Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/hackbyrd/orbital-express/add-migrationnpx skills add Hackbyrd/orbital-express --skill add-migrationgit clone --depth 1 https://github.com/Hackbyrd/orbital-expressWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00065 | $0.01192 |
| Opus 5 | $0.00032 | $0.00596 |
| Sonnet 5 | $0.00013 | $0.00238 |
| Haiku 4.5 | $0.00006 | $0.00119 |
Grade A, and why
add-migration scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 44 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Write a migration
Migrations are the source of truth for the real database (dev/prod). The test DB is built from the models via sync, so when you add a column also add it to the model. Read README "Migrations" + "Database Conventions".
Before generating or editing, plan the schema, constraints, indexes, backfill, rollback, model changes, and fixture impact and get sign-off. For feature work, confirm the complete feature folder with yarn repair <Feature> --dry-run, then yarn repair <Feature>; repair never overwrites.
Filename convention (critical — it documents the change)
- New table:
<timestamp>-create-<Model>-model.js(Model singular PascalCase) - Alter table:
<timestamp>-add-cols-<colA>-and-<colB>-to-<TablePlural>-tbl.js - Add index:
<timestamp>-add-index-<colA>_<colB>-to-<TablePlural>-tbl.js
Generate the file, then fill it. Two documented ways (both produce a timestamped file you then rename to the convention above):
yarn model— for a NEW table;yarn migration— for ALTERing a table. Both create a generically-named file inmigrations/— rename it to the convention.- Or call the CLI directly with the right name (no rename needed):
./node_modules/.bin/sequelize migration:create --name create-<Model>-model ./node_modules/.bin/sequelize migration:create --name add-cols-<col>-to-<TablePlural>-tbl
Rules
- Wrap
upanddowninqueryInterface.sequelize.transaction(async t => { ... }, { transaction: t })on every call. - Never delete columns/tables or rename in place (rollback safety). To rename: add new column, copy data, drop the old one much later. We don't auto-destroy data.
- IDs:
DataTypes.UUIDwith no DB-level default (the model'sdefaultValue: () => uuidv7()always provides the ID before insert). FK column types must match the referenced PK type. - Named indexes,
{Table}_{col}_{idx|unique}, matching the model'sindexesarray exactly.{Table}is the exact explicit static PascalCase pluraltableName, including irregular plurals—not naive<Feature>s.addIndex(table, [cols], { name, unique, transaction: t }). - Foreign keys:
references: { model, key }, explicitonDelete/onUpdate. For self-referencing or composite FKs useaddConstraint(table, { fields, type:'foreign key', name, references:{ table, field }, onDelete, onUpdate, transaction: t }). - Flattened ownership: when data is nested, carry every ancestor's id onto the descendant — not just the immediate parent, but the parent's parent, on up to the top-level owner (e.g.
userId). It looks redundant on purpose: it flattens the hierarchy so you can query "all X for any ancestor" (and scope security touserId) as a single indexedwherewith no joins. The duplication can't drift because a composite FK enforces it (parent needs aUNIQUE (id, userId); child FKs(parentId, userId)→ parent(id, userId), so Postgres rejects any mismatch). See README "Carry the Owner Foreign Key Down to Every Descendant". - You may (and are encouraged to) run data-backfill SQL in the migration after
addColumn— e.g. populate a new NOT NULL column from an existing one so it's ready immediately, instead of a separate script. - Column order in
createTableattrs: id → FKs → vendor IDs → custom →deletedAt/createdAt/updatedAt. - Timestamps: all times are UTC.
createdAt/updatedAt/deletedAtare auto-managed by the model (timestamps: true) but must be defined explicitly in the migration attrs. - ENUMs: type name is ALL CAPS, no underscores/spaces/dashes (e.g.
ORDERSTATUS); values are ALL_CAPS_WITH_UNDERSCORES (e.g.PENDING_REVIEW). Keep ENUM values in sync with the matchingconstants.jsarray. - Booleans
is/has/can/does; FK cols<entity>Id; vendor IDs prefixed. - Add-index migration filename:
<timestamp>-add-index-<colA>_<colB>-to-<TablePlural>-tbl.js.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 44 lines · 65 tokens per session scan A f287cfe0ab48
add-migration is a skill published in the GitHub repository Hackbyrd/orbital-express (14 stars, last pushed 14d ago), licensed MIT. It adds 65 tokens to every session and 1,192 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
db-repair
Auto-fix gbrain's Postgres access so the brain stays available. When any gbrain command or MCP tool result carries a GBRAINDBACCESS marker (or an operator reports the brain database is down), run the hardcoded gbrain db-repair ladder: diagnose, apply the safe tier, verify. The action is ALWAYS the hardcoded command …
postgres-pro
Use when optimizing PostgreSQL queries, configuring replication, or implementing advanced database features. Invoke for EXPLAIN analysis, JSONB operations, extension usage, VACUUM tuning, performance monitoring.
postgres-database-migration
Use this skill for planning, testing, and safely executing PostgreSQL schema migrations — especially when working with production data or shared databases. Trigger when user asks to: Test a schema migration before applying it to production Add, remove, or rename columns safely on a live table Change a column's data…
setup-timescaledb-hypertables
Use this skill when creating database schemas or tables for Timescale, TimescaleDB, TigerData, or Tiger Cloud, especially for time-series, IoT, metrics, events, or log data. Use this to improve the performance of any insert-heavy table. Trigger when user asks to: Create or design SQL schemas/tables AND…
claimable-postgres
Provision instant temporary Postgres databases via Claimable Postgres by Neon (neon.new) with no login, signup, or credit card. Supports REST API, CLI, and SDK. Use when users ask for a quick Postgres environment, a throwaway DATABASEURL for prototyping/tests, or "just give me a DB now". Triggers include: "quick…
dsql
Build with Aurora DSQL — manage schemas, execute queries, handle migrations, diagnose query plans, diagnose cluster performance, load data, and develop applications with a serverless, distributed SQL database. Covers IAM auth, multi-tenant patterns, MySQL-to-DSQL and PostgreSQL-to-DSQL schema conversion, FK…