dbcraft
Design Database Schemas With DB Craft
Database schema design can become fragmented across notes, SQL drafts, and diagrams. DB Craft opens a local visual studio to model tables, validate structure, and export SQL.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "dbcraft" from https://skillstore.io/skills/laozhu001-dbcraft.md and its manifest at https://skillstore.io/api/skills/laozhu001-dbcraft/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "dbcraft". Create a PostgreSQL booking model.
Expected outcome:
DB Craft opens the local studio, creates a booking model, adds core tables, validates the structure, and prepares exportable SQL.
Using "dbcraft". Import my customer table definitions.
Expected outcome:
The skill imports the definitions into the current model, arranges the diagram, flags structure issues, and keeps the workspace model updated.
Using "dbcraft". Prepare this schema for migration review.
Expected outcome:
DB Craft saves the visual model, exports SQL, and creates a clear handoff for a separate migration or deployment workflow.
Security Audit
High RiskMost static hits are false positives from Markdown code spans, loopback URLs, local model filenames, and safety guidance. Confirmed risks remain: the skill can start a local DB Craft service through PowerShell and Node, and AI generation can use OPENAI_API_KEY. I found no prompt injection language or evidence of intentional data exfiltration.
Confirmed security concerns (2)
Capability review items (10)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (37)
🔑 Env variables (4)
Detected Patterns
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/laozhu001-dbcraft/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/laozhu001-dbcraft?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/laozhu001-dbcraft?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/laozhu001-dbcraft/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/laozhu001-dbcraft.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
laozhu001. (2026). dbcraft security audit report (audit version 4) [Author version unspecified]. Skillstore. https://skillstore.io/skills/laozhu001-dbcraft/audits/4BibTeX citation
@techreport{laozhu001-laozhu001-dbcraft-2026,
author = {laozhu001},
title = {dbcraft security audit report (audit version 4)},
institution = {Skillstore},
year = {2026},
number = {4},
url = {https://skillstore.io/skills/laozhu001-dbcraft/audits/4},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "dbcraft security audit report (audit version 4)"
version: "unspecified"
type: report
authors:
- name: "laozhu001"
date-released: "2026-07-05"
url: "https://skillstore.io/skills/laozhu001-dbcraft/audits/4"
identifiers:
- type: other
value: "skillstore:laozhu001-dbcraft:audit:4"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Plan New Service Tables
Create a visual model for a new service, validate table structure, and export SQL for implementation review.
Convert Requirements Into Models
Turn product requirements or screenshots into tables that align frontend data needs with backend storage.
Review Schema Handoffs
Inspect relationships, generated tables, and exported SQL before a separate migration workflow applies changes.
Try These Prompts
Open DB Craft and create a MySQL 8 model for a student management system. Add student, class, and teacher tables.
Open DB Craft and import my existing table definitions into the current workspace model. Validate the structure and organize the diagram.
Use DB Craft AI to design tables for an e-commerce cart, order, and payment workflow. Save the model in the active workspace.
Continue from the current DB Craft handoff, update the model with the requested changes, validate it, export SQL, and summarize deployment notes.
Best Practices
- Keep each project model saved in the active workspace directory.
- Review generated SQL before using it in a real database workflow.
- Use personal API keys carefully and hide secrets from screenshots.
Avoid
- Treating DB Craft output as an automatic production database change.
- Starting duplicate local services before checking the existing service.
- Placing secrets in schema comments, AI prompts, or public screenshots.
Frequently Asked Questions
What is DB Craft?
Which databases are supported?
Does it change a live database?
Is DB Craft a cloud service?
Can AI generation send data outside my machine?
What local requirements are needed?
Developer Details
Author
laozhu001License
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
a25199bc7d6b82598536822d1738eb5d5f54025b
Maintenance freshness
7/18/2026
Usage
7 downloads · 121 views