create-readonly-db-role
Installation
SKILL.md
Create a Read-Only DB Role for Agents
Prepare a SELECT-only role and protected connection. The SQL, role name, grants, denylist, RLS behavior, timeouts, and connection steps are examples to adapt to your system, not live production configuration.
Access model
- SELECT-only grants. Grant no write permissions; use a denylist to exclude secrets and PII.
- Current and future tables. Grant SELECT on all tables in
<application_schema>, including future tables through default privileges, then revoke denylisted tables. Never grant the<restricted_schema>schema. New sensitive tables need a manual revoke. - Soft guardrails. Set
default_transaction_read_only = onand a shortstatement_timeoutsuited to the workload.
RLS: tables may return no rows when the role has no applicable policy. Review row-level policies with the database administrator to ensure the role sees only the intended rows.