Skills subgraph-migrate
๐Ÿ“ฆ

subgraph-migrate

Content revision r1 Critical โš™๏ธ External commands๐ŸŒ Network access

Migrate a Subgraph to Goldsky

Moving from The Graph can require a reliable source identifier, deployment path, and endpoint transition. This skill guides the migration and verifies sync before application cutover.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "subgraph-migrate" from https://skillstore.io/skills/goldsky-io-subgraph-migrate.md and its manifest at https://skillstore.io/api/skills/goldsky-io-subgraph-migrate/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "subgraph-migrate". I have the old public GraphQL endpoint but no IPFS hash.

Expected outcome:

Use the public endpoint migration path. Confirm the endpoint first, deploy the subgraph, and verify indexing before changing the application.

Using "subgraph-migrate". The deployment is stuck at a low synchronization percentage.

Expected outcome:

  • Check the reported network and deployment status.
  • Treat a low percentage as a possible mapping or handler error.
  • Send the exact error to the subgraph troubleshooting workflow.

Using "subgraph-migrate". The migration is synced and I need a stable production endpoint.

Expected outcome:

Create a production tag for the verified version, test its endpoint, then update the application to use the tagged URL.

Security Audit

Critical
v1 โ€ข 9/28/2026 Open versioned report

The 38 external-command findings are false positives caused by Markdown backticks, code fences, and inline command examples in SKILL.md. The installer command at SKILL.md:55 pipes a remote script into a shell and is a confirmed critical supply-chain risk; the three hardcoded URLs are expected service or documentation endpoints, with the installer URL retaining a low network risk.

2
Files scanned
143
Lines analyzed
1
Review items
0
False positives ignored

Confirmed security concerns (1)

Critical
Pipe to shell pattern
curl https://goldsky.com | sh
curl https://goldsky.com | sh executes content fetched from a remote server without local inspection, signature verification, or version pinning. A compromised server or transit path could execute arbitrary commands with the user's shell privileges.
Capability review items (1)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Low
Hardcoded URL
curl https://goldsky.com | sh
The line uses a fixed external URL to download the CLI installer, creating a real network and supply-chain dependency. The critical risk comes from piping that response into a shell, while this verdict records the separate network exposure.

Detected Patterns

Pipe to shell pattern
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/goldsky-io-subgraph-migrate/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/goldsky-io-subgraph-migrate/security.svg)](https://skillstore.io/skills/goldsky-io-subgraph-migrate?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/goldsky-io-subgraph-migrate?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/goldsky-io-subgraph-migrate/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/goldsky-io-subgraph-migrate.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

goldsky-io. (2026). subgraph-migrate security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/goldsky-io-subgraph-migrate/audits/1

BibTeX citation

@techreport{goldsky-io-goldsky-io-subgraph-migrate-2026, author = {goldsky-io}, title = {subgraph-migrate security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/goldsky-io-subgraph-migrate/audits/1}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "subgraph-migrate security audit report (audit version 1)" version: "unspecified" type: report authors: - name: "goldsky-io" date-released: "2026-09-28" url: "https://skillstore.io/skills/goldsky-io-subgraph-migrate/audits/1" identifiers: - type: other value: "skillstore:goldsky-io-subgraph-migrate:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Low
55
Architecture
85
Maintainability
87
Content
65
Community
83
Spec Compliance

What You Can Build

Replace a The Graph endpoint

Move a production subgraph to Goldsky while preserving the existing application query model.

Recover a sunset deployment

Use an existing endpoint or IPFS deployment hash when a former hosted subgraph endpoint is unavailable.

Validate a migration rollout

Deploy, monitor indexing, create a stable tag, and prepare the new endpoint for an application cutover.

Try These Prompts

Start a migration
Help me migrate my subgraph from The Graph to Goldsky. Ask for the current endpoint or IPFS deployment hash before choosing a path.
Choose the source
I have a public GraphQL endpoint, an IPFS deployment hash, and local source. Compare the migration paths and recommend the safest option.
Deploy and verify
Guide me through deploying this subgraph to Goldsky, checking indexing progress, and identifying whether any error requires troubleshooting.
Plan production cutover
Create a production cutover checklist for my Goldsky subgraph, including a stable tag, endpoint validation, rollback considerations, and sync verification.

Best Practices

  • Require the user to provide and verify the source endpoint or IPFS hash.
  • Confirm indexing progress before changing the application endpoint.
  • Use a stable tag so future deployments do not require frontend URL changes.

Avoid

  • Do not guess a The Graph endpoint, IPFS hash, network, or deployment name.
  • Do not declare success before the Goldsky index advances and the endpoint responds.
  • Do not use this workflow to diagnose complex mapping or synchronization errors.

Frequently Asked Questions

What source information is required?
Provide the current GraphQL endpoint, the IPFS deployment hash, or local source when the published deployment is unavailable.
Does migration require subgraph code changes?
The standard migration is a drop-in replacement, but Goldsky validation can expose specification issues that require changes.
Which migration path should I use?
Use the public endpoint when available. Use the IPFS hash when you have the deployment identifier but no queryable endpoint.
How do I know the migration is working?
Check the deployment status and query metadata to confirm that the indexed block advances without indexing errors.
How should I avoid changing my frontend later?
Create a stable Goldsky tag and configure the application to use the tagged endpoint.
What if deployment or sync fails?
Capture the exact error and route it to the subgraph troubleshooting workflow. Do not guess at network or schema changes.

Developer Details

Author

goldsky-io

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

8b5ad1599e7c55e9b6c627bca3f556f6e9061cb1

Maintenance freshness

9/30/2026

Usage

0 downloads ยท 0 views

File structure

๐Ÿ“ evals/

๐Ÿ“„ trigger-eval.json

๐Ÿ“„ SKILL.md

More from goldsky-io

View all
View all