Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/vanterx/mssql-performance-skills/sqlmigration-security-reviewnpx skills add vanterx/mssql-performance-skills --skill sqlmigration-security-reviewgit clone --depth 1 https://github.com/vanterx/mssql-performance-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/vanterx/mssql-performance-skills/sqlmigration-security-review)<a href="https://agentmods.dev/skills/vanterx/mssql-performance-skills/sqlmigration-security-review"><img src="https://agentmods.dev/badge/skills/vanterx/mssql-performance-skills/sqlmigration-security-review.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00123 | $0.03304 |
| Opus 5 | $0.00062 | $0.01652 |
| Sonnet 5 | $0.00025 | $0.00661 |
| Haiku 4.5 | $0.00012 | $0.00330 |
Grade A, and why
sqlmigration-security-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 276 lines — stays where its author put it; the contents beside it link to each section on GitHub.
sqlmigration-security-review
Purpose
Reviews the security-object family of a SQL Server migration — the slice sqlmigration-review
dispatches here rather than checking itself. This skill owns 15 checks (J1–J15) covering whether
logins, server/database permissions, credentials, certificate/key ownership, and Central
Management Server (CMS) registrations will survive a backup/restore or log shipping/Always On
AG seeding migration, and what breaks if they don't.
- Login Portability (J1–J5) — orphaned users after restore, SID mismatch, login type unsupported on target platform, password policy differences, default database missing
- Permission Fidelity (J6–J9) — server-level role membership, database-level role membership, explicit GRANT/DENY statements, ownership chains crossing the migration boundary
- Credentials & Secrets (J10–J12) — SQL Server Credential objects, proxy account mapping, linked server stored logins
- Certificates & Keys (J13–J14) — certificate/key migration for objects that depend on them
(excluding TDE, which is
sqlencryption-review's domain), backup of certificates before cutover - CMS (J15) — Central Management Server registration entries pointing at the old instance name
All fix recipes use native T-SQL system views (sys.server_principals, sys.database_principals,
sys.credentials), the in-box SqlServer PowerShell module, and the native sp_help_revlogin
script — no third-party module is referenced or required.
Input
Accepts any of the following:
- Source and target server facts pasted as text — login lists, permission grants, target platform
- Capture script output (
.txt/.csv) — seescripts/capture-security-facts.sql - Natural-language description — "migrating 40 logins, half are Windows groups, target is Azure SQL Database"
- File path to a directory of exported artifacts —
sp_helploginstext dumps, SSMS Generate Scripts output for logins/users
Recommended capture (run on the source instance):
What ships with it
6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 276 lines · 123 tokens per session scan A e285c8d05f42
sqlmigration-security-review is a skill published in the GitHub repository vanterx/mssql-performance-skills (5 stars, last pushed 1mo ago), licensed MIT. It adds 123 tokens to every session and 3,304 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
oracle-expert
Expert in Oracle Database, PL/SQL programming, Oracle RAC, Data Guard, performance tuning, backup/recovery, and enterprise database administration. Use when the user mentions database, enterprise, ERP, PL/SQL, Oracle RAC, or Data Guard, or when the task involves Oracle Architecture, PL/SQL Programming, Performance &…
PostgreSQL Database Administration
Comprehensive PostgreSQL database administration skill for customer support tech enablement, covering database design, optimization, performance tuning, backup/recovery, and advanced query techniques.
schema-exploration
Lists tables, describes columns and data types, identifies foreign key relationships, and maps entity relationships in a database. Use when the user asks about database schema, table structure, column types, what tables exist, ERD, foreign keys, or how entities relate.
sdk-design
Doctrine for designing and evolving any SDK Grida ships — TypeScript, Rust, or otherwise. "SDK" here means a surface that crosses a foreign-or-foreign-treated boundary: published packages, separately-versioned consumers, FFI bindings, public-by-design modules. An SDK's job is to refuse; a strict, honest surface…
ha-data-stores
Map of Hope Agent's local data stores and safe read-only query workflow. Use when the user asks where Hope Agent stores data, wants to inspect sessions/messages/memory/logs/background jobs/knowledge indexes/settings, asks the model to query local app data, or debugging requires checking persisted state. Trigger…
supabase
Supabase / PostgREST Row-Level-Security playbook — pull the anon (or leaked servicerole) key out of the frontend JS, map tables from the auto-generated OpenAPI spec, test anonymous RLS READ disclosures (PII/secret leaks), and anonymous RLS WRITE abuse (insert/update/delete — e.g. forging…