Skills mirrord-db-branching
๐Ÿ“ฆ

mirrord-db-branching

v2.7 Content revision r1 High Risk ๐Ÿ”‘ Env variablesโš™๏ธ External commands๐ŸŒ Network access๐Ÿ“ Filesystem access

Configure Isolated Database Branches with mirrord

Shared databases make migration testing and development experiments difficult to isolate. This skill helps configure mirrord branches with separate connections, controlled data copying, and validation guidance.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "mirrord-db-branching" from https://skillstore.io/skills/metalbear-co-mirrord-db-branching.md and its manifest at https://skillstore.io/api/skills/metalbear-co-mirrord-db-branching/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "mirrord-db-branching". Set up an empty PostgreSQL branch using DATABASE_URL.

Expected outcome:

  • The proposed configuration nests database branches under feature and selects PostgreSQL.
  • The connection references DATABASE_URL by name, without including its value.
  • The branch starts empty; validate the configuration with mirrord before starting a session.

Using "mirrord-db-branching". Why does Flyway reject my schema-only branch?

Expected outcome:

  • Schema-only copying transfers table definitions but not migration history rows.
  • Include the Flyway history table in the selected table copies, or start empty and apply migrations from scratch.

Using "mirrord-db-branching". Branch an S3 bucket and copy only fixtures.

Expected outcome:

  • Use the bucket environment variable as the source and select an object pattern anchored to the fixtures prefix.
  • The operator creates the branch bucket in your AWS account; no database pod is created.
  • Review copied security settings, scoped IAM permissions, and provider charges before starting.

Security Audit

High Risk
v1 โ€ข 9/29/2026 Open versioned report

All 400 presented static matches are false positives involving documentation, configuration references, or Kubernetes variable expansion. Two semantic risks remain: credential-bearing diagnostic output and a predictable administrator password in a generic branch example. The analyzer reports 59 additional matches outside this catalog; they still require manual review before automatic publication. Static review was capped at 400/459 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.

4
Files scanned
3,619
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (2)

High
Troubleshooting Can Expose Database Credentials
The troubleshooting command runs `env | grep -iE 'database|postgres|mysql|redis|mongo'` through mirrord, printing matching values rather than names. Database URLs can contain credentials, which may enter terminal logs or an agent transcript without redaction.
The command directly prints matching environment entries without removing their values. Exposure depends on the target environment, but no output redaction is shown.
Medium
Predictable Administrator Password in Branch Example
The generic InfluxDB example sets DOCKER_INFLUXDB_INIT_USERNAME to admin and DOCKER_INFLUXDB_INIT_PASSWORD to mirrord-branch. Reusing this example creates a predictable administrator credential, allowing unauthorized access wherever the branch service is reachable.
The schema description explicitly supplies a fixed administrator username and password in an executable configuration example. Exploitability depends on network reachability and example reuse.

Risk Factors

๐Ÿ”‘ Env variables (31)
โš™๏ธ External commands (50)
references/db-branches-schema.json:4 references/db-branches-schema.json:31 references/db-branches-schema.json:93 references/db-branches-schema.json:116 references/db-branches-schema.json:203 references/db-branches-schema.json:206 references/db-branches-schema.json:242-251 references/db-branches-schema.json:251-278 references/db-branches-schema.json:278 references/db-branches-schema.json:301 references/db-branches-schema.json:326-335 references/db-branches-schema.json:335-362 references/db-branches-schema.json:362 references/db-branches-schema.json:390-429 references/db-branches-schema.json:429-443 references/db-branches-schema.json:443-453 references/db-branches-schema.json:453-464 references/db-branches-schema.json:464-473 references/db-branches-schema.json:473-500 references/db-branches-schema.json:500 references/db-branches-schema.json:541-559 references/db-branches-schema.json:559-568 references/db-branches-schema.json:568-595 references/db-branches-schema.json:595 references/db-branches-schema.json:631-640 references/db-branches-schema.json:640-667 references/db-branches-schema.json:667 references/db-branches-schema.json:696-714 references/db-branches-schema.json:714-723 references/db-branches-schema.json:723-750 references/db-branches-schema.json:750 references/db-branches-schema.json:791-809 references/db-branches-schema.json:809-818 references/db-branches-schema.json:818-845 references/db-branches-schema.json:845 references/db-branches-schema.json:854 references/db-branches-schema.json:894-913 references/db-branches-schema.json:913 references/db-branches-schema.json:923-932 references/db-branches-schema.json:932-959 references/db-branches-schema.json:959 references/db-branches-schema.json:969 references/db-branches-schema.json:1012 references/db-branches-schema.json:1049 references/db-branches-schema.json:1061-1070 references/db-branches-schema.json:1070-1096 references/db-branches-schema.json:1096 references/db-branches-schema.json:1119 references/db-branches-schema.json:1138-1147 references/db-branches-schema.json:1147-1174
๐ŸŒ Network access (16)
๐Ÿ“ Filesystem access (3)
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/metalbear-co-mirrord-db-branching/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/metalbear-co-mirrord-db-branching/security.svg)](https://skillstore.io/skills/metalbear-co-mirrord-db-branching?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/metalbear-co-mirrord-db-branching?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/metalbear-co-mirrord-db-branching/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/metalbear-co-mirrord-db-branching.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

metalbear-co. (2026). mirrord-db-branching security audit report (audit version 1) [Author version 2.7]. Skillstore. https://skillstore.io/skills/metalbear-co-mirrord-db-branching/audits/1

BibTeX citation

@techreport{metalbear-co-metalbear-co-mirrord-db-branching-2026, author = {metalbear-co}, title = {mirrord-db-branching security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/metalbear-co-mirrord-db-branching/audits/1}, note = {Author version 2.7} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "mirrord-db-branching security audit report (audit version 1)" version: "2.7" type: report authors: - name: "metalbear-co" date-released: "2026-09-29" url: "https://skillstore.io/skills/metalbear-co-mirrord-db-branching/audits/1" identifiers: - type: other value: "skillstore:metalbear-co-mirrord-db-branching:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
65
Community
74
Spec Compliance

What You Can Build

Test Application Migrations

Prepare a PostgreSQL or MySQL branch with the required schema and migration history before testing application changes.

Build Focused Test Datasets

Configure engine-specific filters to copy approved records into temporary branches for integration tests.

Standardize Branch Configuration

Review engine prerequisites, IAM sources, generic image policies, and storage settings for shared development clusters.

Try These Prompts

Create an Empty PostgreSQL Branch
Generate a minimal PostgreSQL 16 branch configuration using DATABASE_URL as the variable name. Start empty and explain the prerequisites and validation command.
Copy Selected Test Records
Configure a PostgreSQL schema branch for app_db using DATABASE_URL. Copy users only where email ends with @test.com, and explain compatible copy modes.
Prepare Branch Migrations with IAM
Configure PostgreSQL branching for AWS RDS IAM with Flyway migrations from ./migrations. Preserve migration history when copying schema and reference credentials without displaying values.
Review a Generic Branch Design
Review my generic branch configuration against the bundled schema. Check approved images, copy Job readiness, secret-backed parameters, unique branch IDs, and version compatibility. Propose changes without executing workloads.

Best Practices

  • Confirm engine versions and connection variable names, then validate every generated configuration with mirrord verify-config.
  • Use secret references and approved images; keep credential values out of prompts, configurations, and diagnostic output.
  • Prefer empty or narrowly filtered copies, unique branch IDs, and limited lifetimes for authorized test data.

Avoid

  • Copying full production datasets when schema or approved test records would suffice.
  • Assuming SQL table filters still apply when the copy mode is all.
  • Reusing sample administrator passwords or printing remote environment values during troubleshooting.

Frequently Asked Questions

Which AI tools can use this skill?
The marketplace lists support for Claude, Codex, and Claude Code. Runtime validation and branch operations still require the appropriate local tools and cluster access.
Does remote branching require a paid mirrord feature?
Yes. Remote database branching requires a Team or Enterprise operator license, compatible versions, and the relevant engine feature enabled.
Which databases and services are covered?
Coverage includes MySQL, MariaDB, PostgreSQL, MSSQL, MongoDB, Redis, DynamoDB, ClickHouse, Google Spanner, Amazon S3, and generic container services.
Should I give the assistant my database password?
No. Provide variable names or secret references, not credential values. Avoid diagnostic commands that print complete connection strings.
Can I copy only selected records?
Yes, using engine-specific filters. SQL table filters require empty or schema mode; MongoDB, DynamoDB, Redis, and S3 use different filtering options.
How are branches reused and removed?
Remote branches can be reused by ID until their idle lifetime expires. The default lifetime is five minutes, capped at fifteen. Explicit removal commands are documented.

Developer Details

License

MIT

Author version

v2.7

Skillstore revision

r1

Version notice

The author-declared version is not valid SemVer.

Ref

bad9dafc37d1638cd29cb9bab06d5f8dbcd0f6c2

Maintenance freshness

9/30/2026

Usage

0 downloads ยท 0 views

File structure

๐Ÿ“„ README.md

๐Ÿ“ references/

๐Ÿ“„ db-branches-schema.json

๐Ÿ“„ troubleshooting.md

๐Ÿ“„ SKILL.md

More from metalbear-co

View all
View all