skills/ planetscale/skills

planetscale-readonly-inventory

Collect read-only evidence about PlanetScale org, database, branches, webhooks, backups, roles, Insights, recommendations, and traffic configuration.

0
Installs
—
Rating
—
Success rate
1
Files scanned
Scan passeddatabase
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

1 files scannedscanner v1.2.0Oct 11, 2026

Content sha256 2b0daec54c9b3b9f… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

Read-only inventory

Purpose

Build an evidence-backed inventory of a PlanetScale database without making changes.

Allowed actions

Allowed by default:

  • List organizations, databases, branches, keyspaces, regions, and sizes.
  • Read branch metadata.
  • Read webhook configuration.
  • Read schema recommendations.
  • Read Query Insights, anomalies, and query patterns through MCP or API.
  • Read traffic budgets and rules.
  • Read Postgres roles and non-secret role metadata.
  • Read backup schedules and restore metadata.
  • Read branch schema.
  • Inspect live connection/session metadata with the Connections CLI view.
  • Inspect repository files for frameworks, ORMs, migrations, SQL tagging, and connection config.
  • Inspect Terraform or other infrastructure-as-code definitions for PlanetScale roles, backups, backup policies, Postgres parameters, and supported extensions.

Not allowed without explicit approval:

  • Any create, update, delete, enable, disable, reset, deploy, restore, promote, enforce, or apply operation.
  • Any SQL mutation.
  • Any command that emits new credentials unless the operator explicitly asked for credential work.

Interfaces and documentation grounding

Ground every command and endpoint in the official documentation instead of guessing. PlanetScale publishes agent-readable docs:

Verify an endpoint path in the API reference before calling it. A 404 from an unverified path is a wrong path, not a finding; do not record it as platform state and do not conclude "not configured" from it.

Verified interface notes (recheck against the docs when a command fails):

  • pscale database show <database> --org <org> — the org is a flag, not a positional argument.
  • pscale api <path> takes org-relative paths such as organizations/{org}/databases/{db}/branches/{branch} — there is no get subcommand and no /v1/ prefix. Pass query parameters with -Q key=value flags; embedding ?/& in the path breaks under shell globbing.
  • pscale webhook list <database> --org <org> — the database is a positional argument. pscale backup list <database> <branch> requires the branch.
  • pscale branch connections top <database> <branch> — live read-only session inventory works for Postgres and Vitess over a reserved administrative connection. Do not cancel queries or terminate connections unless the operator explicitly approves that operational action.
  • Query Insights is public API. Live query telemetry: .../branches/{branch}/insights (per-pattern statistics; supports from/to/period, q, sort, dir, tablet_type, type, fields, and pagination). Related endpoints under the same branch path: insights/errors, insights/anomalies, insights/tags, insights/tags/summaries, insights/{fingerprint} (individual executions), insights/{fingerprint}/summary, and insights/{fingerprint}/traffic/budgets. The query-patterns path returns generated report metadata, not live patterns.
  • Traffic budgets: .../branches/{branch}/traffic/budgets. The CLI has no pscale traffic-control budget list; use the API for inventory.
  • Postgres roles: list via .../branches/{branch}/roles; fetch a single role by ID, not name (pscale role get <db> <branch> <role-id>).
  • IP restrictions: database-level organizations/{org}/databases/{db}/cidrs. Branch-level IP-restriction paths are not valid.
  • Schema recommendations: database-level .../databases/{db}/schema-recommendations (the branch-level path is not valid). Requesting page=2 currently returns 404 even when the response reports next_page; use the database object's open_schema_recommendations_count as the authoritative total, treat the returned page as a sample, and state in the report when the itemized list covers only part of the total.
  • PITR state and branch-level backup policies have no verified read path; record backup posture from pscale backup list and the database-level backup policy, and mark PITR "not assessed in this run" rather than probing paths.
  • List endpoints paginate; follow the pagination parameters until exhausted before reporting counts (except the schema-recommendations case above).

Record access failures (403s, missing token scopes, timeouts) in the internal run log for the operator. They are not findings and do not enter the customer report (see ../planetscale-customer-report-template/SKILL.md).

Inventory checklist

Database identity

Record:

  • Organization.
  • Database.
  • Branch.
  • Engine: Vitess or Postgres.
  • Region and cloud provider.
  • Production/development branch status.
  • Branch protection and safe workflow state.
  • Size and cluster shape.

Branches and schema workflow

For Vitess, record:

  • Production branch.
  • Whether safe migrations are enabled for production and staging branches.
  • Open deploy requests.
  • Deploy request approval setting.
  • Pending schema changes.
  • Whether branch strategy has a staging branch with safe migrations enabled.

For Postgres, record:

  • Branch list.
  • Whether branches were created from backup or empty.
  • Whether schema changes are managed manually, through migrations, or through an ORM.
  • Whether a separate branch is used for migration testing.
  • Whether the team expects Vitess-style deploy requests; if yes, flag that Postgres branches do not use deploy requests in the same way.

Observability

Record:

  • Insights availability.
  • Whether query tags are present.
  • Which tags appear.
  • Whether high-cardinality tags are present.
  • Whether complete/raw query collection is enabled.
  • Active anomalies.
  • Query patterns with high latency, high rows read, high error rate, or high execution count.
  • Postgres CPU-heavy query patterns and Vitess vindex-usage data when exposed by the Insights interface in use.
  • Whether application deploy identifiers are visible in comments or tags.

Recommendations

Record:

  • Open schema recommendations.
  • Recommendation type.
  • Affected table/query.
  • Proposed DDL or action.
  • Whether a branch/deploy workflow exists to evaluate it safely.
  • Whether the recommendation can be implemented as application code, ORM migration, or database DDL.

Webhooks and automation

Record:

  • Configured webhooks.
  • Subscribed events.
  • Enabled state.
  • Last delivery success or failure.
  • Destination category: Slack, PagerDuty, internal automation, CI, agent queue, unknown.
  • Whether webhook signature verification is documented or implemented.
  • Whether webhook handling is idempotent and asynchronous.

Postgres Traffic Control

For Postgres only, record:

  • Existing budgets and rules.
  • Budget modes: off, warn, enforce.
  • Limits: rate, capacity, burst, concurrency, warning threshold.
  • Rules by fingerprint, keyspace, query kind, or tags.
  • Whether rules are tied to meaningful SQLCommenter tags.
  • Whether any production budget is in enforce mode.

Postgres safety

For Postgres only, record:

  • Application role usage.
  • Whether apps use the default role.
  • Whether app roles are least-privilege.
  • Whether pg_strict is enabled for application roles.
  • Whether PgBouncer is used for appropriate workloads.
  • Whether live connections show blockers, idle-in-transaction sessions, or connection saturation during an active incident.
  • Whether private connectivity and IP restrictions are configured.
  • Whether backup retention and PITR meet the customer’s recovery expectations.

Vitess safety

For Vitess only, record:

  • Safe migrations state.
  • Deploy request workflow.
  • Admin approval requirement.
  • Gated deployment usage.
  • Schema revert availability.
  • Branch and keyspace topology.
  • Sharding/vschema status.
  • Whether sharded query patterns use relevant vindexes.
  • Backups and restore posture.

Evidence format

For every finding, include evidence:

  • Source: MCP, CLI, API, dashboard-observed, SQL read-only, repository file.
  • Path or command used.
  • Timestamp.
  • Raw value or concise excerpt.
  • Confidence: high, medium, low.

Output

Return:

  • Inventory table.
  • Missing evidence table.
  • Risk flags.
  • Recommended next skills to run.

End with:

“No changes have been applied.”

Files

1
8.4 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from planetscale/skills8

planetscale-autonomous-execution-mode

Execute approved PlanetScale changes end-to-end without per-step approval when the operator has explicitly acknowledged the risk. Defines the risk-acknowledgment contract, scoped autonomy levels, sensible execution ordering, continuous status reporting, halt conditions, and rollback discipline. Extr

Scan passed 0
planetscale-best-practices-matrix

A concise feature matrix for deciding which PlanetScale safety, observability, and automation recommendations apply by engine.

Scan passed 0
planetscale-change-gates-and-approval-contract

Enforce explicit approval gates for any PlanetScale, database, repository, credential, network, or automation mutation.

Scan passed 0
planetscale-codebase-sqlcommenter-instrumentation

Inspect an application repository connected to PlanetScale and recommend SQLCommenter-compatible query tagging packages and conventions.

Scan passed 0
planetscale-customer-report-template

Produce the final PlanetScale best-practices report after running the inventory and relevant review skills.

Scan passed 0
planetscale-mcp-agent-operating-model

Configure safe agent behavior around PlanetScale MCP, Insights, schema recommendations, and repository work without autonomous production mutation.

Scan passed 0
planetscale-postgres-safety-review

Review PlanetScale Postgres for Traffic Control, query tags, roles, pg_strict, backups/PITR, private connectivity, webhooks, branches, and safe agent operation.

Scan passed 0
planetscale-pscale-cli-automation

Use the PlanetScale CLI (pscale) from automated agents with --format json, auth check, pscale sql, and per-command --force. Run before other PlanetScale skills when driving pscale directly. Use when the user asks to automate pscale, run CLI commands headless, or verify pscale auth from an agent.

Scan passed 0

Related database skillsscan passed

jpa-patterns

JPA/Hibernate patterns for entity design, relationships, query optimization, transactions, auditing, indexing, pagination, and pooling in Spring Boot. Use when designing JPA entities or relationships, or when a Hibernate query, transaction, or N+1 problem needs fixing.

Scan passed 0
stripe-projects

Use when the user wants to provision infrastructure or third-party services using Stripe Projects. Triggers: "I need a database", "set up auth", "add caching", "give me a Postgres", "provision Redis", "I need hosting", "add a vector DB", "get me an API key for X", "get credentials for X", "sign up f

Scan passed 0
cloudflare-one-migrations

Assess and plan migrations from existing VPN, SWG, or SASE platforms to Cloudflare One, including policy mapping, parity gaps, and rollout.

Scan passed 0
deprecation-and-migration

Manages deprecation and migration. Use when removing old systems, APIs, or features. Use when migrating users from one implementation to another. Use when migrating a database schema in production, such as renaming or dropping a column without downtime (expand/contract). Use when deciding whether to

Scan passed 0
firebase-data-connect

Builds and deploys Firebase SQL Connect (aka Firebase Data Connect) backends with PostgreSQL securely. Use when designing schemas with tables and relations, writing authorized queries and mutations, configuring real-time data updates, or generating type-safe SDKs. Use when you need a relational data

Scan passed 0
migrating-to-amazon-redshift

Guides an end-to-end data-warehouse migration to Amazon Redshift — discovery, schema/SQL/stored-procedure/macro/script conversion, data migration, validation, performance comparison, and reporting. Source-routed via `references/<source>/`; Teradata (Vantage) is the supported source; additional sourc

Scan passed 0