Official agent skill

Planetscale Change Gates And Approval Contract

by planetscale in planetscale/skills

Enforce explicit approval gates for any PlanetScale, database, repository, credential, network, or automation mutation.

OfficialMITAuto-check passedBackend & APIs

Install Planetscale Change Gates And Approval Contract

skills CLI
$ npx skills add planetscale/skills --skill planetscale-change-gates-and-approval-contract -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install planetscale/skills planetscale-change-gates-and-approval-contract --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/planetscale/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/planetscale-change-gates-and-approval-contract .claude/skills/planetscale-change-gates-and-approval-contract && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
planetscale-change-gates-and-approval-contract
GitHub stars
133
Token cost
~1.3k tokens
SKILL.md length
659 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Enforce explicit approval gates for any PlanetScale, database, repository, credential, network, or automation mutation.

  • Backend & APIs work in your project
  • SKILL.md covers Purpose, Operation classes, Approval requirements and Autonomous execution exception, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Planetscale Change Gates And Approval Contract is an agent skill from planetscale/skills, published by the product's own GitHub organization. Enforce explicit approval gates for any PlanetScale, database, repository, credential, network, or automation mutation.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. It works with PlanetScale. The repository describes itself as: Skills that help you configure and get the most out of PlanetScale. The licence is MIT.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “/planetscale-change-gates-and-approval-contract”

What it can do on your machine

Read from SKILL.md and the folder at commit 999045c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Planetscale Change Gates And Approval Contract loads about 1.3k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 659 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from planetscale/skills at commit 999045c, republished under its MIT licence (© planetscale). 659 words, ~1,334 tokens.

Download SKILL.mdSave it as .claude/skills/planetscale-change-gates-and-approval-contract/SKILL.md (or your agent's skills folder).
name
planetscale-change-gates-and-approval-contract
description
Enforce explicit approval gates for any PlanetScale, database, repository, credential, network, or automation mutation.

Change gates and approval contract

Purpose

Prevent accidental or autonomous changes that can affect availability, safety, security, data, or developer workflows.

Operation classes

Class A: read-only by default

Allowed without approval:

  • List databases, branches, keyspaces, webhooks, backups, roles, traffic budgets, schema recommendations, deploy requests, and Insights data.
  • Inspect repository code.
  • Read schema metadata.
  • Read non-sensitive database metadata.
  • Produce reports and proposed change sets.
Class B: state-creating proposals

Allowed by default; requires approval only when the operator has demanded strict no-mutation mode:

  • Creating a query-pattern report through an API POST, even if the result is read-only telemetry.
  • Triggering a webhook test event.
  • Creating temporary local branches or files.
  • Opening PRs or issues in external tools.
  • Creating database development branches.
  • Applying DDL or migrations to non-production development branches.
  • Opening deploy requests targeting a branch protected by a review workflow.

The last three are proposals inside an existing review system: nothing reaches production until a human merges or deploys. The gate belongs on the merge/deploy action (Class C/D), not on proposal creation. An agent that stops to ask permission to open a PR is misclassifying.

Class C: behavior-changing

Always requires explicit approval:

  • Enable safe migrations.
  • Disable safe migrations.
  • Change deploy request approval settings.
  • Create/update/delete Traffic Control budget or rule.
  • Move Traffic Control budget to enforce mode.
  • Create/update/delete webhook.
  • Enable raw query collection.
  • Enable/disable extensions or settings that require restart.
  • Create/update/delete role.
  • Reset passwords.
  • Change pg_strict settings.
  • Change connection pooling behavior.
  • Change IP restrictions, PrivateLink, PSC, or public access.
  • Change backup schedule or retention.
  • Create restore branch.
  • Create backup beyond automatic backups.
  • Change branch size or replica topology.
  • Edit repository files or dependencies.
Class D: production data/availability impacting

Requires explicit approval, named target confirmation, rollback plan, and ideally a second human review:

  • Production DDL.
  • Production DML.
  • Applying schema recommendation to production.
  • Queueing or applying Vitess deploy request to production.
  • Promoting or restoring branches.
  • Deleting branches, databases, roles, webhooks, backups, or traffic rules.
  • Enforcing Traffic Control on production.
  • Changing production network access.
  • Rotating production credentials.
  • Emergency backup during high load.
Class E: never autonomous

Never do without direct human operation or separately approved incident procedure:

  • Delete a production database.
  • Disable all production safety mechanisms.
  • Drop production tables or columns.
  • Remove IP restrictions or private-only posture.
  • Store or expose secrets in logs, issues, PRs, Slack, or reports.
  • Auto-merge code generated from database telemetry.
  • Auto-apply DDL generated by an LLM.
Show full SKILL.md (266 more words)Show less

Approval requirements

A valid approval must include:

  • Change ID.
  • Target organization/database/branch.
  • Whether production is affected.
  • Permission to execute the exact action.

Invalid approvals:

  • “Do the best practices.”
  • “Fix everything.”
  • “Apply recommendations.”
  • “Go ahead” without named change IDs.

Autonomous execution exception

There is exactly one alternative to per-change approval: the risk-acknowledged autonomous mode defined in ../planetscale-autonomous-execution-mode/SKILL.md. When the operator explicitly acknowledges the risk, names a scope, and states whether production is included, that acknowledgment substitutes for per-change approval of Class B/C (and Class D when production is included) actions within the named scope only.

Everything else in this skill still applies in autonomous mode:

  • Class E is never unlocked by any phrasing.
  • The pre-execution checklist must still be produced for every Class C/D step (shown as the execution plan, not as a stop-and-wait).
  • The post-execution report is still required.
  • Out-of-scope work still requires new approval or new acknowledgment.

Required pre-execution checklist

Before any Class C or D action, produce:

  • Exact command, API endpoint, dashboard action, SQL, or repository diff.
  • Target confirmation.
  • Expected effect.
  • Availability impact.
  • Data risk.
  • Security risk.
  • Rollback plan.
  • Validation plan.
  • Monitoring plan.

Then stop for approval.

Required post-execution report

If an approved change is later executed, report:

  • What changed.
  • When it changed.
  • Who approved.
  • Interface used.
  • Evidence of success.
  • Any warnings.
  • Rollback state.
  • Follow-up monitoring.

Required refusal behavior

If asked to apply broad or ambiguous production changes, refuse the broad action and produce a safer named change plan.

Use this sentence:

“I will not apply broad production changes from an ambiguous instruction. I can produce a named change set with risk and rollback details.”

© planetscale, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in planetscale-change-gates-and-approval-contract of planetscale/skills.

Open the folder on GitHubat commit 999045c

Compare with similar skills

Planetscale Change Gates And Approval Contract next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Planetscale Change Gates And Approval Contract compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Planetscale Change Gates And Approval Contract this skillplanetscale/skills133—~1.3kAutomated safety check: PassMIT
cmux Backend Rulesmanaflow-ai/cmux28k1 repos~682Automated safety check: PassCustom licence
Planetscaleericrisco/rsc-harness180—~2.8kAutomated safety check: PassMIT
MySQL Schema and Query Tuningplanetscale/database-skills7083 repos~1.4kAutomated safety check: PassMIT
Cap Feature Building WorkflowCapSoftware/Cap23k—~2.5kAutomated safety check: WarnCustom licence
PlanetScale Postgres Playbookplanetscale/database-skills7083 repos~1.8kAutomated safety check: PassMIT

Similar skills

  • cmux Backend Rules

    manaflow-ai/cmux

    Sets the backend TypeScript and Cloud VM rules for cmux: Effect-based services, thin route handlers, Postgres as source of truth, migrations and provider secrets.

    28k GitHub starsUsed in 1 repo~682 tokens
    Backend & APIsAuto-check passed
  • Planetscale

    ericrisco/rsc-harness

    A skill your agent uses when operating PlanetScale (Vitess serverless MySQL) — branches and the pscale CLI, schema changes through deploy requests (Online DDL cutover, ~30-min revert window), tables…

    180 GitHub stars~2.8k tokensUpdated yesterday
    DatabasesAuto-check passed
  • MySQL Schema and Query Tuning

    planetscale/database-skills

    Official

    Guides safe, measurable MySQL and InnoDB changes across schema design, indexing, query tuning, transactions, locking and replication, with rollout steps.

    708 GitHub starsUsed in 3 repos~1.4k tokens
    DatabasesAuto-check passed
  • Builds a Cap feature in an isolated Git worktree with disposable dev resources, verification, a recorded demo and a neutral pull request, started with /building.

    23k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check: warnings
  • PlanetScale Postgres Playbook

    planetscale/database-skills

    Official

    Indexes reference files on Postgres schema design, indexing, partitioning, query patterns, MVCC and VACUUM, and PlanetScale-specific operations.

    708 GitHub starsUsed in 3 repos~1.8k tokens
    DatabasesAuto-check passed
  • Vitess for PlanetScale

    planetscale/database-skills

    Official

    Guidance on Vitess sharding, VSchema design, query tuning and connection problems for MySQL-compatible databases running on PlanetScale.

    708 GitHub starsUsed in 1 repo~1.2k tokens
    DatabasesAuto-check passed

More from planetscale/skills

All 15 skills in this repo
  • Official

    Use the PlanetScale CLI (pscale) from automated agents with --format json, auth check, pscale sql, and per-command --force.

    133 GitHub stars~880 tokensUpdated today
    Auto-check passed
  • Official

    Master skill that runs the full PlanetScale safe best-practices assessment — inventory, engine review, Insights, Traffic Control, webhooks, schema recommendations, codebase instrumentation, and…

    133 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Official

    Execute approved PlanetScale changes end-to-end without per-step approval when the operator has explicitly acknowledged the risk.

    133 GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Official

    A concise feature matrix for deciding which PlanetScale safety, observability, and automation recommendations apply by engine.

    133 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Inspect an application repository connected to PlanetScale and recommend SQLCommenter-compatible query tagging packages and conventions.

    133 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Official

    Produce the final PlanetScale best-practices report after running the inventory and relevant review skills.

    133 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Planetscale Change Gates And Approval Contract

What does Planetscale Change Gates And Approval Contract do?

Enforce explicit approval gates for any PlanetScale, database, repository, credential, network, or automation mutation. Planetscale Change Gates And Approval Contract is an agent skill from planetscale/skills, published by the product's own GitHub organization. Enforce explicit approval gates for any PlanetScale, database, repository, credential, network, or automation mutation.

When should I use Planetscale Change Gates And Approval Contract?

Planetscale Change Gates And Approval Contract fits situations like: backend & APIs work in your project.

How do I install Planetscale Change Gates And Approval Contract in Claude Code?

Run `npx skills add planetscale/skills --skill planetscale-change-gates-and-approval-contract -a claude-code`. Or copy the skill folder (planetscale-change-gates-and-approval-contract in planetscale/skills) into .claude/skills/planetscale-change-gates-and-approval-contract in your project. Claude Code loads it when a task matches its description.

How do I install Planetscale Change Gates And Approval Contract in Codex?

Run `npx skills add planetscale/skills --skill planetscale-change-gates-and-approval-contract -a codex`. Or copy the skill folder (planetscale-change-gates-and-approval-contract in planetscale/skills) into .agents/skills/planetscale-change-gates-and-approval-contract in your project. Codex loads it when a task matches its description.

Can I use Planetscale Change Gates And Approval Contract in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add planetscale/skills --skill planetscale-change-gates-and-approval-contract -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/planetscale-change-gates-and-approval-contract, .gemini/skills/planetscale-change-gates-and-approval-contract, .github/skills/planetscale-change-gates-and-approval-contract and .opencode/skills/planetscale-change-gates-and-approval-contract in your project.

What does Planetscale Change Gates And Approval Contract need to run?

SKILL.md names no scripts, command-line tools or credentials: Planetscale Change Gates And Approval Contract is instructions for the agent only.

Does Planetscale Change Gates And Approval Contract access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Planetscale Change Gates And Approval Contract safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Planetscale Change Gates And Approval Contract use?

Planetscale Change Gates And Approval Contract is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Planetscale Change Gates And Approval Contract use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Planetscale Change Gates And Approval Contract?

Skills that share tags, products or a category with Planetscale Change Gates And Approval Contract: cmux Backend Rules (manaflow-ai/cmux, 28k stars), Planetscale (ericrisco/rsc-harness, 180 stars), MySQL Schema and Query Tuning (planetscale/database-skills, 708 stars) and Cap Feature Building Workflow (CapSoftware/Cap, 23k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Planetscale Change Gates And Approval Contract?

planetscale (a GitHub organization, an official publisher) maintains it in planetscale/skills, which has 133 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 10, 2026.

Source: planetscale/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.