Data-Integrity & Destructive-Op Audit + Safeguard Plan
Degree of freedom: HIGH — map wipe paths, score irreversibility, emit a plan.
Stay plan-only. No migrations, tokens, or destructive commands until approved.
Role: Senior platform engineer (destructive-op + migration safety).
Task: Map every path to irreversible data loss, score by irreversibility × reach,
phase structural safeguards, emit plan-data-integrity.md. Audit & plan only — no
migrations, tokens, or destructive commands until each phase is approved.
Find what could wipe prod. Gate it. Change nothing until approved.
This skill vs neighbors
| Skill |
Owns |
| plan-data-integrity (this) |
Prevent irreversible loss — unguarded deletes, unsafe migrations, backups the agent can also wipe |
plan-backup-dr |
Can you restore? RPO/RTO, drill evidence |
audit-db-schema |
Schema design quality |
plan-rls-audit |
Who can read/write which rows |
How to reason (every plan item)
- Propose — gate, blast-radius split, backfill-before-drop, or token scope
- Risk — irreversible prod loss, including backups the same identity can wipe
- Keep-working — already-gated, transactional, isolated paths
- Phase — Gates & isolation → Migration safety → Backup blast-radius → Least-privilege (do not execute)
Worked example
Propose: scope the agent token to non-destructive; move backups off the prod volume; split 0007_drop_legacy.sql into backfill → verify → drop.
Risk: same identity can DROP prod and the backups — restore is theater.
Keep-working: additive migrations already wrap in a transaction.
Phase: Phase 1 — Gates & isolation (Critical).
Restore proof: plan-backup-dr, never this skill.
In a widely reported 2026 incident, an AI agent deleted a startup's entire production
database — and every backup — in seconds. Four structural failures: overprivileged
tokens, shared blast radius (backups on same volume as prod), no environment
isolation, no destructive-action gate. Written rules were ignored. Soft prompt-rules
are not a control; the guardrail must be a system boundary.
When this fires
Trigger phrases: "is this migration safe", "could I lose data",
"destructive operations", "my agent might nuke prod", "safe schema
change", "pre-launch data safety".
Do not fire for: query speed (backend-db-performance), RLS access
(plan-rls-audit), schema design (audit-db-schema), or "can we restore /
what's our RPO / disaster recovery" → plan-backup-dr. This skill owns
preventing irreversible loss; that skill owns recovering after one.
Why a dedicated skill
The db-migrator subagent executes migrations; this audits the safety net
before you trust automated execution. Distinct from audit-db-schema — here the
only question is: "what here could destroy data, and what stops it?"
The audit [HIGH freedom]
A · Destructive operations in code & migrations
- Unguarded
DELETE / UPDATE without WHERE — or WHERE that matches all.
TRUNCATE, DROP TABLE, DROP COLUMN in migrations — confirm intent.
- Column drops/renames without backfill — silent data loss.
- Cascade reach —
ON DELETE CASCADE further than intended.
- Destructive verbs in agent/CI scope —
drop, truncate, destroy, rm -rf.
B · Migration discipline
- No transaction wrapping — half-applied migrations.
- No down/rollback path.
- Run straight against prod — no staging dry-run.
- Supabase specifics — prod-linked CLI without branch/preview check.
C · Backup blast radius (prevent-wipe only)
- Backups in the same blast radius as production — same credentials can delete both.
- Hand restore drills, RPO/RTO, and "can we recover" to
plan-backup-dr. This
section only asks: can the same identity that wipes prod also wipe the backups?
D · Privilege & isolation (least privilege)
- Overprivileged tokens — destructive scope when only read/narrow write needed.
- No environment isolation — staging reaches prod; shared connection strings.
- Production reachable from agent context — top finding regardless of prompts.
E · Confirmation gates
- No out-of-band gate on destructive ops — must be system boundary (RBAC/
approval), not prompt text.
- No kill switch / audit log for agent operations.
Procedure [HIGH freedom — plan only]
- Inventory destructive surface. Migrations, SQL, scripts, agent/CI scopes.
- Trace each to impact. Reversible? gated? backed up outside blast radius?
- Score. "Agent can delete prod, backups share volume" = Critical, top of list.
- Phase — gates and blast-radius separation first.
- Emit
plan-data-integrity.md. End the turn. Do not edit anything.
Guardrails
- Plan only. No migration edits, token changes, backup config, and never run
destructive commands to "verify".
- System boundaries over prompt-rules. Recommend structural gates, not more
agent instructions.
- Least privilege is the cheapest win.
- Backups outside the blast radius or they don't count.
- Backfill before drop. One-step column drops on populated data = data loss.
Self-critique before the burndown [LOW freedom — do not skip]
- evidenced-not-assumed — every wipe path cites a migration, script, or token scope
- plan-only — no SQL, no token edits, never a destructive "verify"
- severity/phase justified — agent-can-wipe-prod-and-backups is Critical, top of list
- right-owner — RPO/RTO/restore drill →
plan-backup-dr; who-can-read-rows → plan-rls-audit; key rotation → plan-secrets-audit
- no-false-safety — prompt-rules are not a gate; backups in the same blast radius do not count
Report template — plan-data-integrity.md
# Data-Integrity & Destructive-Op Audit — <repo>
_Audit-only. No migration, token, or backup config changes until approved._
_No destructive command is run for any reason._
## Scope
- Audited: migrations ☐ SQL/scripts ☐ agent/CI token scopes ☐ backup config ☐
- Stack: Supabase ☐ Railway ☐ Vercel ☐ AWS ☐ | Assumptions: …
## Verdict
| Severity | Count | Worst case |
|----------|-------|-----------|
| Critical | n | irreversible prod loss, no gate, backups in blast radius |
| High | n | unbackfilled drop, over-scoped token |
| Medium | n | no rollback path |
## Findings
| # | Operation / location | Data at risk | Reversible? | Gated? | Sev | Direction |
|---|----------------------|--------------|-------------|--------|-----|-----------|
| D1 | agent token scope | all prod tables | no | no | Crit | scope token; read-only default; approval gate |
| D2 | backups on prod volume | all backups | no | no | Crit | move backups to isolated/immutable store |
| D3 | 0007_drop_legacy.sql | users.legacy_id | no | no | High | backfill→verify→drop in separate migration |
## Phased burndown
- **Phase 1 — Gates & isolation** → infra/RBAC config — D1, D2 (make catastrophe impossible)
- **Phase 2 — Migration safety** → `db-migrator` — backfill steps, transactions, rollbacks
- **Phase 3 — Backup blast-radius gates** → isolate backups from the agent identity; restore drills / RPO stay on `plan-backup-dr`
- **Phase 4 — Least-privilege sweep** → infra + `plan-secrets-audit` — token scoping
## Execution handoff
Approve a phase to run it. Confirm the agent identity cannot delete backups.
Restore proof is `plan-backup-dr`, never this skill.
Chains with
- Security spine — blast-radius layer (this skill); cross-hand tokens to
plan-secrets-audit. Recoverability → plan-backup-dr.
- Source transforms (jscodeshift / find-replace / AI bulk edit) →
audit-codemod-safety.
- Execution:
db-migrator, backend-patterns, infra config, create-hook.
- Verify: confirm agent token can't reach prod; restore proof lives on
plan-backup-dr.
Plan with a strong model; execute with composer-2.5-execution.mdc riding
along. Highest-stakes plan in the set — the plan says what can destroy data;
the rule forbids the agent from doing it autonomously.
1---2name: plan-data-integrity3description: Audit a project for destructive-operation and migration safety gaps, then produce a phased safeguard plan. Use when "is my migration safe", "could I lose data", "my agent might delete prod", or "safe schema changes". Restore drills and RPO/RTO belong to plan-backup-dr. Source transforms → audit-codemod-safety.4license: MIT5---67# Data-Integrity & Destructive-Op Audit + Safeguard Plan89**Degree of freedom: HIGH** — map wipe paths, score irreversibility, emit a plan.10Stay **plan-only**. No migrations, tokens, or destructive commands until approved.1112**Role:** Senior platform engineer (destructive-op + migration safety).1314**Task:** Map every path to irreversible data loss, score by irreversibility × reach,15phase structural safeguards, emit `plan-data-integrity.md`. **Audit & plan only — no16migrations, tokens, or destructive commands until each phase is approved.**1718**Find what could wipe prod. Gate it. Change nothing until approved.**1920## This skill vs neighbors2122| Skill | Owns |23|---|---|24| **plan-data-integrity** (this) | Prevent irreversible loss — unguarded deletes, unsafe migrations, backups the agent can also wipe |25| `plan-backup-dr` | Can you restore? RPO/RTO, drill evidence |26| `audit-db-schema` | Schema design quality |27| `plan-rls-audit` | Who can read/write which rows |2829## How to reason (every plan item)30311. **Propose** — gate, blast-radius split, backfill-before-drop, or token scope322. **Risk** — irreversible prod loss, including backups the same identity can wipe333. **Keep-working** — already-gated, transactional, isolated paths344. **Phase** — Gates & isolation → Migration safety → Backup blast-radius → Least-privilege (do not execute)3536## Worked example3738> **Propose:** scope the agent token to non-destructive; move backups off the prod volume; split `0007_drop_legacy.sql` into backfill → verify → drop.39> **Risk:** same identity can `DROP` prod *and* the backups — restore is theater.40> **Keep-working:** additive migrations already wrap in a transaction.41> **Phase:** Phase 1 — Gates & isolation (Critical).42> **Restore proof:** `plan-backup-dr`, never this skill.4344In a widely reported 2026 incident, an AI agent deleted a startup's entire production45database — *and every backup* — in seconds. Four structural failures: **overprivileged46tokens**, **shared blast radius** (backups on same volume as prod), **no environment47isolation**, **no destructive-action gate**. Written rules were ignored. Soft prompt-rules48are not a control; the guardrail must be a *system boundary*.4950---5152## When this fires5354Trigger phrases: *"is this migration safe"*, *"could I lose data"*,55*"destructive operations"*, *"my agent might nuke prod"*, *"safe schema56change"*, *"pre-launch data safety"*.5758Do **not** fire for: query speed (`backend-db-performance`), RLS access59(`plan-rls-audit`), schema *design* (`audit-db-schema`), or *"can we restore /60what's our RPO / disaster recovery"* → `plan-backup-dr`. This skill owns61*preventing* irreversible loss; that skill owns *recovering* after one.6263---6465## Why a dedicated skill6667The `db-migrator` subagent *executes* migrations; this *audits the safety net*68before you trust automated execution. Distinct from `audit-db-schema` — here the69only question is: *"what here could destroy data, and what stops it?"*7071---7273## The audit [HIGH freedom]7475### A · Destructive operations in code & migrations76- **Unguarded `DELETE` / `UPDATE` without `WHERE`** — or WHERE that matches all.77- **`TRUNCATE`, `DROP TABLE`, `DROP COLUMN`** in migrations — confirm intent.78- **Column drops/renames without backfill** — silent data loss.79- **Cascade reach** — `ON DELETE CASCADE` further than intended.80- **Destructive verbs in agent/CI scope** — `drop`, `truncate`, `destroy`, `rm -rf`.8182### B · Migration discipline83- **No transaction wrapping** — half-applied migrations.84- **No down/rollback path.**85- **Run straight against prod** — no staging dry-run.86- **Supabase specifics** — prod-linked CLI without branch/preview check.8788### C · Backup blast radius (prevent-wipe only)89- **Backups in the same blast radius** as production — same credentials can delete both.90- Hand restore drills, RPO/RTO, and "can we recover" to `plan-backup-dr`. This91 section only asks: can the same identity that wipes prod also wipe the backups?9293### D · Privilege & isolation (least privilege)94- **Overprivileged tokens** — destructive scope when only read/narrow write needed.95- **No environment isolation** — staging reaches prod; shared connection strings.96- **Production reachable from agent context** — top finding regardless of prompts.9798### E · Confirmation gates99- **No out-of-band gate** on destructive ops — must be system boundary (RBAC/100 approval), not prompt text.101- **No kill switch / audit log** for agent operations.102103---104105## Procedure [HIGH freedom — plan only]1061071. **Inventory destructive surface.** Migrations, SQL, scripts, agent/CI scopes.1082. **Trace each to impact.** Reversible? gated? backed up outside blast radius?1093. **Score.** "Agent can delete prod, backups share volume" = Critical, top of list.1104. **Phase** — gates and blast-radius separation first.1115. **Emit `plan-data-integrity.md`. End the turn. Do not edit anything.**112113---114115## Guardrails116117- **Plan only.** No migration edits, token changes, backup config, and **never run118 destructive commands to "verify".**119- **System boundaries over prompt-rules.** Recommend structural gates, not more120 agent instructions.121- **Least privilege is the cheapest win.**122- **Backups outside the blast radius or they don't count.**123- **Backfill before drop.** One-step column drops on populated data = data loss.124125## Self-critique before the burndown [LOW freedom — do not skip]1261271. **evidenced-not-assumed** — every wipe path cites a migration, script, or token scope1282. **plan-only** — no SQL, no token edits, **never** a destructive "verify"1293. **severity/phase justified** — agent-can-wipe-prod-and-backups is Critical, top of list1304. **right-owner** — RPO/RTO/restore drill → `plan-backup-dr`; who-can-read-rows → `plan-rls-audit`; key rotation → `plan-secrets-audit`1315. **no-false-safety** — prompt-rules are not a gate; backups in the same blast radius do not count132133---134135## Report template — `plan-data-integrity.md`136137```markdown138# Data-Integrity & Destructive-Op Audit — <repo>139140_Audit-only. No migration, token, or backup config changes until approved._141_No destructive command is run for any reason._142143## Scope144- Audited: migrations ☐ SQL/scripts ☐ agent/CI token scopes ☐ backup config ☐145- Stack: Supabase ☐ Railway ☐ Vercel ☐ AWS ☐ | Assumptions: …146147## Verdict148| Severity | Count | Worst case |149|----------|-------|-----------|150| Critical | n | irreversible prod loss, no gate, backups in blast radius |151| High | n | unbackfilled drop, over-scoped token |152| Medium | n | no rollback path |153154## Findings155| # | Operation / location | Data at risk | Reversible? | Gated? | Sev | Direction |156|---|----------------------|--------------|-------------|--------|-----|-----------|157| D1 | agent token scope | all prod tables | no | no | Crit | scope token; read-only default; approval gate |158| D2 | backups on prod volume | all backups | no | no | Crit | move backups to isolated/immutable store |159| D3 | 0007_drop_legacy.sql | users.legacy_id | no | no | High | backfill→verify→drop in separate migration |160161## Phased burndown162- **Phase 1 — Gates & isolation** → infra/RBAC config — D1, D2 (make catastrophe impossible)163- **Phase 2 — Migration safety** → `db-migrator` — backfill steps, transactions, rollbacks164- **Phase 3 — Backup blast-radius gates** → isolate backups from the agent identity; restore drills / RPO stay on `plan-backup-dr`165- **Phase 4 — Least-privilege sweep** → infra + `plan-secrets-audit` — token scoping166167## Execution handoff168Approve a phase to run it. Confirm the agent identity cannot delete backups.169Restore proof is `plan-backup-dr`, never this skill.170```171172---173174## Chains with175176- **Security spine** — blast-radius layer (**this skill**); cross-hand tokens to177 `plan-secrets-audit`. Recoverability → `plan-backup-dr`.178- **Source transforms** (jscodeshift / find-replace / AI bulk edit) → `audit-codemod-safety`.179- **Execution:** `db-migrator`, `backend-patterns`, infra config, `create-hook`.180- **Verify:** confirm agent token can't reach prod; restore proof lives on `plan-backup-dr`.181182> Plan with a strong model; execute with `composer-2.5-execution.mdc` riding183> along. Highest-stakes plan in the set — the plan says *what* can destroy data;184> the rule forbids the agent from doing it autonomously.