Governance & Safety Scripts
The scripts the flow runs to keep the context current and the database safe.
These are scripts of the skills (in fireskills/skills/), run with node. The flow runs them for you; you can run them too.
Context monitor: monitor_context.mjs
node fireskills/skills/fireskill-setup/scripts/monitor_context.mjs --project . --check
Looks at the files you changed and have not committed (git diff, staged and untracked; it ignores _docs/, fireskills/, the context files and test files) and lists which .fireskills/* document each change requires. The rules and the full table are in Project Context.
Output is Context monitor: CURRENT, or Context monitor: PENDING followed by one line per document, for example:
- .fireskills/DATABASE.md via $fireskill-aux-database: persistência alterada (apps/functions/src/database/migrations/0001_x.sql)
Options: --json, --paths <files…>, --acknowledge-project-no-change, --acknowledge-rules-no-change. The flow treats PENDING as a blocker for closing a task and for the Delivery Gate.
Database guard: check_database_safety.mjs
node fireskills/skills/fireskill-setup/scripts/check_database_safety.mjs --project . --command "<command to check>"
Classifies a command before the flow runs it. SAFE lets it run. Destructive commands are classified IGNORED and are never run, even if you approve:
drizzle-kit push --force,drizzle-kit dropmigrate:fresh,migrate:refresh,migrate:reset,migrate:rollbackdb:wipe,schema:drop,prisma migrate resetDROP DATABASE,DROP SCHEMA,DROP TABLE,TRUNCATERefreshDatabase,DatabaseMigrationsand equivalents
Tests that touch PostgreSQL also need a test database different from the one in the stage secrets (DATABASE_HOST, DATABASE_NAME…). Until that separation is proven, no such test runs. None of the existing Vitest tests (billing, team seats, abilities, the branding loader) touches a database. Tests that do need a database use a rolled-back transaction or fixtures limited to the case.
Repository check: verify_repo.mjs
node fireskills/skills/fireskill-04-validate/scripts/verify_repo.mjs .
Validates every spec under specs/ with the scripts of Acts I to III and checks the contract of every fireskill-* skill: SKILL.md with a matching name, an agents/openai.yaml, fewer than 500 lines, and the expected counts of base and auxiliary skills. Prints Specsfy verify: PASSED or FAILED.
Ready to build and launch your SaaS?
Get 100% full source code ownership, zero proprietary wrappers, and architecture engineered for millions of requests on Cloudflare.