py-alembic-patterns
Review Safer Alembic Migrations
Alembic autogenerate can create migrations that lose data or lock tables. This skill gives practical PostgreSQL patterns for safer schema changes, reviews, testing, and production rollout.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "py-alembic-patterns" from https://skillstore.io/skills/cjharmath-py-alembic-patterns.md and its manifest at https://skillstore.io/api/skills/cjharmath-py-alembic-patterns/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "py-alembic-patterns". A migration renames users.name to users.full_name but autogenerate produced a drop and add.
Expected outcome:
The review flags data loss risk and recommends an explicit column rename. It also asks for a matching downgrade and a migration test.
Using "py-alembic-patterns". A new non-nullable role column must be added to a table that already has rows.
Expected outcome:
The response proposes adding the column as nullable, backfilling existing rows, then applying the not-null constraint in a later step.
Using "py-alembic-patterns". A large events table needs a new index on user_id.
Expected outcome:
The guidance recommends a concurrent index, autocommit considerations, downgrade handling, and a production review for lock behavior.
Security Audit
SafeAll static findings were false positives caused by Markdown code fences, inline-code formatting, and static Alembic or PostgreSQL examples. I found no prompt injection, hidden execution path, credential exfiltration, network abuse, or system reconnaissance intent in SKILL.md.
Risk Factors
⚙️ External commands (24)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/cjharmath-py-alembic-patterns/audits/7?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/cjharmath-py-alembic-patterns?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/cjharmath-py-alembic-patterns?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/cjharmath-py-alembic-patterns/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/cjharmath-py-alembic-patterns.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
CJHarmath. (2026). py-alembic-patterns security audit report (audit version 7) [Author version unspecified]. Skillstore. https://skillstore.io/skills/cjharmath-py-alembic-patterns/audits/7BibTeX citation
@techreport{cjharmath-cjharmath-py-alembic-patterns-2026,
author = {CJHarmath},
title = {py-alembic-patterns security audit report (audit version 7)},
institution = {Skillstore},
year = {2026},
number = {7},
url = {https://skillstore.io/skills/cjharmath-py-alembic-patterns/audits/7},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "py-alembic-patterns security audit report (audit version 7)"
version: "unspecified"
type: report
authors:
- name: "CJHarmath"
date-released: "2026-07-05"
url: "https://skillstore.io/skills/cjharmath-py-alembic-patterns/audits/7"
identifiers:
- type: other
value: "skillstore:cjharmath-py-alembic-patterns:audit:7"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Review an autogenerated migration
Check an Alembic autogenerate result for data-loss patterns, missing names, unsafe constraints, and incomplete downgrade logic.
Plan a production schema change
Design safer PostgreSQL steps for large tables, non-null columns, indexes, enum changes, and data backfills.
Add migration tests to a service
Create test coverage that upgrades, downgrades, and upgrades again to catch broken migration history early.
Try These Prompts
Review this Alembic migration for PostgreSQL safety. Check for data loss, missing downgrade steps, unsafe defaults, and lock risks. Explain the changes I should make.
Help me design an Alembic migration for this schema change. Use PostgreSQL-safe steps, include downgrade behavior, and call out testing requirements.
This Alembic autogenerate output looks risky. Rewrite the migration approach to preserve data, use explicit names, and handle existing rows safely.
Evaluate this migration for production rollout. Consider locks, large-table behavior, concurrent indexes, enum changes, transaction settings, backups, and rollback options.
Best Practices
- Review every autogenerated migration before it reaches production.
- Use explicit names for indexes, foreign keys, constraints, and enum types.
- Test upgrade, downgrade, and upgrade again with realistic data where possible.
Avoid
- Treating a column rename as drop and add without preserving existing data.
- Adding a non-nullable column to a populated table without a backfill plan.
- Applying production migrations without preview, backup, rollback, and lock review.