db-truth
Installation
SKILL.md
DB Truth — the database is the only schema authority (repo-agnostic)
Overview
Types, specs, docs, ORMs, and memory are NOT schema truth. Only the database is. The incident record behind this skill: a spec ratified by six agent reviewers assumed a column that didn't exist (reality was a many-to-many junction); a type regen against a stale local DB deleted 211 real production type keys; migration tools have exited success without applying, and applied without recording.
If the current repo has its own .claude/skills/db-truth/ or .agents/skills/db-truth/, that version is authoritative — follow it instead. This global version is the fallback.
Announce at start: "Running /db-truth <pre-work | post-apply> verification."
Part A — Pre-work (before any DB-touching spec, plan, or code)
- Dump the real schema for EVERY table you'll reference. Postgres:
\d <table>via psql, orSELECT column_name, data_type, is_nullable FROM information_schema.columns WHERE table_name='<t>'. Supabase repos: local stack creds viaeval "$(npx supabase status -o env)"; prod read-only via the MCP/dashboard. Paste relevant output into the spec/plan as canonical context — especially for junction tables. - Label every relationship M2M or scalar. If you're writing a singular possessive ("the record's parent") about a junction-linked entity, you have the wrong model. The spec's data-model section must mark each relationship explicitly.
- Check the invisible properties. Row-level security policies and table GRANTs for the operation you're adding (Supabase: new public tables need explicit GRANTs — auto-grants are being phased out). For functions:
CREATE OR REPLACEresets EVERY unrestated property, including security settings likeSET search_path— your replacement must restate them or you silently un-harden production. - Nested JSON writes:
jsonb_set-style patches silently no-op when the parent key is missing. Verify the parent is seeded before targeting a nested key. - Verify claimed call sites. If a plan says "the call happens in X", grep it and cite
file:line. Plans have named wrong injection sites; implementers propagate the error.