All skills

Use this Skill: https://skilld.dev/gh/garrytan/gstack/review

This session only. Nothing lands on disk.

specialistsdata-migration.md

≈577 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Data Migration Specialist Review Checklist

Scope: When SCOPE_MIGRATIONS=true Output: JSON objects, one finding per line. Schema: {"severity":"CRITICAL|INFORMATIONAL","confidence":N,"path":"file","line":N,"category":"data-migration","summary":"...","fix":"...","fingerprint":"path:line:data-migration","specialist":"data-migration"} Optional: line, fix, fingerprint, evidence, test_stub. If no findings: output NO FINDINGS and nothing else.


Categories

Reversibility

  • Can this migration be rolled back without data loss?
  • Is there a corresponding down/rollback migration?
  • Does the rollback actually undo the change or just no-op?
  • Would rolling back break the current application code?

Data Loss Risk

  • Dropping columns that still contain data (add deprecation period first)
  • Changing column types that truncate data (varchar(255) → varchar(50))
  • Removing tables without verifying no code references them
  • Renaming columns without updating all references (ORM, raw SQL, views)
  • NOT NULL constraints added to columns with existing NULL values (needs backfill first)

Lock Duration

  • ALTER TABLE on large tables without CONCURRENTLY (PostgreSQL)
  • Adding indexes without CONCURRENTLY on tables with >100K rows
  • Multiple ALTER TABLE statements that could be combined into one lock acquisition
  • Schema changes that acquire exclusive locks during peak traffic hours

Backfill Strategy

  • New NOT NULL columns without DEFAULT value (requires backfill before constraint)
  • New columns with computed defaults that need batch population
  • Missing backfill script or rake task for existing records
  • Backfill that updates all rows at once instead of batching (locks table)

Index Creation

  • CREATE INDEX without CONCURRENTLY on production tables
  • Duplicate indexes (new index covers same columns as existing one)
  • Missing indexes on new foreign key columns
  • Partial indexes where a full index would be more useful (or vice versa)

Multi-Phase Safety

  • Migrations that must be deployed in a specific order with application code
  • Schema changes that break the current running code (deploy code first, then migrate)
  • Migrations that assume a deploy boundary (old code + new schema = crash)
  • Missing feature flag to handle mixed old/new code during rolling deploy

Source: SKILL.md on GitHub

3 warnings3d5 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    The skill performs automated code reviews by executing local scripts and dispatching subagents. It includes logic for autonomous decision-making in specific environments, bypassing human oversight for certain steps. It also transmits telemetry and diff data to external services (Codex) and processes untrusted user-supplied content through a security wrapper.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    2/2 files flagged

  • ZeroLeaks5mo

    2 findings · Score: 54/100

Signed by skilld at dcaea52. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 15 hours ago.

Activeupdated 2 days ago
What it can do
Runs commands Reads files Edits files Network
preamble-tier
4
version
1.0.0
All 9 allowed tools
BashReadEditWriteGrepGlobAgentAskUserQuestionWebSearch
Other metadata
triggers
[
  "review this pr",
  "code review",
  "check my diff",
  "pre-landing review"
]

README badge

README badge for garrytan/gstack/review

Analyzes diffs against the base branch for SQL safety, LLM trust boundary violations, conditional side effects, and other structural issues. Use when reviewing pull requests before landing or merging code changes. Runs preamble checks and proactively suggests review when appropriate.

Generated from the current SKILL.md.

What does this skill check for in a diff?
The skill analyzes diffs against the base branch for SQL safety, LLM trust boundary violations, conditional side effects, and other structural issues.
When should I invoke this skill?
Use it when asked to 'review this PR', 'code review', 'pre-landing review', or 'check my diff'. The skill can also be proactively suggested when you are about to merge or land code changes.
Does this skill work in plan mode?
Yes. In plan mode, the skill takes precedence over generic plan mode behavior and follows its workflow step by step. AskUserQuestion calls satisfy plan mode's end-of-turn requirement.
What tools does this skill use?
The skill uses Bash, Read, Edit, Write, Grep, Glob, Agent, AskUserQuestion, and WebSearch to analyze and review code changes.

Generated from the current SKILL.md. These answers refresh after source changes.