skills.

Open the folder on GitHubat commit 999045c

Compare with similar skills

Planetscale Autonomous Execution Mode next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Planetscale Autonomous Execution Mode compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Planetscale Autonomous Execution Mode this skillplanetscale/skills133—~2.6kAutomated safety check: PassMIT
Cap Feature Building WorkflowCapSoftware/Cap23k—~2.5kAutomated safety check: WarnCustom licence
Monitor CInrwl/nx29k6 repos~4.7kAutomated safety check: PassMIT
Terraform and OpenTofu Guideagentscope-ai/QwenPaw35k6 repos~4.2kAutomated safety check: PassApache-2.0
Vercel Optimize Auditvercel-labs/agent-skills32k9 repos~4.3kAutomated safety check: PassNone
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT

Similar skills

  • Builds a Cap feature in an isolated Git worktree with disposable dev resources, verification, a recorded demo and a neutral pull request, started with /building.

    23k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check: warnings
  • Monitor CI

    nrwl/nx

    Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.

    29k GitHub starsUsed in 6 repos~4.7k tokens
    DevOps & CloudAuto-check passed
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    35k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 9 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed

More from planetscale/skills

All 15 skills in this repo
  • Official

    Use the PlanetScale CLI (pscale) from automated agents with --format json, auth check, pscale sql, and per-command --force.

    133 GitHub stars~880 tokensUpdated yesterday
    Auto-check passed
  • Official

    Master skill that runs the full PlanetScale safe best-practices assessment — inventory, engine review, Insights, Traffic Control, webhooks, schema recommendations, codebase instrumentation, and…

    133 GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Official

    A concise feature matrix for deciding which PlanetScale safety, observability, and automation recommendations apply by engine.

    133 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Enforce explicit approval gates for any PlanetScale, database, repository, credential, network, or automation mutation.

    133 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Inspect an application repository connected to PlanetScale and recommend SQLCommenter-compatible query tagging packages and conventions.

    133 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Official

    Produce the final PlanetScale best-practices report after running the inventory and relevant review skills.

    133 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Planetscale Autonomous Execution Mode

What does Planetscale Autonomous Execution Mode do?

Execute approved PlanetScale changes end-to-end without per-step approval when the operator has explicitly acknowledged the risk. Planetscale Autonomous Execution Mode is an agent skill from planetscale/skills, published by the product's own GitHub organization. Execute approved PlanetScale changes end-to-end without per-step approval when the operator has explicitly acknowledged the risk.

When should I use Planetscale Autonomous Execution Mode?

Planetscale Autonomous Execution Mode fits situations like: devOps & Cloud work in your project.

How do I install Planetscale Autonomous Execution Mode in Claude Code?

Run `npx skills add planetscale/skills --skill planetscale-autonomous-execution-mode -a claude-code`. Or copy the skill folder (planetscale-autonomous-execution-mode in planetscale/skills) into .claude/skills/planetscale-autonomous-execution-mode in your project. Claude Code loads it when a task matches its description.

How do I install Planetscale Autonomous Execution Mode in Codex?

Run `npx skills add planetscale/skills --skill planetscale-autonomous-execution-mode -a codex`. Or copy the skill folder (planetscale-autonomous-execution-mode in planetscale/skills) into .agents/skills/planetscale-autonomous-execution-mode in your project. Codex loads it when a task matches its description.

Can I use Planetscale Autonomous Execution Mode in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add planetscale/skills --skill planetscale-autonomous-execution-mode -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/planetscale-autonomous-execution-mode, .gemini/skills/planetscale-autonomous-execution-mode, .github/skills/planetscale-autonomous-execution-mode and .opencode/skills/planetscale-autonomous-execution-mode in your project.

What does Planetscale Autonomous Execution Mode need to run?

SKILL.md names no scripts, command-line tools or credentials: Planetscale Autonomous Execution Mode is instructions for the agent only.

Does Planetscale Autonomous Execution Mode access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Planetscale Autonomous Execution Mode safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Planetscale Autonomous Execution Mode use?

Planetscale Autonomous Execution Mode is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Planetscale Autonomous Execution Mode use?

About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Planetscale Autonomous Execution Mode?

Skills that share tags, products or a category with Planetscale Autonomous Execution Mode: Cap Feature Building Workflow (CapSoftware/Cap, 23k stars), Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 35k stars) and Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Planetscale Autonomous Execution Mode?

planetscale (a GitHub organization, an official publisher) maintains it in planetscale/skills, which has 133 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 7, 2026.

Source: planetscale/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.