Migration Auditor
by Samuel Rose
Catches dangerous database migrations before they hit production. Reviews schema changes for locking hazards, data loss, missing rollbacks, and index issues across PostgreSQL, MySQL, and SQLite.
Secure checkout via Stripe
Works with the AI tools you already use
See it in action
You say
I'm about to deploy a PR that drops the legacy_id column from the orders table and adds an index to the customer_id column on our Postgres 15 database. Can you review these migrations?
Your agent does
Migration Audit: FAIL
- [FAIL] CREATE INDEX: Missing CONCURRENTLY on "orders" (50M rows).
- [WARN] DROP COLUMN "legacy_id": Confirm code isn't reading.
- [FIX] Rewritten migration provided with CONCURRENTLY and two-phase drop strategy for PostgreSQL 15.
What you get
About this skill
Every team has a story about a migration that took down production. A column drop that wasn't actually unused. An index creation that locked a 50M-row table for 20 minutes during peak traffic. A NOT NULL constraint added to a populated table that blew up on deploy.
Migration Auditor catches these before they happen.
Point it at your migration files and it runs a 30+ point checklist covering destructive operations, locking hazards (engine-specific), missing or broken rollbacks, data integrity risks, index issues, migration ordering problems, environment-specific gotchas, and transaction safety.
It doesn't just flag problems. It writes the corrected migration code for you.
Works with Rails, Django, Laravel, Prisma, Drizzle, Knex, TypeORM, Sequelize, Flyway, Liquibase, and raw SQL. Covers PostgreSQL, MySQL/MariaDB, and SQLite with engine-specific rules (because locking behavior between them is completely different).
What it catches that generic code review doesn't:
ADD COLUMN NOT NULL DEFAULT is dangerous on PostgreSQL < 11 but safe on 11+ (fast default). The skill checks your PG version.
CREATE INDEX without CONCURRENTLY blocks writes on large tables. The skill flags this and rewrites it.
MySQL ALTER TABLE copies the entire table for most DDL. On large tables, the skill recommends pt-online-schema-change or gh-ost instead.
Rollbacks that exist but don't actually reverse the forward migration. An empty down method on a destructive migration is a failure, not a pass.
Foreign key constraints added without NOT VALID on PostgreSQL, which locks the table for a full validation scan.
Migrations that are safe on your 50-row dev database but will lock a 50M-row production table for minutes.
Output is a structured audit report with pass/warn/fail for each check, concrete fixes for every issue, and a recommended deploy order if you're running multiple migrations.
How to install
Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.
Reviews
2 people have installed this skill.
Trust & safety
Security scanned
Verified clean 4 months ago
- 30-day refund guarantee
- One-time purchase, yours forever
- Secure checkout via Stripe
Also available in a bundle
Frequently Asked Questions
Popular in Code Review

Senior Web App Architect for Coding Agents
Messy, insecure, unfixable — that's what AI builds without architecture. This file is the architecture: 10 years of senior judgement on rendering, caching, security and SEO, so your agent builds it right from day one.

inline-comment
Best way to steer your agents, effortlessly.
code-reviewer
Reviews your code for bugs, security vulnerabilities, logic errors, performance issues, and style violations. Organizes findings by severity and suggests fixes with code examples.
java-best-practice-checker
Expert Java code auditor for SE 8–24, flagging performance leaks, threading risks, and modernization gaps.