Install
$ agentstack add skill-nikandr-surkov-ai-saas-starter-db-migration ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Database migration
Applied migrations are immutable history. This skill exists so nobody ever "just edits the SQL file".
Steps
- Ask the user first. Schema changes are on the ASK FIRST list in
AGENTS.md. Describe the change and why.
- Edit
src/db/schema.tsonly. Conventions:
- Every foreign key gets an index.
- Timestamps:
createdAtwithdefaultNow(), timezone-aware. - Money in integer cents; credits in integers.
- Enums via
pgEnum, named_.
- Generate:
pnpm db:generate. Never write migration SQL by hand. - Read the generated file in
drizzle/. Confirm: no unintended
DROP, correct column types/defaults, indexes present. Column renames often generate drop+create — if data must survive, say so and write the migration plan out for the user before applying.
- Apply locally:
pnpm db:migrate(Postgres running via
docker compose up -d).
- Run
pnpm test— the ledger suite will catch schema drift in credit
tables.
- Commit
src/db/schema.tsand the newdrizzle/files together.
Never
- Edit or delete an existing file in
drizzle/. - Run
drizzle-kit pushagainst anything but a throwaway local DB —
this repo uses generated, committed migrations.
- Touch
credit_transactionssemantics (signed integer amounts, UNIQUE
idempotencyKey) without reading .claude/rules/billing.md.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: nikandr-surkov
- Source: nikandr-surkov/ai-saas-starter
- License: MIT
- Homepage: https://ai-saas-starter-six.vercel.app
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.