safe-migration

safe-migration is a skill for Claude Code, Codex from aropan/clist. It costs 76 tokens per session (533 once invoked), scanned A, original, Apache-2.0.

A safe procedure for changing the database structure or data in a Django application. Django is a Python web framework, and migrations record database changes over time.

In plain words
What is it for?
Use it when adding, renaming, or removing Django fields or tables, creating or running migrations, or writing data migrations.
Why use it?
It reduces the risk of losing data or breaking code by encouraging inspection, additive changes, reversible steps, and verification.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/aropan/clist/safe-migration
Any agent
npx skills add aropan/clist --skill safe-migration
Clone the repo
git clone --depth 1 https://github.com/aropan/clist

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for safe-migration

README.md
[![agentmods](https://agentmods.dev/badge/skills/aropan/clist/safe-migration.svg)](https://agentmods.dev/skills/aropan/clist/safe-migration)
Your own site
<a href="https://agentmods.dev/skills/aropan/clist/safe-migration"><img src="https://agentmods.dev/badge/skills/aropan/clist/safe-migration.svg" alt="Measured on agentmods" height="20"></a>
Per session 76 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 533 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00076 $0.00533
Opus 5 $0.00038 $0.00267
Sonnet 5 $0.00015 $0.00107
Haiku 4.5 $0.00008 $0.00053

Measured 5d ago against content hash 11d5d4985cef, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

safe-migration scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.agents/skills/safe-migration/SKILL.md · 54 lines

What it actually says

Safe Django migrations in CLIST

Database changes are the highest-risk edits in this repo. The DB runs in the db container and holds real data. Be conservative.

Procedure

  1. Inspect first. Read the target model in src/<app>/models.py and look at recent migrations in src/<app>/migrations/ to match style.
  2. Find all usages of any field/table you plan to change or remove (grep/search across src/ and legacy/). Removing or renaming something still referenced will break the app.
  3. Prefer additive changes. Add new nullable fields rather than renaming or dropping. For a rename, prefer add-new → backfill → switch readers → remove old, across separate migrations.
  4. Generate, don't hand-write:
    docker compose exec dev ./manage.py makemigrations <app>
    
    Review the generated migration file before applying.
  5. Apply:
    docker compose exec dev ./manage.py migrate <app>
    
  6. Verify the app still imports/serves and relevant tests pass (./manage.py test <app>).

Hard rules

  • Never edit an already-applied historical migration unless explicitly asked. Add a new one instead.
  • Never run DROP / DELETE / TRUNCATE or an irreversible data migration without explicit user approval.
  • Don't rename or drop a column/table without first proving it's unused.
  • If a data migration is needed, make it reversible (RunPython with a reverse function) where feasible, and call out anything that isn't.
  • Treat src/clist/, src/true_coders/, src/my_oauth/, src/ranking/ models as high-traffic — extra care.

When done, report

The migration created, whether it was applied, backward-compatibility risks, and any manual backfill/cleanup step a human still needs to run.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 54 lines · 76 tokens per session scan A 11d5d4985cef

Subscribe to this mod's changes

safe-migration is a skill published in the GitHub repository aropan/clist (440 stars, last pushed 19d ago), licensed Apache-2.0. It adds 76 tokens to every session and 533 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

schema-exploration

Lists tables, describes columns and data types, identifies foreign key relationships, and maps entity relationships in a database. Use when the user asks about database schema, table structure, column types, what tables exist, ERD, foreign keys, or how entities relate.

langchain-ai/deepagents · 57 tokens

ha-data-stores

Map of Hope Agent's local data stores and safe read-only query workflow. Use when the user asks where Hope Agent stores data, wants to inspect sessions/messages/memory/logs/background jobs/knowledge indexes/settings, asks the model to query local app data, or debugging requires checking persisted state. Trigger…

shiwenwen/hope-agent · 115 tokens

supabase

Supabase / PostgREST Row-Level-Security playbook — pull the anon (or leaked servicerole) key out of the frontend JS, map tables from the auto-generated OpenAPI spec, test anonymous RLS READ disclosures (PII/secret leaks), and anonymous RLS WRITE abuse (insert/update/delete — e.g. forging…

PentesterFlow/agent · 120 tokens

dsql

Build with Aurora DSQL — manage schemas, execute queries, handle migrations, diagnose query plans, diagnose cluster performance, load data, and develop applications with a serverless, distributed SQL database. Covers IAM auth, multi-tenant patterns, MySQL-to-DSQL and PostgreSQL-to-DSQL schema conversion, foreign key…

awslabs/agent-plugins · 229 tokens

nw-ddd-eventsourcing

Event Sourcing and CQRS as DDD implementation patterns — when to use, aggregate event streams, projections, snapshots, sagas, upcasting, conflict resolution.

nWave-ai/nWave · 38 tokens

sql-translate

Translate SQL queries between database dialects (Snowflake, BigQuery, PostgreSQL, MySQL, etc.).

AltimateAI/altimate-code · 26 tokens