create-readonly-db-role

Installation
SKILL.md

Create a Read-Only DB Role for Agents

Prepare a SELECT-only role and protected connection. The SQL, role name, grants, denylist, RLS behavior, timeouts, and connection steps are examples to adapt to your system, not live production configuration.

Access model

  1. SELECT-only grants. Grant no write permissions; use a denylist to exclude secrets and PII.
  2. Current and future tables. Grant SELECT on all tables in <application_schema>, including future tables through default privileges, then revoke denylisted tables. Never grant the <restricted_schema> schema. New sensitive tables need a manual revoke.
  3. Soft guardrails. Set default_transaction_read_only = on and a short statement_timeout suited to the workload.

RLS: tables may return no rows when the role has no applicable policy. Review row-level policies with the database administrator to ensure the role sees only the intended rows.

Workflow

Installs
174
GitHub Stars
4.1K
First Seen
Jul 10, 2026
create-readonly-db-role — davidondrej/skills