db-truth

Installation
SKILL.md

DB Truth — the database is the only schema authority (repo-agnostic)

Overview

Types, specs, docs, ORMs, and memory are NOT schema truth. Only the database is. The incident record behind this skill: a spec ratified by six agent reviewers assumed a column that didn't exist (reality was a many-to-many junction); a type regen against a stale local DB deleted 211 real production type keys; migration tools have exited success without applying, and applied without recording.

If the current repo has its own .claude/skills/db-truth/ or .agents/skills/db-truth/, that version is authoritative — follow it instead. This global version is the fallback.

Announce at start: "Running /db-truth <pre-work | post-apply> verification."

Part A — Pre-work (before any DB-touching spec, plan, or code)

  1. Dump the real schema for EVERY table you'll reference. Postgres: \d <table> via psql, or SELECT column_name, data_type, is_nullable FROM information_schema.columns WHERE table_name='<t>'. Supabase repos: local stack creds via eval "$(npx supabase status -o env)"; prod read-only via the MCP/dashboard. Paste relevant output into the spec/plan as canonical context — especially for junction tables.
  2. Label every relationship M2M or scalar. If you're writing a singular possessive ("the record's parent") about a junction-linked entity, you have the wrong model. The spec's data-model section must mark each relationship explicitly.
  3. Check the invisible properties. Row-level security policies and table GRANTs for the operation you're adding (Supabase: new public tables need explicit GRANTs — auto-grants are being phased out). For functions: CREATE OR REPLACE resets EVERY unrestated property, including security settings like SET search_path — your replacement must restate them or you silently un-harden production.
  4. Nested JSON writes: jsonb_set-style patches silently no-op when the parent key is missing. Verify the parent is seeded before targeting a nested key.
  5. Verify claimed call sites. If a plan says "the call happens in X", grep it and cite file:line. Plans have named wrong injection sites; implementers propagate the error.

Part B — Post-apply (after every migration)

Installs
2
First Seen
Aug 7, 2026
db-truth — stylusnexus/agent-plugins