Best AI Agent Skills for Database Migrations (2026)
A. Frans
Published August 18, 2026
Table of Contents
A schema migration is the one operation where an AI agent can do damage you can't undo with git revert. Drop a column, and the data that was in it is gone. That single asymmetry should drive every decision about which skills you install and how you wire them up, and it's the reason this list is organized by blast radius rather than by popularity.
Eight skills in the directory touch database schema work. They split into two groups that people constantly conflate: skills that teach the agent how to write migrations, and MCP servers that give the agent a live connection to run things against a database. The first group is safe. The second group needs a policy.
Quick comparison
| Skill | What it does | Trust tier | Stars | Security |
|---|---|---|---|---|
| Atlas | Declarative schema-as-code migrations | Verified | 8,649 | Community-reviewed |
| Prisma Database | Prisma ORM patterns and migration practice | Verified | 47,575 | Community-reviewed |
| Drizzle ORM | Type-safe SQL and Drizzle migration patterns | Verified | 35,492 | Community-reviewed |
| MCP Toolbox | Google's multi-database MCP server | Official | 16,180 | Audited |
| DBHub | Token-efficient multi-engine database MCP | Verified | 3,365 | Community-reviewed |
| Supabase MCP | Official Supabase database and auth management | Official | 2,866 | Audited |
| MCP Server MySQL | Read-only MySQL access | Verified | 2,047 | Community-reviewed |
| Pigsty | PostgreSQL distribution with HA and PITR | Verified | 5,535 | Community-reviewed |
Group one: skills that write migrations
These load knowledge into the agent's context. They don't connect to anything. Worst case, the agent writes a bad migration file and you catch it in review, which is the same failure mode as a junior developer's first PR.
Atlas
claude skill add ariga/atlas
Atlas is the pick if you want declarative migrations, where you describe the schema you want and the tool computes the diff. That model fits agent workflows better than imperative migrations do, because the agent's job becomes "edit this schema file" rather than "write correct forward and backward SQL," and editing a declarative spec is a task LLMs are reliably good at.
Apache-2.0, 8,649 stars on ariga/atlas, last updated 2026-08-02. Community-reviewed rather than audited, which for a skill that ships no network access is a reasonable place to land.
The specific reason to prefer it: Atlas computes the migration plan and shows it to you before applying. An agent proposing a schema change against Atlas produces a reviewable diff. An agent proposing raw SQL produces a wall of DDL you have to reason about yourself.
Prisma Database
claude skill add prisma/prisma
At 47,575 stars and roughly 84,000 installs, Prisma Database is the most-installed skill in this category by a wide margin, and it's the one to install if your project already uses Prisma. It teaches the agent Prisma's migration conventions, which matters because prisma migrate dev and prisma migrate deploy do very different things and an agent that confuses them in a production script is a bad afternoon.
Works with Claude Code, Cursor, and Codex CLI. Apache-2.0, updated 2026-08-14.
Drizzle ORM
claude skill add drizzle-team/drizzle-orm
Drizzle ORM covers the same ground for teams on Drizzle, with 35,492 stars and around 56,000 installs. Drizzle's migration story is closer to raw SQL than Prisma's, so the skill spends more of its budget on schema-definition patterns and less on migration lifecycle.
Pick between these two on what your codebase already uses. Installing the skill for an ORM you don't use adds context noise and no capability.
Group two: MCP servers with live database access
This is where the policy matters. An MCP server that can reach your database can, depending on configuration, read every row in it and execute arbitrary statements against it. That's the useful part and the dangerous part at the same time.
MCP Toolbox
claude mcp add mcp-toolbox -- npx -y googleapis/mcp-toolbox
MCP Toolbox is Google's open-source database MCP server, official tier, audited, 16,180 stars on googleapis/mcp-toolbox, Apache-2.0. It covers multiple engines and it's the one I'd default to for anything touching production, on the strength of the audit status and the maintainer.
DBHub
claude mcp add dbhub -- npx -y bytebase/dbhub
DBHub from Bytebase is zero-dependency and explicitly token-efficient, covering Postgres, MySQL, SQL Server and others. MIT, 3,365 stars, updated 2026-08-15. The token efficiency claim is worth taking seriously: schema introspection output is one of the fastest ways to burn a context window, and a server that returns compact schema descriptions rather than raw catalog dumps leaves you room to do the work.
Works across Claude Code, Cursor, Codex CLI, and VS Code Copilot.
Supabase MCP
claude mcp add supabase -- npx -y @supabase/mcp-server
If you're on Supabase, Supabase MCP is the official server, audited, Apache-2.0, with about 25,000 installs. It handles database and auth management together. Note there's also a community-tier supabase-mcp-server from a different author in the directory; the official one is the one you want.
MCP Server MySQL
claude mcp add mcp-server-mysql -- npx -y benborla/mcp-server-mysql
MCP Server MySQL is read-only by design, and that constraint is a feature rather than a limitation. For the common case of "let the agent understand my schema so it can write a correct migration," read-only access is all you need, and it removes the entire category of accidental-write incidents. MIT, 2,047 stars, updated 2026-07-27.
Pigsty
claude skill add pgsty/pigsty
Pigsty is a different animal, an enterprise PostgreSQL distribution covering high availability, point-in-time recovery, and monitoring. Install it when your question is "how should this Postgres cluster be operated," not "how do I add a column." Apache-2.0, 5,535 stars.
Its relevance to migrations is indirect and important: PITR is what makes a bad migration survivable. If you're going to let an agent near a schema, having a tested restore path matters more than any of the skills above.
The setup I'd run
Two agents, two configurations.
The migration author gets Atlas plus whichever ORM skill matches your stack, and no database connection at all. It reads your schema files from the repo and proposes changes as a diff. It cannot touch anything live.
The schema inspector gets a read-only MCP connection to a staging replica, never production. It answers questions about actual data shape, row counts, and index usage that the schema file doesn't tell you.
Nothing in the loop applies a migration. That step stays in CI, behind the same review gate as any other deploy.
This costs you a few minutes of setup and removes the failure mode where an agent helpfully "fixes" a schema drift by dropping the column it thinks is extra. If that sounds paranoid, the security review of untrusted skills covers what happens when the assumption goes the other way.
Trust tiers and what they mean here
Two of the eight are official tier with audited security status: MCP Toolbox and Supabase MCP. Both are also the ones with live database access, which is the right way round.
The rest are verified tier with community-reviewed status. For the skills that only load knowledge, that's fine. For an MCP server with write access to a database holding customer records, "community-reviewed" is a reason to read the source before you install, not a reason to skip it. All eight are open source under MIT or Apache-2.0, so that review is available to you.
More on how the tiers are assigned in why skill author trust tiers matter.
FAQ
Can Claude Code run a migration against my production database?
Only if you connect it to one. Skills like Atlas and Prisma Database have no network access; they only change what the agent knows. MCP servers do have access, and they'll do whatever their configured credentials permit. The credential you hand the server is the actual security boundary, not the skill.
Which skill should I install first?
Whichever ORM skill matches your stack, because it costs nothing and immediately reduces the rate at which the agent writes migrations that don't match your project's conventions. Add Atlas next if you want declarative diffs. Add an MCP server only when you have a concrete question that requires reading live schema.
Is a read-only MCP server enough for migration work?
For writing the migration, yes. The agent needs to know the current schema, index coverage, and rough table sizes; none of that requires write access. Reserve write-capable connections for local development databases you can drop and rebuild.
Do these work outside Claude Code?
Mixed. Prisma Database and Drizzle ORM list Claude Code, Cursor, and Codex CLI. DBHub and MCP Toolbox add VS Code Copilot. Atlas and Pigsty are Claude Code only at the moment.
What about migration rollback?
None of these skills solve rollback, and treating them as though they do is the main way people get hurt. Rollback for a destructive migration is a restore from backup, which is why Pigsty's PITR coverage shows up on this list at all. Test the restore before you need it.
Share this article
⚙Related Tools
📄Related Articles
Get More AI Tool Guides
New comparisons and guides every week. Join thousands of professionals staying ahead of the AI curve.