skills/ planetscale/skills

planetscale-traffic-control-recommendations

Build a safe recommendation plan for PlanetScale Postgres Database Traffic Control budgets and rules without applying them.

0
Installs
—
Rating
—
Success rate
1
Files scanned
Scan passeddatabase
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

1 files scannedscanner v1.2.0Oct 11, 2026

Content sha256 47b1a25a966b1317… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

Database Traffic Control recommendations

Purpose

For PlanetScale Postgres, recommend Traffic Control budgets and rules that protect critical traffic from runaway queries, traffic spikes, batch jobs, agents, and third-party integrations. Do not create or change budgets without approval.

Preconditions

Run this skill only for PlanetScale Postgres.

Before recommending rules, inspect:

  • Current budgets and rules.
  • Insights query patterns.
  • Current query tags.
  • Application routes and jobs.
  • Known critical paths.
  • Known expensive non-critical paths.
  • Active incidents or recent anomalies.

If query tags are missing, recommend tagging first unless a fingerprint-specific rule is clearly needed for an immediate known offender.

Candidate traffic slices

Look for:

  • Exports.
  • Reports.
  • Search endpoints.
  • Admin dashboards.
  • Backfills.
  • Workers and queues.
  • Webhooks from third-party systems.
  • BI tools.
  • Agent-generated read queries.
  • High-frequency polling.
  • Known expensive query fingerprints.
  • Customer-triggered endpoints with high variance.

Budget modes

Recommend in this order:

  1. warn mode first for normal rollout.
  2. Observe warnings and false positives.
  3. Tune tags, fingerprints, and thresholds.
  4. Move to enforce only with explicit approval and an emergency rollback path.

Do not recommend starting directly in enforce unless there is an active incident and the operator explicitly asks for emergency mitigation.

Rule strategy

Prefer tag-based rules when tags are stable and bounded:

  • source=agent
  • source=bi
  • feature=export
  • feature=report
  • route=/admin/reports
  • job=DailyBackfill
  • service=analytics-worker

Use fingerprint rules when:

  • A specific known query pattern is dangerous.
  • Tagging is missing or unreliable.
  • The query source is hard to attribute.

Use a separate budget for each materially different traffic class.

Do not combine unrelated traffic in one budget because it hides who is consuming the budget.

Suggested default budgets

Use these as recommendation patterns, not as values to apply blindly.

Agent budget

Target: queries tagged source=agent or source=mcp.

Intent: prevent agents from starving application traffic.

Mode: start in warn.

Recommendation: agents should prefer replicas and read-only scopes. Writes require human approval.

Export/reporting budget

Target: feature=export, feature=report, or specific report route/job.

Intent: keep customer-triggered reporting from consuming all database resources.

Mode: start in warn; consider enforce after observation.

Background job budget

Target: worker service, queue, or job tags.

Intent: prevent backfills and retries from starving interactive traffic.

Mode: warn first; enforce only after confirming queue backpressure behavior.

Third-party integration budget

Target: source=integration, partner-specific bounded tags, or route templates for inbound integration calls.

Intent: isolate unpredictable partner behavior.

Mode: warn first.

Known fingerprint budget

Target: specific expensive query fingerprint.

Intent: contain a known pathological query while code or schema fixes are developed.

Mode: warn first unless emergency.

“Each tag value” strategy

When PlanetScale supports applying a budget separately for each unique value of a selected tag, recommend it for bounded tags such as:

  • application
  • service
  • route when normalized
  • job
  • feature
  • source

Do not recommend it for unbounded tags such as user IDs, request IDs, raw tenant IDs, emails, UUIDs, or raw URLs.

Limits and caveats to include

Every recommendation must explain:

  • Traffic Control limits resource use; it does not replace query tuning.
  • It is not a web application firewall.
  • It does not replace application-level rate limits.
  • Limits are guardrails, not exact guarantees for every failure mode.
  • Bad tags create bad rules.
  • Enforce mode can reject queries and affect application behavior.

Output format

For each proposed budget:

  • Budget name.
  • Target branch.
  • Mode: off, warn, or enforce.
  • Matched traffic slice.
  • Rule type: tag, fingerprint, keyspace, query kind.
  • Proposed tags or fingerprint.
  • Limit rationale.
  • Queries seen in Insights that justify it.
  • Safety risk.
  • Test/observe plan.
  • Rollback plan.
  • Approval requirement.

End with:

“No Traffic Control budgets or rules have been created, updated, deleted, or enforced.”

Files

1
4.6 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from planetscale/skills8

planetscale-autonomous-execution-mode

Execute approved PlanetScale changes end-to-end without per-step approval when the operator has explicitly acknowledged the risk. Defines the risk-acknowledgment contract, scoped autonomy levels, sensible execution ordering, continuous status reporting, halt conditions, and rollback discipline. Extr

Scan passed 0
planetscale-best-practices-matrix

A concise feature matrix for deciding which PlanetScale safety, observability, and automation recommendations apply by engine.

Scan passed 0
planetscale-change-gates-and-approval-contract

Enforce explicit approval gates for any PlanetScale, database, repository, credential, network, or automation mutation.

Scan passed 0
planetscale-codebase-sqlcommenter-instrumentation

Inspect an application repository connected to PlanetScale and recommend SQLCommenter-compatible query tagging packages and conventions.

Scan passed 0
planetscale-customer-report-template

Produce the final PlanetScale best-practices report after running the inventory and relevant review skills.

Scan passed 0
planetscale-mcp-agent-operating-model

Configure safe agent behavior around PlanetScale MCP, Insights, schema recommendations, and repository work without autonomous production mutation.

Scan passed 0
planetscale-postgres-safety-review

Review PlanetScale Postgres for Traffic Control, query tags, roles, pg_strict, backups/PITR, private connectivity, webhooks, branches, and safe agent operation.

Scan passed 0
planetscale-pscale-cli-automation

Use the PlanetScale CLI (pscale) from automated agents with --format json, auth check, pscale sql, and per-command --force. Run before other PlanetScale skills when driving pscale directly. Use when the user asks to automate pscale, run CLI commands headless, or verify pscale auth from an agent.

Scan passed 0

Related database skillsscan passed

scientific-db-pubmed-database

Direct PubMed and NCBI E-utilities search workflows for biomedical literature, MeSH queries, PMID lookup, citation retrieval, and API-backed literature monitoring. Use when a task needs biomedical literature from PubMed rather than general web search.

Scan passed 0
stripe-projects

Use when the user wants to provision infrastructure or third-party services using Stripe Projects. Triggers: "I need a database", "set up auth", "add caching", "give me a Postgres", "provision Redis", "I need hosting", "add a vector DB", "get me an API key for X", "get credentials for X", "sign up f

Scan passed 0
basin

Build and troubleshoot Cloudflare Basin analytics workflows with Basin Pipelines, Basin Catalog, and Basin SQL. Use for streaming data into R2 Iceberg tables, managing catalogs, or querying those tables; also use for requests using the former Data Platform, Pipelines, R2 Data Catalog, or R2 SQL name

Scan passed 0
deprecation-and-migration

Manages deprecation and migration. Use when removing old systems, APIs, or features. Use when migrating users from one implementation to another. Use when migrating a database schema in production, such as renaming or dropping a column without downtime (expand/contract). Use when deciding whether to

Scan passed 0
firebase-firestore

Sets up, manages, queries, and configures Cloud Firestore databases (Standard/Enterprise edition), including data modeling, security rules, indexes, and SDK integrations (Web, Python, iOS, Android, Flutter). Use when creating/listing Firestore databases, defining data models/indexes, writing SDK que

Scan passed 0
exploring-data-catalog

Full inventory and audit of AWS Glue Data Catalog assets across S3 Tables, Redshift-federated, and remote Iceberg catalogs. Triggers on: inventory the catalog, audit databases, list all tables, catalog overview, data landscape, enumerate catalogs, data inventory, search the catalog. Do NOT use for f

Scan passed 0