Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add Omar-Obando/qwen-orchestrator --skill database-securitygit clone --depth 1 https://github.com/Omar-Obando/qwen-orchestratorWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/omar-obando/qwen-orchestrator/database-security)<a href="https://agentmods.dev/skills/omar-obando/qwen-orchestrator/database-security"><img src="https://agentmods.dev/badge/skills/omar-obando/qwen-orchestrator/database-security.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00055 | $0.02356 |
| Opus 5 | $0.00028 | $0.01178 |
| Sonnet 5 | $0.00011 | $0.00471 |
| Haiku 4.5 | $0.00006 | $0.00236 |
Grade A, and why
database-security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 321 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Database Security Skill — Database Architect
Overview
This skill provides comprehensive guidance for implementing database security controls. It covers encryption, access control, audit logging, compliance, data masking, row-level security, and database hardening following CISSP and CDP certifications.
When to Use
Use this skill when:
- Implementing database encryption
- Setting up access control and RBAC
- Creating audit logging for databases
- Ensuring compliance (GDPR, HIPAA, PCI-DSS)
- Implementing data masking
- Setting up row-level security
- Encrypting data at rest
- Encrypting data in transit
- Implementing database hardening
- Setting up database monitoring
- Creating database security policies
- Implementing database firewalls
- Setting up database activity monitoring
- Implementing secret management
- Setting up database backups securely
- Implementing database patch management
- Creating database security documentation
- Implementing database vulnerability scanning
- Setting up database security alerts
- Implementing database access review
- Creating database security training
- Implementing database security testing
- Setting up database security governance
- Implementing database security architecture
Do NOT use this skill when:
- Writing application business logic (use domain-driven skill)
- Designing database schemas (use database-design skill)
- Writing API endpoint specifications (use api-design skill)
- Performing security audits (use security-auditor skill)
- Writing SQL queries (use sql-best-practices skill)
- Designing multi-page website layouts (use design-system skill)
- Analyzing deployment configurations (use deployment skill)
- Writing documentation (use documentation-best-practices skill)
Database Security Controls
Encryption
┌─────────────────────────────────────────────────────────────┐
│ Database Encryption │
├─────────────────────────────────────────────────────────────┤
│ Encryption at Rest: │
│ - Database-level encryption │
│ - Table-level encryption │
│ - Column-level encryption │
│ - Filesystem-level encryption │
│ │
│ Encryption in Transit: │
│ - TLS for database connections │
│ - SSL certificates │
│ - Certificate validation │
│ - Certificate pinning │
│ │
│ Encryption Keys: │
│ - Key management service │
│ - Key rotation │
│ - Key access control │
│ - Key audit logging │
└─────────────────────────────────────────────────────────────┘
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 321 lines · 55 tokens per session scan A 108f4409e935
database-security is a skill published in the GitHub repository Omar-Obando/qwen-orchestrator (48 stars, last pushed 2mo ago), licensed MIT. It adds 55 tokens to every session and 2,356 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
warehouse-sql
Review and run read-only natural-language SQL against a customer data warehouse with cached schema introspection and explicit write grants.
architect-agent
A high-level system design expert. Use when: (1) planning new system architectures, (2) designing database schemas, (3) evaluating tech stacks, (4) creating technical design documents (TDD). This agent uses the sqlite-mcp to maintain a persistent architectural log for the project.
data-quality-fixer
A data-quality repair process in which one role proposes database fixes and another independently checks them on a copy before changes are saved.
buckets
Spaces are stateless. All data is wiped on restart / rebuild. For state that must survive (user uploads, generations, dynamic feeds, logs, growing databases): mount an HF Bucket — S3-like object storage living at hf://buckets/ / .
Arquitetura de Sistemas de Dados
Aborda princípios e práticas para projetar sistemas de dados escaláveis e eficientes.
evolve
Start or monitor an evolutionary development loop.