Official agent skill

Planetscale Postgres Safety Review

by planetscale in planetscale/skills

Review PlanetScale Postgres for Traffic Control, query tags, roles, pgstrict, backups/PITR, private connectivity, webhooks, branches, and safe agent operation.

OfficialMITAuto-check passedDevOps & Cloud

Install Planetscale Postgres Safety Review

skills CLI
$ npx skills add planetscale/skills --skill planetscale-postgres-safety-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install planetscale/skills planetscale-postgres-safety-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/planetscale/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/planetscale-postgres-safety-review .claude/skills/planetscale-postgres-safety-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
planetscale-postgres-safety-review
GitHub stars
132
Token cost
~2.4k tokens
SKILL.md length
1,179 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Review PlanetScale Postgres for Traffic Control, query tags, roles, pgstrict, backups/PITR, private connectivity, webhooks, branches, and safe agent operation.

  • Works in 4 steps: Enable warning mode or evaluate in… → Fix queries that would be blocked. → Enable strict blocking for application… → …
  • Tasks that involve Backup and disaster recovery
  • SKILL.md covers Purpose, Branch and schema workflow, Roles and least privilege and pg_strict, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Planetscale Postgres Safety Review is an agent skill from planetscale/skills, published by the product's own GitHub organization. Review PlanetScale Postgres for Traffic Control, query tags, roles, pgstrict, backups/PITR, private connectivity, webhooks, branches, and safe agent operation.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Backup and disaster recovery and Webhooks. It works with PlanetScale and PostgreSQL. The repository describes itself as: Skills that help you configure and get the most out of PlanetScale. The licence is MIT.

When your agent uses it

  • Tasks that involve Backup and disaster recovery
  • Tasks that involve Webhooks

Example prompts

  • “/planetscale-postgres-safety-review”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Enable warning mode or evaluate in non-production where possible.
  2. Fix queries that would be blocked.
  3. Enable strict blocking for application roles.
  4. Document approved one-off override procedure.

What it can do on your machine

Read from SKILL.md and the folder at commit 999045c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Planetscale Postgres Safety Review loads about 2.4k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 1,179 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from planetscale/skills at commit 999045c, republished under its MIT licence (© planetscale). 1,179 words, ~2,414 tokens.

Download SKILL.mdSave it as .claude/skills/planetscale-postgres-safety-review/SKILL.md (or your agent's skills folder).
name
planetscale-postgres-safety-review
description
Review PlanetScale Postgres for Traffic Control, query tags, roles, pg_strict, backups/PITR, private connectivity, webhooks, branches, and safe agent operation.

Postgres safety review

Purpose

Recommend best practices for a PlanetScale Postgres database. Focus on availability protection, application isolation, recovery, safe automation, and observability. Do not apply changes.

Branch and schema workflow

PlanetScale Postgres branches do not use Vitess-style deploy requests. Schema changes are made directly to each branch, and production schema changes should be managed through the application’s normal migration workflow with a branch validation step.

Check:

  • Whether a development or test branch exists.
  • Whether branches are empty or restored from backup.
  • Whether migrations are tested against a branch before production.
  • Whether application migrations are reversible or have a documented rollback strategy.
  • Whether production DDL is manually reviewed.

Recommend:

  • Create or use a non-production branch for migration testing.
  • Run migration validation and application tests against that branch.
  • Treat production migration application as an explicit human-approved deployment step.
  • Use PITR/backup restore branches for incident recovery, not as an automatic rollback mechanism.

Do not create branches, run migrations, or restore backups without approval.

Roles and least privilege

Check whether the application connects with the default role. Flag this as a safety gap.

Recommend:

  • Use user-defined application roles, not the default role, for application servers.
  • Separate roles by service, environment, and access pattern.
  • Use read-only roles for analytics, dashboards, reporting, and agents that do not need writes.
  • Use short-lived or purpose-limited roles for automation.
  • When Terraform manages PlanetScale Postgres roles, prefer planetscale_postgres_redacted_branch_role for roles whose password should stay out of Terraform state; reset the password through the API or dashboard and store it in the team's secret manager.
  • Document credential rotation without application downtime.

Do not create, reset, delete, or rotate roles without approval.

pg_strict

Check whether pg_strict is enabled for application roles.

Recommend enabling pg_strict for production application roles when the workload can tolerate blocking dangerous UPDATE or DELETE without WHERE.

Recommended rollout:

  1. Enable warning mode or evaluate in non-production where possible.
  2. Fix queries that would be blocked.
  3. Enable strict blocking for application roles.
  4. Document approved one-off override procedure.

Do not enable pg_strict without approval because it can block application queries after new connections are established.

Query Insights and pginsights

Review:

  • Slow queries.
  • High rows-read queries.
  • High CPU query patterns (sort=cpuTime or sort=percentCpuTime on the Insights API).
  • High-frequency queries.
  • Erroring queries.
  • Active anomalies.
  • Query tags.
  • Whether literal/raw query collection is enabled.

Raw query collection is governed by the pginsights.raw_queries cluster parameter, configured per branch in the dashboard Extensions tab. The database API object also carries an insights_raw_queries field; when the two differ, the cluster parameter is the effective collection state. Report the effective state only — never describe the two surfaces as a contradiction or inconsistency.

Recommend:

  • Treat raw query collection as a capability, per ../planetscale-query-insights-and-tags/SKILL.md: when pattern-level data cannot isolate a pathological invocation, raw collection is the mechanism that can. Where the customer's data-handling requirements constrain it, scoped enablement (incident windows, defined retention) and leaving collection disabled are both valid outcomes; record the rationale.
  • Use tags for attribution and raw collection for invocation-level drill-down; they are complementary instruments.
  • Use deploy SHA and route/job tags to correlate regressions with application deploys.

Query tags

Evaluate whether SQL comments contain structured SQLCommenter tags.

Recommend tags that support both Insights and Traffic Control:

  • application
  • service
  • route using normalized route templates, not concrete URLs
  • controller and action where relevant
  • job or queue for background workers
  • feature for expensive features like exports or reports
  • environment
  • release_sha
  • tenant_tier only if cardinality is bounded
  • source for agents, scripts, BI tools, integrations, and MCP

Avoid high-cardinality or sensitive tags:

  • User ID
  • Request ID
  • Email
  • Session ID
  • Tenant ID unless explicitly bounded and accepted
  • Raw URL paths with identifiers
  • Access tokens, secrets, or API keys

Database Traffic Control

For Postgres, recommend Traffic Control when the database has any of these patterns:

  • Public or customer-triggered expensive features.
  • Exports, reports, analytics, or ad hoc search sharing the OLTP database.
  • Background jobs that can starve interactive traffic.
  • Third-party integrations with unpredictable query volume.
  • Agent-generated queries.
  • Known query fingerprints that occasionally run away.
  • Tenant or route classes that need bounded database resource use.

Default recommendation:

  • Start budgets in warn mode.
  • Use query tags where possible.
  • Use fingerprint-specific rules for known offenders.
  • Use enforce mode only after observing warnings and confirming no critical traffic is blocked.
  • Maintain an emergency disable procedure.

Do not create budgets or enforce rules without approval.

Show full SKILL.md (462 more words)Show less

Backups and PITR

Check:

  • Automated backup schedule.
  • Retention window.
  • WAL/PITR availability.
  • Manual backups that prevent deletion.
  • Restore drill history.
  • Recovery runbook.

Recommend:

  • Confirm default backups meet the customer’s RPO/RTO.
  • Increase retention or add backup schedules if the customer’s recovery window exceeds defaults.
  • If Terraform is the customer's source of truth, manage backup policies in Terraform so retention and schedule changes are reviewed with the rest of the infrastructure code.
  • Run a restore drill to a new branch.
  • Document the exact application cutover procedure after restore.

Do not restore or create emergency backups without approval. Emergency backups may affect performance and should be treated as an operational action.

Connections, pooling, and network safety

Check:

  • Whether app uses direct port 5432 or PgBouncer port 6432.
  • Whether connection pool size matches runtime and deployment model.
  • Whether serverless or edge environments can create connection storms.
  • Live connection/session pressure through pscale branch connections top, including blockers and idle-in-transaction sessions when diagnosing active incidents.
  • Whether private connectivity is configured.
  • Whether IP restrictions are configured.
  • Whether public access remains available unexpectedly.

Recommend:

  • Use PgBouncer for high-churn application connections where transaction-pooling limitations are acceptable.
  • Use direct connections for session-dependent features that PgBouncer transaction mode cannot support.
  • Use AWS PrivateLink or GCP Private Service Connect for private network requirements.
  • Use IP restrictions to reduce public exposure.
  • Be explicit that private connectivity does not automatically block public access; IP restrictions or equivalent controls are required for private-only posture.

Do not change network restrictions without approval. Network changes can break application connectivity.

Extensions

Review enabled and available extensions relevant to safety and observability:

  • pginsights
  • pg_strict
  • pg_stat_statements
  • auto_explain
  • pg_squeeze
  • pg_cron
  • pg_partman_bgw
  • pg_hint_plan
  • TimescaleDB, if time-series features are relevant

Recommend extensions only when use case is clear. auto_explain is available for PlanetScale Postgres and can log execution plans for slow queries when configured with parameters such as auto_explain.log_min_duration; recommend it when slow-query plan capture would materially improve diagnosis and the logging volume is acceptable. When Terraform is the customer's source of truth, Postgres branch parameters and supported extensions can be managed there, but parameter or extension changes still require the same approval and restart impact review as dashboard changes. Some extension activation paths require dashboard changes and database restarts; do not enable them without approval.

Webhook recommendations for Postgres

Evaluate and recommend webhooks for:

  • branch.anomaly
  • branch.out_of_memory
  • branch.primary_promoted
  • branch.ready
  • branch.start_maintenance
  • cluster.storage
  • database.access_request
  • branch.schema_recommendation if available
  • webhook.test for setup validation

Recommended automation behavior:

  • Alerts: anomaly, out-of-memory, primary promotion, storage, maintenance.
  • Agent intake: anomaly, schema recommendation.
  • Human approval: any generated Traffic Control, schema, role, or network change.

Output

Return:

  • Current Postgres safety posture.
  • Highest-risk availability gaps.
  • Recommended Traffic Control plan.
  • Recommended role and pg_strict plan.
  • Recommended backup/PITR plan.
  • Recommended network posture plan.
  • Recommended query tagging plan.
  • Proposed changes requiring approval.

End with:

“No Postgres changes have been applied.”

© planetscale, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in planetscale-postgres-safety-review of planetscale/skills.

Open the folder on GitHubat commit 999045c

Compare with similar skills

Planetscale Postgres Safety Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Planetscale Postgres Safety Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Planetscale Postgres Safety Review this skillplanetscale/skills132—~2.4kAutomated safety check: PassMIT
Kopiur Designhome-operations/kopiur113—~2.4kAutomated safety check: PassAGPL-3.0
Supabasemagnus919/agent-skills111—~2.2kAutomated safety check: PassMIT
Mg Local DB Restoremodelguide/modelguide108—~645Automated safety check: PassMIT
Azure Resource Manager Postgresql Dotnetmicrosoft/skills3.1k6 repos~4kAutomated safety check: PassMIT
Database Adminaiskillstore/marketplace4306 repos~2.5kAutomated safety check: PassNone

Similar skills

  • Kopiur Design

    home-operations/kopiur

    Design norms and locked decisions for the Kopiur Kopia-native Kubernetes backup operator (Rust/kube-rs).

    113 GitHub stars~2.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Supabase

    magnus919/agent-skills

    A skill your agent uses when developing applications with Supabase, running the Supabase CLI, designing migrations and RLS policies, testing database behavior, generating client types, deploying the…

    111 GitHub stars~2.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Mg Local DB Restore

    modelguide/modelguide

    Trigger phrases - "reset local db", "recreate local postgres", "restore dump to local", "reset local database", "load backup locally"

    108 GitHub stars~645 tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Azure PostgreSQL Flexible Server SDK for .NET. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 6 repos~4k tokens
    DevOps & CloudAuto-check passed
  • Database Admin

    aiskillstore/marketplace

    Expert database administrator specializing in modern cloud databases, automation, and reliability engineering.

    430 GitHub starsUsed in 6 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Postgres Backup Restore

    fmflurry/settings-opencode

    PostgreSQL backup & restore playbook for the docker instance: pgdump/pgdumpall recipes, WAL archiving + PITR setup (archivemode, archivecommand, recovery.signal, recoverytargettime, timelines)…

    171 GitHub stars~2.3k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from planetscale/skills

All 15 skills in this repo
  • Official

    Use the PlanetScale CLI (pscale) from automated agents with --format json, auth check, pscale sql, and per-command --force.

    132 GitHub stars~880 tokensUpdated 4 days ago
    Auto-check passed
  • Official

    Master skill that runs the full PlanetScale safe best-practices assessment — inventory, engine review, Insights, Traffic Control, webhooks, schema recommendations, codebase instrumentation, and…

    132 GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed
  • Official

    Execute approved PlanetScale changes end-to-end without per-step approval when the operator has explicitly acknowledged the risk.

    132 GitHub stars~2.6k tokensUpdated 4 days ago
    Auto-check passed
  • Official

    A concise feature matrix for deciding which PlanetScale safety, observability, and automation recommendations apply by engine.

    132 GitHub stars~1.4k tokensUpdated 4 days ago
    Auto-check passed
  • Enforce explicit approval gates for any PlanetScale, database, repository, credential, network, or automation mutation.

    132 GitHub stars~1.3k tokensUpdated 4 days ago
    Auto-check passed
  • Inspect an application repository connected to PlanetScale and recommend SQLCommenter-compatible query tagging packages and conventions.

    132 GitHub stars~1.2k tokensUpdated 4 days ago
    Auto-check passed

Questions about Planetscale Postgres Safety Review

What does Planetscale Postgres Safety Review do?

Review PlanetScale Postgres for Traffic Control, query tags, roles, pgstrict, backups/PITR, private connectivity, webhooks, branches, and safe agent operation. Planetscale Postgres Safety Review is an agent skill from planetscale/skills, published by the product's own GitHub organization. Review PlanetScale Postgres for Traffic Control, query tags, roles, pgstrict, backups/PITR, private connectivity, webhooks, branches, and safe agent operation.

When should I use Planetscale Postgres Safety Review?

Planetscale Postgres Safety Review fits situations like: tasks that involve Backup and disaster recovery; tasks that involve Webhooks.

How do I install Planetscale Postgres Safety Review in Claude Code?

Run `npx skills add planetscale/skills --skill planetscale-postgres-safety-review -a claude-code`. Or copy the skill folder (planetscale-postgres-safety-review in planetscale/skills) into .claude/skills/planetscale-postgres-safety-review in your project. Claude Code loads it when a task matches its description.

How do I install Planetscale Postgres Safety Review in Codex?

Run `npx skills add planetscale/skills --skill planetscale-postgres-safety-review -a codex`. Or copy the skill folder (planetscale-postgres-safety-review in planetscale/skills) into .agents/skills/planetscale-postgres-safety-review in your project. Codex loads it when a task matches its description.

Can I use Planetscale Postgres Safety Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add planetscale/skills --skill planetscale-postgres-safety-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/planetscale-postgres-safety-review, .gemini/skills/planetscale-postgres-safety-review, .github/skills/planetscale-postgres-safety-review and .opencode/skills/planetscale-postgres-safety-review in your project.

What does Planetscale Postgres Safety Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Planetscale Postgres Safety Review is instructions for the agent only.

Does Planetscale Postgres Safety Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Planetscale Postgres Safety Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Planetscale Postgres Safety Review use?

Planetscale Postgres Safety Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Planetscale Postgres Safety Review use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Planetscale Postgres Safety Review?

Skills that share tags, products or a category with Planetscale Postgres Safety Review: Kopiur Design (home-operations/kopiur, 113 stars), Supabase (magnus919/agent-skills, 111 stars), Mg Local DB Restore (modelguide/modelguide, 108 stars) and Azure Resource Manager Postgresql Dotnet (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Planetscale Postgres Safety Review?

planetscale (a GitHub organization, an official publisher) maintains it in planetscale/skills, which has 132 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 3, 2026.

Source: planetscale/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.