Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add KyaniteLabs/checkyourself --skill 06-multitenancy-rls-isolationgit clone --depth 1 https://github.com/KyaniteLabs/checkyourselfWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/kyanitelabs/checkyourself/06-multitenancy-rls-isolation)<a href="https://agentmods.dev/skills/kyanitelabs/checkyourself/06-multitenancy-rls-isolation"><img src="https://agentmods.dev/badge/skills/kyanitelabs/checkyourself/06-multitenancy-rls-isolation/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/kyanitelabs/checkyourself/06-multitenancy-rls-isolation"><img src="https://agentmods.dev/badge/skills/kyanitelabs/checkyourself/06-multitenancy-rls-isolation.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00080 | $0.01258 |
| Opus 5 | $0.00040 | $0.00629 |
| Sonnet 5 | $0.00016 | $0.00252 |
| Haiku 4.5 | $0.00008 | $0.00126 |
Grade A, and why
multitenancy-rls-isolation scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 108 lines — stays where its author put it; the contents beside it link to each section on GitHub.
multitenancy-rls-isolation
Harden multi-tenant systems with database-enforced isolation, tenant-aware caches, and cross-tenant negative tests.
Operating contract
Act as a production hardening specialist for 06 Tenant Isolation & RLS. Use model-agnostic reasoning: no instruction, output, or workflow in this capability depends on a particular model vendor or agent runtime. Prefer deterministic evidence over persuasive prose. When evidence is missing, name the assumption and make it visible in the output.
When to activate
Use this capability whenever multi-tenancy, tenant isolation, Row-Level Security, shared-schema SaaS, organization-scoped data, tenant_id, database policies, cross-tenant access, or tenant-aware caching appears. Trigger even if the user only says “orgs”, “workspaces”, “teams”, “customers”, or “B2B SaaS”.
Inputs to request or inspect
- tenant model
- database schema
- queries
- auth claims
- cache keys
- service roles
- migration plan
Work protocol
- Classify tenant scope for every table, object, file, cache key, search index, queue, and analytics event.
- Prefer database-enforced tenant isolation for shared-schema relational data. Application filters are not enough for high-risk tenant boundaries.
- Set tenant context transaction-locally where supported, then run queries through roles that cannot bypass isolation.
- Use restrictive write checks so inserts and updates cannot assign data to another tenant.
- Build dual-tenant fixtures and negative tests that prove reads, writes, lists, aggregates, exports, caches, and background jobs cannot cross tenants.
- Create a documented bypass matrix for admin, support, migration, analytics, and break-glass flows.
Required output format
Return a concise report with these sections unless the user requested a concrete file or code diff:
- Scope interpreted — what is in and out.
- Findings / decisions — ordered by production risk, not by discovery order.
- Recommended actions — owner-ready tasks with priority and rationale.
- Verification evidence — tests, scans, contracts, telemetry, commands, or review steps required.
- Residual risk / assumptions — what remains uncertain and how to resolve it.
- Hand-offs — other capabilities that should review the work.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 108 lines · 80 tokens per session scan A a9cfd2cca986
multitenancy-rls-isolation is a skill published in the GitHub repository KyaniteLabs/checkyourself (5 stars, last pushed 3d ago), licensed Apache-2.0. It adds 80 tokens to every session and 1,258 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
postgresql
PostgreSQL schema design, query optimization, indexing, and administration. Use when working with PostgreSQL, JSONB, partitioning, RLS, CTEs, window functions, or EXPLAIN ANALYZE.
redteam-sqli-detail-pack
Domain routing and boundary guidance for authorized SQL injection testing, including union-based, blind, error-based, stacked query, and second-order SQL injection variants. Use when a task belongs to the SQL injection domain and needs scope, evidence, pivot, or exit criteria.
api-canvas
DataCanvas primitive reference — a Tier 3 SQL/analytical workspace for tabular MCP servers, backed by DuckDB. Use when registering tables from upstream APIs, running ad-hoc SQL across them, and exporting results. Covers the acquire → register → query → export flow, per-table TTL, the token-sharing pattern for…
api-mirror
Stand up a persistent, self-refreshing local mirror of a bulk upstream dataset with the MirrorService (@cyanheads/mcp-ts-core/mirror). Use when a server wraps a large or slow API and should query a synced local index (embedded SQLite + FTS5) instead of paginating the live API per request.
codex-log-guard
Diagnose excessive Codex local SQLite diagnostic log writes with read-only evidence by default. Use when a user mentions logs2.sqlite, logs2.sqlite-wal, blockloginserts, SSD/TBW wear, or explicitly asks to protect, clean up, verify, or restore Codex diagnostic logging.
ml-data-pipeline-architecture
Patterns for efficient ML data pipelines using Polars, Arrow, and ClickHouse. TRIGGERS - data pipeline, polars vs pandas, arrow format.