Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Openrind Navigate

ASecurity

Query PostgreSQL with pg and navigate Openrind Shell's primary FUSE or compatibility workspace; /db is custom-agent-only.

3 stars
0 votes
0 copies
0 views
Added 9/26/2026
databasesshellbashsqldatabasesecurity

Works with

claude code

Security Analysis

A100/100

Scanned 10/4/2026

$npx -y skills add openrind/openrind-shell --skill openrind-navigate --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Openrind Navigate?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Openrind Navigate
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/openrind-openrind-navigate/badge)](https://www.skillsdirectory.com/skills/openrind-openrind-navigate)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: openrind-navigate
description: Query PostgreSQL with pg and navigate Openrind Shell's primary FUSE or compatibility workspace; /db is custom-agent-only.
---

# Openrind Shell Navigate

Identify the runtime from the kernel mount, not an image tag:

```bash
if mountpoint -q /sandbox/work 2>/dev/null; then
  echo primary-fuse
else
  echo compatibility
fi
```

## Persistence Map

```mermaid
flowchart TB
  detect{"mountpoint /sandbox/work?"}
  detect -->|Yes| primary["Primary FUSE<br/>HOME=/sandbox/work"]
  primary --> all["Every descendant file<br/>PostgreSQL-backed"]
  detect -->|No| compat["Compatibility<br/>HOME=/sandbox"]
  compat --> scoped["Persisted: .claude, .claude.json,<br/>.openrind-shell and legacy .openeral"]
  compat --> ephemeral["Everything else<br/>sandbox-local"]
  custom["createOpenrindShell custom agent"] --> db["/db read-only PgFs"]
```

## PostgreSQL Queries

Use the `pg` helper in either runtime and quote the complete SQL string:

```bash
pg "SELECT table_name FROM information_schema.tables WHERE table_schema = 'public'"
pg "SELECT * FROM public.users LIMIT 5"
```

The helper prints a JSON array and exits nonzero on database or policy failure.

## Primary FUSE Workspace

Use normal tools below `/sandbox/work`. `fsync` is an explicit durability barrier;
clean Claude exit also flushes pending dirty data.

```bash
openrind-shell-fused health
openrind-shell-fused flush-all
```

Only one writable sandbox may mount a given workspace ID. Stop mutating files if
health is not `writable`. Operations return `EIO` while the daemon reconnects to
PostgreSQL; a daemon exit or lease loss restarts the whole container and ends the
current shell or Claude session, so `fsync` anything you cannot afford to lose.

## Compatibility Workspace

Compatibility synchronization covers only:

```text
/sandbox/.claude/**
/sandbox/.claude.json
/sandbox/.openrind-shell/**
/sandbox/.openeral/**    # legacy state during migration
```

PGlite, when used, lasts only for that sandbox. Other files are not persisted.

## Claude Memory

Run from the relevant project directory:

```bash
openrind-shell memory refresh --query "current project"
claude -c
```

## `/db` Virtual Filesystem

`/db` is not mounted in Claude Code's native shell. It exists only when a custom agent
uses `createOpenrindShell()` and just-bash:

```bash
ls /db
cat /db/public/users/.info/columns.json
cat /db/public/users/.info/schema.sql
cat /db/public/users/.info/count
cat /db/public/users/page_1/1/row.json
```

The custom-agent path is read-only. Prefer `.filter/` and `.info/count` over scanning
page trees.

## Security Facts

- Provider keys remain OpenShell placeholders resolved only at approved egress.
- The PostgreSQL URL is raw-protocol runtime state, not a provider placeholder.
- Primary v1 runs Claude and the FUSE daemon as the same UID; do not claim secret
  isolation between them.
- `/tmp` and `/var/lib/openrind-shell/runtime` are operational, not persisted FUSE
  namespace paths.

Attribution

openrindopenrind
View sourceSee grades on GitHubMore from openrind →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Mysql Best Practices

MySQL development best practices for schema design, query optimization, and database administration

2481 votes

Jpa Patterns

Spring Boot中的JPA/Hibernate实体设计、关系、查询优化、事务、审计、索引、分页和连接池模式。

2456590 votes

Clickhouse Io

ClickHouse数据库模式、查询优化、分析和数据工程最佳实践,适用于高性能分析工作负载。

2456590 votes

Postgres Patterns

基于Supabase最佳实践的PostgreSQL数据库模式,用于查询优化、架构设计、索引和安全。

2456590 votes

Sql Pro

Master modern SQL with cloud-native databases, OLTP/OLAP

458250 votes
View all in databases →