Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add myths-labs/muse --skill database-reviewergit clone --depth 1 https://github.com/myths-labs/museWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/myths-labs/muse/database-reviewer)<a href="https://agentmods.dev/skills/myths-labs/muse/database-reviewer"><img src="https://agentmods.dev/badge/skills/myths-labs/muse/database-reviewer/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/myths-labs/muse/database-reviewer"><img src="https://agentmods.dev/badge/skills/myths-labs/muse/database-reviewer.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00048 | $0.00326 |
| Opus 5 | $0.00024 | $0.00163 |
| Sonnet 5 | $0.00010 | $0.00065 |
| Haiku 4.5 | $0.00005 | $0.00033 |
Grade A, and why
database-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Database Reviewer Skill
This skill adopts the persona of an expert PostgreSQL/Supabase database specialist.
Usage
Invoking this skill allows you to review SQL schema, optimization, and security issues (especially RLS).
Core Responsibilities
- Query Performance: Index usage, Query Plan Analysis.
- Schema Design: Data Types, Constraints (PK/FK/Check).
- Security (RLS): CRITICAL for Supabase projects. Ensure
(select auth.uid())pattern vsauth.uid()for performance. - Connection Management: Pooling, Timeouts.
Tools
read_resource: (If available) to read Supabase logs or specialized external tools.run_command: To executepsqldiagnostic commands if ENV is configured.view_file: To review.sqlmigration files.
Review Checklist
- RLS enabled on all user-data tables?
- Indexes on all Foreign Keys?
- No N+1 query patterns?
- Lowercase identifiers?
- Secrets/PII encrypted or protected?
Project Specifics
- Supabase: Verify
auth.uid()usage in Policies. - Realtime: Check if Replication is enabled only for necessary tables.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 34 lines · 48 tokens per session scan A 26b02d6c2aaa
database-reviewer is a skill published in the GitHub repository myths-labs/muse (32 stars, last pushed 2d ago), licensed MIT. It adds 48 tokens to every session and 326 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
postgres-supabase
Handles Postgres and Supabase specifics: row-level security policies, auth.uid() and auth.users integration, the supabase CLI migration workflow, PostgREST and schema-cache quirks, and storage bucket policies. Use when the project runs on Supabase, when RLS blocks or leaks rows, or when PostgREST returns a…
db-context-postgres
Validate that a generic Postgres database (GCP Cloud SQL, GKE Autopilot, self-hosted, etc.) is reachable via psql or pgdump, introspect a user-scoped subset of the schema (extensions, tables, columns, indexes, foreign keys, and optionally RLS policies and functions), and persist the result as DBCONTEXT.md inside the…
db-context-supabase
Validate that a Supabase MCP server is reachable, introspect a user-scoped subset of the database (tables, columns, types, RLS policies, optionally functions and recent migrations), and persist the result as DBCONTEXT.md inside the active task folder; adds a single ## DB context cross-link in SOURCEOFTRUTH.md.…
sql_mastery
CREATE OR REPLACE PROCEDURE sprefreshattributiondaily() LANGUAGE plpgsql AS $$ BEGIN -- 1. Truncate Staging TRUNCATE TABLE stgdailytraffic.
supabase-node
Express/Hono with Supabase and Drizzle ORM.
supabase
Core Supabase CLI, migrations, RLS, Edge Functions.