Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add evgenii-studitskikh/Claude-Code-SaaS-Studio --skill design-schemagit clone --depth 1 https://github.com/evgenii-studitskikh/Claude-Code-SaaS-StudioWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/evgenii-studitskikh/claude-code-saas-studio/design-schema)<a href="https://agentmods.dev/skills/evgenii-studitskikh/claude-code-saas-studio/design-schema"><img src="https://agentmods.dev/badge/skills/evgenii-studitskikh/claude-code-saas-studio/design-schema.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00037 | $0.00573 |
| Opus 5 | $0.00018 | $0.00287 |
| Sonnet 5 | $0.00007 | $0.00115 |
| Haiku 4.5 | $0.00004 | $0.00057 |
Grade A, and why
design-schema scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 23 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Translate the architecture and PRD into a concrete Postgres schema with Row-Level Security policies, tenant isolation, and a ready-to-apply Supabase migration file. Non-autonomous: the full schema draft is presented and approved before any migration is applied.
Phases
- Load context — read
docs/specs/architecture.md,docs/specs/prd.md, and any existing migration files undersupabase/migrations/. If the architecture doc is missing, stop and direct to/design-architecture. - Draft tables and relations — propose each table with columns, data types, primary keys, foreign keys, and indexes. Note which tables are tenant-scoped (include a
tenant_idcolumn referencing anorganizationsortenantstable). Present the entity-relation summary for the user's review. - Design RLS policies — for every tenant-scoped table, write the RLS
ENABLE ROW LEVEL SECURITYstatement and at least a SELECT, INSERT, UPDATE, and DELETE policy usingauth.uid()and tenant scoping. Explain each policy in plain language. Flag any table that is intentionally public-read or service-role-only. - Review edge cases — check for: missing indexes on foreign keys, cascade-delete implications, enum vs. text trade-offs, and any table that stores PII (flag for encryption or masking consideration). Surface findings; get the user's decisions before locking the schema.
- Write migration draft — fill
.claude/templates/data-model.mdintodocs/specs/data-model.mdand write the migration SQL tosupabase/migrations/{timestamp}_initial_schema.sql. Show both files for approval. Do NOT runsupabase db pushor any database command until the user explicitly approves. Honor the review intensity: underfull, walk through each table and policy for sign-off; underlean, get a single confirmation before writing; undersolo, proceed and summarize after. - Apply (optional) — if the user approves application, run
supabase db pushand verify success. Report the output. Next step: point to/build-feature.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 23 lines · 37 tokens per session scan A b7beec89cd50
design-schema is a skill published in the GitHub repository evgenii-studitskikh/Claude-Code-SaaS-Studio (1 stars, last pushed 2mo ago), licensed MIT. It adds 37 tokens to every session and 573 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
claimable-postgres
Provision instant temporary Postgres databases via Claimable Postgres by Neon (pg.new). No login or credit card required. Use for quick Postgres environments and throwaway DATABASEURL for prototyping.
postgresql-optimization
PostgreSQL database optimization workflow for query tuning, indexing strategies, performance analysis, and production database management.
factory-data-layer
Database schema, ORM, and migration conventions across builds. Drizzle as default with domain-partitioned schema modules, shared timestamps helper, multi-tenancy keys with cascade delete, pgTableCreator prefixing, JSONB for flexible attributes, schema-derived type exports, polymorphic table patterns, ESLint Drizzle…
cloud-sql-postgres-health
Use these skills when you need to audit database health, identify storage bloat, find invalid indexes, analyze table statistics, and manage maintenance configurations like autovacuum.
cloud-sql-postgres-vectorassist
Use these skills to set up and optimize production-ready vector workloads by simply expressing your intent and performance requirements.
neon-postgres
Expert patterns for Neon serverless Postgres, branching, connection pooling, and Prisma/Drizzle integration.