Official agent skill

Planetscale MCP Agent Operating Model

by planetscale in planetscale/skills

Configure safe agent behavior around PlanetScale MCP, Insights, schema recommendations, and repository work without autonomous production mutation.

OfficialMITAuto-check passedAgent Workflows

Install Planetscale MCP Agent Operating Model

skills CLI
$ npx skills add planetscale/skills --skill planetscale-mcp-agent-operating-model -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install planetscale/skills planetscale-mcp-agent-operating-model --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/planetscale/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/planetscale-mcp-agent-operating-model .claude/skills/planetscale-mcp-agent-operating-model && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
planetscale-mcp-agent-operating-model
GitHub stars
132
Token cost
~2.4k tokens
SKILL.md length
1,250 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Configure safe agent behavior around PlanetScale MCP, Insights, schema recommendations, and repository work without autonomous production mutation.

  • Works in 2 steps: CLI agent guide — shipped with pscale… → Project agent guide — your application…
  • Tasks that involve MCP servers
  • SKILL.md covers Purpose, Default MCP choice, AGENTS.md guidance and Safe autonomous tasks, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Planetscale MCP Agent Operating Model is an agent skill from planetscale/skills, published by the product's own GitHub organization. Configure safe agent behavior around PlanetScale MCP, Insights, schema recommendations, and repository work without autonomous production mutation.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers. It works with PlanetScale and Model Context Protocol. The repository describes itself as: Skills that help you configure and get the most out of PlanetScale. The licence is MIT.

When your agent uses it

  • Tasks that involve MCP servers

Example prompts

  • “/planetscale-mcp-agent-operating-model”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. CLI agent guide — shipped with pscale (AGENTS.md in the
  2. Project agent guide — your application repository's AGENTS.md (or

What it can do on your machine

Read from SKILL.md and the folder at commit 999045c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Planetscale MCP Agent Operating Model loads about 2.4k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 1,250 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from planetscale/skills at commit 999045c, republished under its MIT licence (© planetscale). 1,250 words, ~2,366 tokens.

Download SKILL.mdSave it as .claude/skills/planetscale-mcp-agent-operating-model/SKILL.md (or your agent's skills folder).
name
planetscale-mcp-agent-operating-model
description
Configure safe agent behavior around PlanetScale MCP, Insights, schema recommendations, and repository work without autonomous production mutation.

MCP agent operating model

Purpose

Define how agents should use PlanetScale MCP safely. Agents should use production telemetry to generate useful work while avoiding autonomous production changes.

Default MCP choice

Use the PlanetScale MCP insights-only server when the task only needs Insights and Schema Recommendations.

Use the full PlanetScale MCP server only when the task explicitly requires database/schema access beyond Insights. Prefer read-only scopes.

The full MCP server has query execution tools. Treat write query tools as disabled unless the operator explicitly approves a specific non-production action or a carefully reviewed production action.

AGENTS.md guidance

Two different documents both named AGENTS.md serve different purposes:

  1. CLI agent guide — shipped with pscale (AGENTS.md in the planetscale/cli repo, or pscale agent-guide --format json). Covers auth, --format json, flag placement, and pscale sql. Load skill planetscale-pscale-cli-automation for the same conventions inside this skills pack.

  2. Project agent guide — your application repository's AGENTS.md (or equivalent). Covers database targeting and approval policy for this app.

When working inside a repository, recommend adding a project database targeting section to AGENTS.md or equivalent project instructions:

  • PlanetScale organization.
  • Database.
  • Branch.
  • Engine: Vitess or Postgres.
  • Production branch name.
  • Whether agents may use MCP insights-only or full MCP.
  • Whether write queries are forbidden.
  • Required approval protocol for schema, Traffic Control, webhooks, roles, and network changes.

Do not edit AGENTS.md without approval.

Safe autonomous tasks

Allowed by default:

  • Read Insights.
  • Read schema recommendations.
  • Read schema metadata.
  • Read existing webhooks and Traffic Control configuration.
  • Read branch metadata.
  • Inspect repository code.
  • Correlate query patterns with code.
  • File issues.
  • Open pull requests.
  • Create development branches.
  • Apply DDL and migrations to non-production development branches.
  • Open deploy requests into branches protected by a review workflow.
  • Draft Traffic Control budget proposals.
  • Draft webhook receiver requirements.

Where a PR + deploy-request workflow exists, the default deliverable for a schema recommendation is the complete reviewable unit: development branch with the DDL applied, PR with evidence (fingerprint, metrics, expected effect), and an open deploy request. The human action is the merge/deploy decision, not shepherding the proposal into existence.

Not allowed by default (the review-gate actions and non-reviewable mutations):

  • Execute write SQL against production.
  • Execute DDL directly against production branches.
  • Deploy a deploy request / apply schema to production.
  • Merge pull requests.
  • Create webhooks.
  • Create or enforce Traffic Control budgets.
  • Rotate credentials.
  • Change roles.
  • Change IP restrictions or private connectivity.
  • Restore or promote branches.

Agent loops

Daily recommendation loop
  1. Read open schema recommendations.
  2. Read top Insights regressions.
  3. Correlate with repository code.
  4. Generate ranked issues or PRs.
  5. Human reviews.
  6. Human approves any database-affecting action.
Anomaly loop
  1. Receive or inspect anomaly.
  2. Gather affected query patterns and tags.
  3. Identify source route/job/deploy.
  4. Produce incident note and proposed remediation.
  5. If code fix is obvious, open PR.
  6. If database change is needed, create a proposed change set only.
Traffic Control loop
  1. Identify unsafe traffic slice from Insights/tags.
  2. Draft warn budget proposal.
  3. Human approves creation.
  4. Observe warnings.
  5. Human approves enforce mode only after validation.

Scheduled loops (cron / Automations)

The loops above run interactively. They can also run on a schedule with no human in the loop, in two tiers. Tier 2 requires a standing authorization per ../planetscale-autonomous-execution-mode/SKILL.md; Tier 1 requires none.

Every scheduled loop, both tiers: re-read authorization at run start, stream status to a configured delivery channel, persist a run log, and avoid filing duplicates (do not re-file an issue that is already open for the same fingerprint/recommendation ID).

Tier 1 — propose through the review workflow (no authorization needed)
  • Recommendation-to-PR loop (daily): list open schema recommendations via MCP; for each new one matching the workflow (additive or destructive — the PR review is the gate), create a development branch, apply the DDL, open a PR with fingerprint, metrics, and expected effect, and open the deploy request. The reviewable unit is complete when a human can ship it with one merge/deploy action. Output: branch + PR + deploy request per recommendation.
  • Regression watch (hourly or per-deploy): compare top patterns against a stored baseline (p50/p99, rows read, execution count); on material regression, identify the deploy SHA from query tags and file a report linking pattern to commit range. Output: report.
  • Tag coverage audit (weekly): measure percentage of query time carrying tags; list untagged high-cost patterns with likely code paths; open or update a single tracking issue. Output: issue.
  • Anomaly triage (webhook-triggered, not polled): on branch.anomaly, gather affected patterns, classify probable cause, post triage note to the incident channel. Output: triage note.
  • Posture drift check (daily): diff current safe-migrations flags, webhook config, role list, and backup schedule against the last assessment report; report any drift. Output: report.
Show full SKILL.md (481 more words)Show less
Tier 2 — execute the review-gate action (standing authorization required)
  • Recommendation deployer (daily, after the PR loop): deploy open deploy requests that match the allowlist — typically "additive DDL, PR approved or authored from an open recommendation, deploy with revert window, max N per run" — then verify via schema read-back and an Insights follow-up on the target fingerprint. Destructive DDL deploys autonomously only when the authorization states a runtime-verifiable bound (e.g. "drop only indexes with zero reads in 30 days, confirmed via Insights at run time"). Where the org requires PR approval before deploy, an approved PR satisfies the review gate and the authorization covers only the mechanical deploy.
  • Branch hygiene (weekly): delete development branches older than the authorized age bound with no open deploy request; never touch production or protected branches.
  • Warn-budget gardener (weekly): create warn-mode Traffic Control budgets for newly identified expensive slices matching the allowlist; report warn counts on existing budgets. Enforce mode is never entered autonomously unless the authorization names the specific budget.
  • Credential expiry enforcement (daily): delete or flag passwords past the authorized max age, only where the authorization lists the affected roles and a rotation runbook exists.
Loop anti-patterns
  • Polling MCP on a cron for events webhooks already deliver — use the webhook as the trigger; use cron for baselines, sweeps, and audits.
  • A Tier 2 loop whose allowlist is an intent ("keep things healthy") rather than bounded operations.
  • Loops that mutate without a delivery channel for status.
  • Unbounded fan-out: one run applying every open recommendation at once with no per-run cap.

Query execution safeguards

For read queries:

  • Prefer replicas when available.
  • planetscale_execute_read_query routes reads to replicas by default when a branch has replicas configured (use_replica: true). Set use_replica: false only when the task needs primary-read semantics, such as checking immediately-after-write state or primary-only behavior.
  • Add source tags/comments for agent work.
  • Avoid unbounded scans.
  • Avoid EXPLAIN ANALYZE on production unless explicitly approved.
  • Limit result sizes.
  • Avoid querying sensitive columns unless required and approved.
  • For Postgres tables with row-level security, remember that the MCP read role uses pg_read_all_data and does not bypass RLS. If a read query returns zero rows or a zero count and the MCP response warns that RLS may be filtering results, treat the result as policy-filtered/unknown until confirmed through an approved path; do not conclude the table is empty.
  • When debugging high CPU on Postgres, use Insights data sorted by CPU usage (via MCP where available, or sort=cpuTime on the Insights API). CPU time metrics are Postgres-only; do not ask for the same CPU-sorted view on Vitess.

For write queries:

  • Default is forbidden.
  • If approved, prefer non-production branch.
  • Require exact SQL review.
  • Require rollback plan.
  • Require branch and database name confirmation.

Output

Return:

  • Recommended MCP server choice.
  • Required scopes.
  • AGENTS.md instructions to add.
  • Allowed autonomous work.
  • Disallowed work.
  • Proposed agent loops.
  • Approval gates.

End with:

“No MCP write tools or database mutations have been used.”

© planetscale, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in planetscale-mcp-agent-operating-model of planetscale/skills.

Open the folder on GitHubat commit 999045c

Compare with similar skills

Planetscale MCP Agent Operating Model next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Planetscale MCP Agent Operating Model compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Planetscale MCP Agent Operating Model this skillplanetscale/skills132—~2.4kAutomated safety check: PassMIT
Prod TelemetryUsefulSoftwareCo/executor4.1k—~1.9kAutomated safety check: PassMIT
MCP Server Builderanthropics/skills180k62 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official37k11 repos~3.1kAutomated safety check: PassApache-2.0
Fastmcp Client CLIPrefectHQ/fastmcp28k1 repos~823Automated safety check: PassApache-2.0

Similar skills

  • Prod Telemetry

    UsefulSoftwareCo/executor

    Query Executor's production telemetry — Axiom traces (executor-cloud dataset), prod Postgres via PlanetScale, PostHog product analytics — through the Executor MCP.

    4.1k GitHub stars~1.9k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 62 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    37k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Fastmcp Client CLI

    PrefectHQ/fastmcp

    Query and invoke tools on MCP servers using fastmcp list and fastmcp call.

    28k GitHub starsUsed in 1 repo~823 tokens
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed

More from planetscale/skills

All 15 skills in this repo
  • Official

    Use the PlanetScale CLI (pscale) from automated agents with --format json, auth check, pscale sql, and per-command --force.

    132 GitHub stars~880 tokensUpdated 4 days ago
    Auto-check passed
  • Official

    Master skill that runs the full PlanetScale safe best-practices assessment — inventory, engine review, Insights, Traffic Control, webhooks, schema recommendations, codebase instrumentation, and…

    132 GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed
  • Official

    Execute approved PlanetScale changes end-to-end without per-step approval when the operator has explicitly acknowledged the risk.

    132 GitHub stars~2.6k tokensUpdated 4 days ago
    Auto-check passed
  • Official

    A concise feature matrix for deciding which PlanetScale safety, observability, and automation recommendations apply by engine.

    132 GitHub stars~1.4k tokensUpdated 4 days ago
    Auto-check passed
  • Enforce explicit approval gates for any PlanetScale, database, repository, credential, network, or automation mutation.

    132 GitHub stars~1.3k tokensUpdated 4 days ago
    Auto-check passed
  • Inspect an application repository connected to PlanetScale and recommend SQLCommenter-compatible query tagging packages and conventions.

    132 GitHub stars~1.2k tokensUpdated 4 days ago
    Auto-check passed

Categories

Questions about Planetscale MCP Agent Operating Model

What does Planetscale MCP Agent Operating Model do?

Configure safe agent behavior around PlanetScale MCP, Insights, schema recommendations, and repository work without autonomous production mutation. Planetscale MCP Agent Operating Model is an agent skill from planetscale/skills, published by the product's own GitHub organization. Configure safe agent behavior around PlanetScale MCP, Insights, schema recommendations, and repository work without autonomous production mutation.

When should I use Planetscale MCP Agent Operating Model?

Planetscale MCP Agent Operating Model fits situations like: tasks that involve MCP servers.

How do I install Planetscale MCP Agent Operating Model in Claude Code?

Run `npx skills add planetscale/skills --skill planetscale-mcp-agent-operating-model -a claude-code`. Or copy the skill folder (planetscale-mcp-agent-operating-model in planetscale/skills) into .claude/skills/planetscale-mcp-agent-operating-model in your project. Claude Code loads it when a task matches its description.

How do I install Planetscale MCP Agent Operating Model in Codex?

Run `npx skills add planetscale/skills --skill planetscale-mcp-agent-operating-model -a codex`. Or copy the skill folder (planetscale-mcp-agent-operating-model in planetscale/skills) into .agents/skills/planetscale-mcp-agent-operating-model in your project. Codex loads it when a task matches its description.

Can I use Planetscale MCP Agent Operating Model in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add planetscale/skills --skill planetscale-mcp-agent-operating-model -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/planetscale-mcp-agent-operating-model, .gemini/skills/planetscale-mcp-agent-operating-model, .github/skills/planetscale-mcp-agent-operating-model and .opencode/skills/planetscale-mcp-agent-operating-model in your project.

What does Planetscale MCP Agent Operating Model need to run?

SKILL.md names no scripts, command-line tools or credentials: Planetscale MCP Agent Operating Model is instructions for the agent only.

Does Planetscale MCP Agent Operating Model access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Planetscale MCP Agent Operating Model safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Planetscale MCP Agent Operating Model use?

Planetscale MCP Agent Operating Model is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Planetscale MCP Agent Operating Model use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Planetscale MCP Agent Operating Model?

Skills that share tags, products or a category with Planetscale MCP Agent Operating Model: Prod Telemetry (UsefulSoftwareCo/executor, 4.1k stars), MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars) and MCP Integration for Plugins (anthropics/claude-plugins-official, 37k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Planetscale MCP Agent Operating Model?

planetscale (a GitHub organization, an official publisher) maintains it in planetscale/skills, which has 132 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 3, 2026.

Source: planetscale/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.