Alibaba Cloud AnalyticDB PostgreSQL Query Skill for Openclaw

A highly secure, read-only SQL query and data analysis capability for shell-capable AI agents connecting to AnalyticDB PostgreSQL databases via psql.

sdk-team
v0.0.1-beta.1
Jun 23, 2026
0
448
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install alibabacloud-analyticdb-postgresql-query

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install alibabacloud-analyticdb-postgresql-query using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Alibaba Cloud AnalyticDB PostgreSQL Query Skill?

The Alibaba Cloud AnalyticDB PostgreSQL Query Skill is a highly secure, enterprise-grade integration designed for shell-capable AI agents. It enables agents to connect to an AnalyticDB PostgreSQL (ADBPG) database instance via psql, generate compliant read-only queries from natural language, and export structured datasets to CSV format. As a core tool among Openclaw Skills, this capability bridges the gap between deep AI reasoning and structured operational databases.\n\nSecurity is prioritized at every step of execution. By implementing strict pre-query gates, read-only safeguards, resource constraints, and human-in-the-loop (HITL) approval gates, this skill mitigates the risk of destructive actions, resource exhaustion, or data leakage. It serves as an essential runtime capability for organizations that use Openclaw Skills to expose analytical data to AI workflows safely.

Alibaba Cloud AnalyticDB PostgreSQL Query Skill Use Cases

  • Natural Language to SQL Analysis: Convert user queries regarding business performance or analytical trends directly into secure, read-only SQL execution statements.\n- Compliant CSV Data Exporting: Provide users with authorized, timestamped CSV files of query results for offline local analysis without raw table exposures.\n- Database Insight Discovery with Openclaw Skills: Safely catalog schemas, query specific KPIs, and verify metadata configurations without giving agents direct structural control.\n- Secure Data Audits: Execute query operations with a strict read-only mandate, preventing accidental write, update, or structural operations on sensitive production databases.

How Alibaba Cloud AnalyticDB PostgreSQL Query Skill Works

  1. Session Startup Verification: On session initialization, the agent performs quick diagnostics checking for psql, auditing account privileges, verifying Resource Group constraints, and loading semantic metadata tables.\n2. Natural Language Request Processing: The agent receives a business question or analytic query request from the user.\n3. Pre-Query Gate Evaluation: Before generating SQL, the agent runs through automated gates to enforce read-only variables, inject statement timeouts, verify database schema availability, and match business metrics.\n4. SQL Generation and Compliance Validation: The agent translates the query, automatically injecting a hard limit (e.g., LIMIT 50000) and stripping out any prohibited SQL statements. Only SELECT, WITH...SELECT, and EXPLAIN statements are permitted.\n5. Human-In-The-Loop (HITL) Halt: The agent presents the synthesized SQL and pauses immediately, prompting the user for explicit confirmation.\n6. Safe Execution and Export: Upon receiving positive user validation, the agent runs the SQL command using a dedicated read-only role via psql and shares the results or a timestamped CSV download link.

Alibaba Cloud AnalyticDB PostgreSQL Query Skill Setup

First, verify that your runtime environment has the psql client binary installed as required by Openclaw Skills database clients:\n\nbash\npsql --version\n\n\nNext, export the necessary credentials to your runtime environment variables. Never expose database passwords in the agent's prompt history. We recommend configuring these variables via a system env file or secure environment injector:\n\nbash\nexport PGHOST="your-adbpg-instance-endpoint.gpdb.rds.aliyuncs.com"\nexport PGPORT=5432\nexport PGDATABASE="analytics_db"\nexport PGUSER="readonly_agent_user"\nexport PGPASSWORD="your_secure_password_here"\n\n\nAlternatively, configure service connection profiles inside ~/.pg_service.conf to avoid exposing structural parameters inside individual agent contexts.

Alibaba Cloud AnalyticDB PostgreSQL Query Skill Data Schema & Taxonomy

This skill depends heavily on a structured semantic model layer to validate context and map queries. It uses a custom database schema designated as _agent_meta to verify accessibility limits:\n\n| Table / Metadata Object | Purpose | Requirement Status |\n| :--- | :--- | :--- |\n| _agent_meta.tables | Stores permitted tables and schema properties. | Required (Query fails if missing) |\n| _agent_meta.metric_meta | Houses predefined business metrics (sql_expressions and dimensions). | Optional (Enhances accuracy) |\n| _agent_meta.filters | Map standard business rules and filter scopes (where, measure, etc.). | Optional (Enhances filtering) |\n\nAll file exports generated by the agent are formatted as CSV files and named dynamically with distinct timestamp structures (e.g., export_adbpg_YYYYMMDD_HHMMSS.csv) for traceability.

Alibaba Cloud AnalyticDB PostgreSQL Query Skill Advanced Features

  • Zero-Tolerance Credential Safeguards: Explicitly blocks and halts executions that attempt to read, inspect, or cat sensitive files like .pgpass, .pgenv, or parse environment variables containing password text.\n- Granular Semantic Layer Enforcement: Features a hard-stop gate that blocks database queries completely if target tables are not documented in the _agent_meta.tables validation schema.\n- Dynamic Resource Control and Resource Groups: Inspects and warns if the target user is not isolated into a dedicated database Resource Group, safeguarding transactional server performance during analytical queries.\n- Strict Error Halting: Follows a strict 'no act first, ask later' protocol. When configuration anomalies or security warnings arise, the agent immediately terminates processing and requests human feedback, maintaining high trust standards across Openclaw Skills integrations.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*