Governance & Safety Scripts

The scripts the flow runs to keep the context current and the database safe.

These are scripts of the skills (in fireskills/skills/), run with node. The flow runs them for you; you can run them too.


Context monitor: monitor_context.mjs

node fireskills/skills/fireskill-setup/scripts/monitor_context.mjs --project . --check

Looks at the files you changed and have not committed (git diff, staged and untracked; it ignores _docs/, fireskills/, the context files and test files) and lists which .fireskills/* document each change requires. The rules and the full table are in Project Context.

Output is Context monitor: CURRENT, or Context monitor: PENDING followed by one line per document, for example:

- .fireskills/DATABASE.md via $fireskill-aux-database: persistência alterada (apps/functions/src/database/migrations/0001_x.sql)

Options: --json, --paths <files…>, --acknowledge-project-no-change, --acknowledge-rules-no-change. The flow treats PENDING as a blocker for closing a task and for the Delivery Gate.


Database guard: check_database_safety.mjs

node fireskills/skills/fireskill-setup/scripts/check_database_safety.mjs --project . --command "<command to check>"

Classifies a command before the flow runs it. SAFE lets it run. Destructive commands are classified IGNORED and are never run, even if you approve:

  • drizzle-kit push --force, drizzle-kit drop
  • migrate:fresh, migrate:refresh, migrate:reset, migrate:rollback
  • db:wipe, schema:drop, prisma migrate reset
  • DROP DATABASE, DROP SCHEMA, DROP TABLE, TRUNCATE
  • RefreshDatabase, DatabaseMigrations and equivalents

Tests that touch PostgreSQL also need a test database different from the one in the stage secrets (DATABASE_HOST, DATABASE_NAME…). Until that separation is proven, no such test runs. None of the existing Vitest tests (billing, team seats, abilities, the branding loader) touches a database. Tests that do need a database use a rolled-back transaction or fixtures limited to the case.


Repository check: verify_repo.mjs

node fireskills/skills/fireskill-04-validate/scripts/verify_repo.mjs .

Validates every spec under specs/ with the scripts of Acts I to III and checks the contract of every fireskill-* skill: SKILL.md with a matching name, an agents/openai.yaml, fewer than 500 lines, and the expected counts of base and auxiliary skills. Prints Specsfy verify: PASSED or FAILED.

Nuxfire Production Kit

Ready to build and launch your SaaS?

Get 100% full source code ownership, zero proprietary wrappers, and architecture engineered for millions of requests on Cloudflare.

© 2026 Nuxfire