sealos-database — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited sealos-database (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this skill to give a project a real Sealos Cloud database during development. The default outcome is: identify the app's database need, create or reuse a Sealos database with sealos-cli, fetch connection details, wire only the needed local env vars, and verify the app can connect.
.env, .env.local, connection strings, passwords, kubeconfig, or Sealos auth files.database delete, backup-delete, restoring over a name that may collide, or disabling access that an active app depends on.sealos-cli by default and parse it instead of scraping table output.Confirm the working directory with pwd or git rev-parse --show-toplevel.
Run the analyzer when a project directory is available:
node <SKILL_DIR>/scripts/analyze-project-database.mjs <project-dir>Use the analyzer result as a starting point, then inspect the real files it cites before editing anything. It intentionally avoids printing secret values.
sealos-cliPrefer an existing sealos-cli binary:
sealos-cli --version
sealos-cli database --help
sealos-cli whoamiIf it is not installed, use npx -y sealos-cli@latest ... for one-off commands. Ask before installing it globally.
If auth is missing or expired, run:
sealos-cli login <region>
sealos-cli workspace list
sealos-cli workspace currentUse the workspace the user expects. If multiple workspaces exist and the target is ambiguous, ask before provisioning.
List existing databases first:
sealos-cli database list -o jsonReuse an existing database when the name, type, and purpose match. Create a new one when the project has no suitable database or the user asks for a fresh dev database.
Use conservative development defaults unless the project clearly needs more:
sealos-cli database create postgresql --name <app-dev-db> --cpu 1 --memory 1 --storage 3 --replicas 1 -o jsonBefore creating, check supported versions if version choice matters:
sealos-cli database versions --type postgresql -o jsonSupported CLI database types include postgresql, mongodb, mysql, apecloud-mysql, redis, kafka, qdrant, nebula, weaviate, milvus, pulsar, and clickhouse. Use the type detected from the project; default to postgresql only when the project has no database-specific signals.
Poll details until the database is running or connection data is present:
sealos-cli database get <name> -o json
sealos-cli database connection <name> -o jsonRead references/sealos-cli-database.md for the current command contract and response handling.
Map the connection into the env var the project already uses:
| Project signal | Preferred env key |
|---|---|
| Prisma, Drizzle, TypeORM, generic Postgres | DATABASE_URL |
| MySQL app with existing MySQL-specific config | DATABASE_URL or existing MYSQL_URL |
| MongoDB app | MONGODB_URI |
| Redis cache/queue | REDIS_URL |
Use the existing local env convention:
.env.local for Next.js and frontend-adjacent projects..env only when the repo already uses it for local development and it is gitignored..env.example as documentation only; never write real secrets there.If a connection string is not directly returned in the desired form, compose it from host, port, username, and password fields from sealos-cli database connection.
Run the project's normal verification path, not just the CLI command:
prisma migrate, drizzle-kit migrate, db:migrate, db:push).sealos-cli database enable-public <name> -o json
sealos-cli database connection <name> -o jsonDisable public access after testing if it is no longer needed:
sealos-cli database disable-public <name> -o jsonSummarize:
postgres, mysql, mongo, or redis compose services.scripts/analyze-project-database.mjs - read-only project database intent analyzer.references/sealos-cli-database.md - sealos-cli database command contract.references/env-integration.md - safe env-file editing and connection-string mapping.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.