redshift-lineage-from-stl

redshift-lineage-from-stl is a skill for Claude Code from kouko/redshift-comment-mcp. It costs 125 tokens per session (1,658 once invoked), scanned A, original, MIT.

A read-only reconstruction of table-to-table data flow from Amazon Redshift query history. It can reveal queries run by people, dashboards, or other tools that a dbt manifest—a file describing dbt models—does not list.

In plain words
What is it for?
Use it to audit table usage, find dashboard and ad-hoc query consumers, investigate freshness problems, or produce a Mermaid flow diagram.
Why use it?
It helps uncover real users of a table before you change or remove it, while showing that older query history may no longer be available.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the redshift-comment-mcp plugin — 7 skills, 7 commands, 1 MCP server shipped together

Good fit Use it to audit table usage, find dashboard and ad-hoc query consumers, investigate freshness problems, or produce a Mermaid flow diagram.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/kouko/redshift-comment-mcp/redshift-lineage-from-stl
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add kouko/redshift-comment-mcp --skill redshift-lineage-from-stl
Clone the repo
git clone --depth 1 https://github.com/kouko/redshift-comment-mcp

Made for: Claude Code.

Or install redshift-comment-mcp, the plugin that ships this one along with the rest of its 7 skills, 7 commands, 1 MCP server.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for redshift-lineage-from-stl

README.md
[![agentmods](https://agentmods.dev/badge/skills/kouko/redshift-comment-mcp/redshift-lineage-from-stl/github.svg)](https://agentmods.dev/skills/kouko/redshift-comment-mcp/redshift-lineage-from-stl)
Your own site
<a href="https://agentmods.dev/skills/kouko/redshift-comment-mcp/redshift-lineage-from-stl"><img src="https://agentmods.dev/badge/skills/kouko/redshift-comment-mcp/redshift-lineage-from-stl/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for redshift-lineage-from-stl

Your own site · 80×15
<a href="https://agentmods.dev/skills/kouko/redshift-comment-mcp/redshift-lineage-from-stl"><img src="https://agentmods.dev/badge/skills/kouko/redshift-comment-mcp/redshift-lineage-from-stl.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 125 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,658 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00125 $0.01658
Opus 5 $0.00063 $0.00829
Sonnet 5 $0.00025 $0.00332
Haiku 4.5 $0.00013 $0.00166

Measured 10d ago against content hash e97c45ab33b5, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade A, and why

redshift-lineage-from-stl scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.

The scan reads SKILL.md. This mod also ships 2 executable files (assets/parse_stl_lineage_test.py, assets/parse_stl_lineage.py), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/redshift-lineage-from-stl/SKILL.md · 142 lines

How it starts

The opening of the file, as written. The whole thing — 142 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Redshift Lineage from STL_QUERY

Reconstructs actual lineage by mining query history + sqlglot parsing. Ships a helper script — the only one in this plugin that does, justified because LLM-driven SQL parsing is unreliable.

STL retention warning (mention upfront in chat):

  • Provisioned: ~2-5 days; older queries gone.
  • Serverless: longer; uses SYS_QUERY_HISTORY.
  • Permissions: STL needs SYSLOG ACCESS UNRESTRICTED or admin.

When to use / NOT

  • Use to find ad-hoc / BI-tool consumers, audit deprecation candidates, diagnose freshness gaps.
  • NOT for dbt-internal lineage (manifest is authoritative); NOT for declared FKs (use erd); NOT real-time.

Inputs

Form Behavior
--since <date> or --since 7d window (clamped to STL retention)
--table <s>.<t> scope to queries touching this table
--user <name> scope to one user
--limit N cap pulled queries (default 5000)
--include-system keep pg_catalog/STL/etc (default: filter out)
--output mermaid also emit Mermaid graph

Flow

  1. Detect cluster type: execute_sql("SELECT version()"). Look for "Redshift Serverless" → use SYS_QUERY_HISTORY; else STL.

  2. Pull queries — provisioned (STL_QUERY + STL_QUERYTEXT):

    WITH recent AS (
        SELECT q.query, q.userid, q.starttime,
               u.usename AS user_name
        FROM STL_QUERY q LEFT JOIN PG_USER u ON u.usesysid = q.userid
        WHERE q.starttime >= '<since>'::timestamp AND q.aborted = 0
          /* if --user */ AND u.usename = '<user>'
        ORDER BY q.starttime DESC LIMIT <limit>
    )
    SELECT r.query, r.user_name, r.starttime,
           LISTAGG(qt.text, '') WITHIN GROUP (ORDER BY qt.sequence) AS sql_text
    FROM recent r JOIN STL_QUERYTEXT qt ON qt.query = r.query
    GROUP BY r.query, r.user_name, r.starttime;
    

    Caveat: LISTAGG result is VARCHAR(65535) — long queries truncate. Mention to user; truncated SQL parses worse.

    Serverless (SYS_QUERY_HISTORY — full SQL is one column already):

    SELECT query_id AS query, user_id AS user_name,
           start_time AS starttime, query_text AS sql_text
    FROM SYS_QUERY_HISTORY
    WHERE start_time >= '<since>'::timestamp
      AND status NOT IN ('failed', 'aborted')
      /* if --user */ AND user_id = '<user>'
    ORDER BY start_time DESC LIMIT <limit>;
    

Read the full file on GitHub · 142 lines

Files

What ships with it

5 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 10d ago First seen · 142 lines · 125 tokens per session scan A e97c45ab33b5

Subscribe to this mod's changes

redshift-lineage-from-stl is a skill published in the GitHub repository kouko/redshift-comment-mcp (1 stars, last pushed 2mo ago), licensed MIT. It adds 125 tokens to every session and 1,658 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

create-pr

Creates a GitHub PR with a Linear-ticket-prefixed title and a decision-led, narrative description for prisma-next. Use when the user wants to create a pull request, open a PR, or submit changes for review.

prisma/orm · 47 tokens

schema-exploration

Lists tables, describes columns and data types, identifies foreign key relationships, and maps entity relationships in a database. Use when the user asks about database schema, table structure, column types, what tables exist, ERD, foreign keys, or how entities relate.

langchain-ai/deepagents · 57 tokens

ha-data-stores

Map of Hope Agent's local data stores and safe read-only query workflow. Use when the user asks where Hope Agent stores data, wants to inspect sessions/messages/memory/logs/background jobs/knowledge indexes/settings, asks the model to query local app data, or debugging requires checking persisted state. Trigger…

shiwenwen/hope-agent · 115 tokens

supabase

Supabase / PostgREST Row-Level-Security playbook — pull the anon (or leaked servicerole) key out of the frontend JS, map tables from the auto-generated OpenAPI spec, test anonymous RLS READ disclosures (PII/secret leaks), and anonymous RLS WRITE abuse (insert/update/delete — e.g. forging…

PentesterFlow/agent · 120 tokens

nornicdb-cypher-queries

Pick fast, predictable Cypher query shapes in NornicDB — point lookups, batch retrieval, pagination, search, traversal, batched UNWIND/MERGE writes, cleanup, multi-tenant isolation. Use when writing or reviewing Cypher whose latency or throughput matters; maps user intent to the executor's hot-path query templates.

orneryd/NornicDB · 79 tokens

dsql

Build with Aurora DSQL — manage schemas, execute queries, handle migrations, diagnose query plans, diagnose cluster performance, load data, and develop applications with a serverless, distributed SQL database. Covers IAM auth, multi-tenant patterns, MySQL-to-DSQL and PostgreSQL-to-DSQL schema conversion, foreign key…

awslabs/agent-plugins · 229 tokens