Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add girijashankarj/cursor-handbook --skill migrationgit clone --depth 1 https://github.com/girijashankarj/cursor-handbookWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/girijashankarj/cursor-handbook/migration)<a href="https://agentmods.dev/skills/girijashankarj/cursor-handbook/migration"><img src="https://agentmods.dev/badge/skills/girijashankarj/cursor-handbook/migration/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/girijashankarj/cursor-handbook/migration"><img src="https://agentmods.dev/badge/skills/girijashankarj/cursor-handbook/migration.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00023 | $0.00550 |
| Opus 5 | $0.00012 | $0.00275 |
| Sonnet 5 | $0.00005 | $0.00110 |
| Haiku 4.5 | $0.00002 | $0.00055 |
Grade A, and why
migration scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 65 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Skill: Create Database Migration
Trigger
When the user needs to modify the database schema.
Steps
Step 1: Plan the Change
- Define what's changing and why
- Check for backward compatibility
- Identify affected queries and code
- Determine if data migration is needed
Step 2: Create Migration File
- Name:
YYYYMMDDHHMMSS_descriptive_name.sql - Write UP migration (apply change)
- Write DOWN migration (rollback)
- Include required columns:
{{CONFIG.database.timestampFields.created}},{{CONFIG.database.timestampFields.updated}},{{CONFIG.database.softDeleteField}}
Step 3: Safety Checks
- No
DELETE FROMstatements (soft delete only) - New columns have defaults or are nullable
- Indexes created with
CONCURRENTLYfor large tables - No column renames (add new → migrate → drop old)
- Foreign keys have appropriate cascade rules
Step 4: Data Migration
If needed:
- Write data migration script
- Use batch processing (1000-5000 rows per batch)
- Make it idempotent (safe to re-run)
- Include progress logging
Step 5: Test Migration
- Apply to development database
- Verify data integrity
- Test rollback
- Test with production-like data volume
- Verify affected queries still work
Step 6: Update Code
- Update models/types to match new schema
- Update affected queries
- Run type check:
{{CONFIG.testing.typeCheckCommand}} - Run affected tests
If a step fails
| Step | Failure | Recovery |
|---|---|---|
| Step 2 | Syntax error in migration | Fix SQL; re-run |
| Step 4 | Data migration fails mid-run | Script should be idempotent; fix and re-run; if partial data, document manual cleanup |
| Step 5 | Test migration fails | Run DOWN migration to revert; fix UP migration; retest |
| Step 5 | Rollback test fails | Fix DOWN migration; ensure DOWN fully reverts UP before retrying |
Never apply migrations to production without testing UP and DOWN in a non-prod environment first.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 65 lines · 23 tokens per session scan A f6417ccc501c
migration is a skill published in the GitHub repository girijashankarj/cursor-handbook (30 stars, last pushed 8d ago), licensed MIT. It adds 23 tokens to every session and 550 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
firebase-cloud-firestore
Use when setting up Firestore, designing schemas, doing CRUD, creating listeners, paginating queries, configuring indexes, enabling offline persistence, or writing security rules.
firebase-database
Use when syncing real-time data, structuring JSON trees, reading/writing, creating listeners, enabling offline persistence, managing presence, sharding, or writing security rules.
firebase-data-connect
Use when setting up Data Connect, writing GraphQL queries/mutations, configuring generated SDKs, handling offline, or applying security rules.
audit-db-schema
Audit database schema for consistency, validation, and industry standards. Use when reviewing schema design, naming conventions, constraints, indexes, or migrations. Destructive-op gates → plan-data-integrity. Who-can-read-what RLS → plan-rls-audit. Restore/RPO → plan-backup-dr.
backend-db-performance
Optimize slow queries, indexes, and N+1s. Use when "slow query", "database performance", "add an index", or "N+1". Schema consistency → audit-db-schema. RLS access control → plan-rls-audit.
plan-rls-audit
Audit a Supabase/Postgres project for Row-Level Security and access-control gaps, then produce a phased remediation plan. Use when "RLS", "is my Supabase secure", "anyone can read my data", "lock down my tables". App-layer session/route gates → audit-auth-flows.