ScopeGuard AI
Turns scattered client instructions (briefs, notes, emails, chats) into an evidence-backed scope that a person reviews and confirms before any work is committed.
Case study · 2026 · Hackathon
A deploy gate for PostgreSQL migrations: it flags lock-taking statements, proves the locks in embedded Postgres, estimates blocking time, and has IBM Bob rewrite them for zero downtime.
Result pending
LockSmith is a deploy gate for PostgreSQL schema migrations. It reads a migration, flags the statements that would block reads or writes, proves each lock by replaying the migration inside a real embedded Postgres, estimates how long production would be blocked, and hands the fix to IBM Bob. I built it solo for the IBM Bob 2.0 Hackathon on lablab.ai and submitted it on 27 September 2026.
Migrations go through the same pull-request review as application code, but their risk is invisible in a diff. CREATE INDEX without CONCURRENTLY holds a ShareLock that blocks writes for the whole build. ALTER COLUMN … TYPE takes an AccessExclusiveLock and rewrites the table. A column rename is instant, yet it breaks every running app instance still using the old name. Any heavy DDL without lock_timeout can queue behind one slow query and freeze everything behind it. Reviewers are expected to know all of this by heart. When they miss one, the first sign is a stalled deploy.
The pipeline has five steps.
NOT NULL adds, volatile defaults, type changes, validated foreign keys and checks, renames and drops still referenced by application code, missing lock_timeout, CONCURRENTLY inside a transaction, and un-batched backfills.pg_locks for the lock actually taken and compares relfilenode before and after to catch table rewrites.lock-audit skill, has Bob rewrite each flagged migration in its own subagent. Bob also updates the dependent app code, adding dual-writes for renames, and leaves unflagged files alone.The engine is TypeScript, the web report and analyser run on Next.js with Tailwind, and tests run on Vitest. LockSmith never connects to a real database.
CREATE INDEX CONCURRENTLY can't run inside the probe's transaction, so its lock is marked inferred in the UI rather than presented as measured.The demo repository is a fictional shop app with 8 pending migrations. As written, the gate fails with a risk score of 100 and 14 findings. After Bob's rewrite, it passes with 0 findings, and 6 dangerous migrations have become 13 ordered safe files.
The README roadmap lists a GitHub Action wrapper, Prisma, Rails and Flyway adapters, importing real pg_stat table sizes, and MySQL online-DDL rules. For now LockSmith covers PostgreSQL and plain SQL migration files only.
Schema migrations are reviewed as text, but they fail as locks. A one-line CREATE INDEX blocks every write for the whole build; ALTER COLUMN … TYPE takes an AccessExclusiveLock and rewrites the table. None of that shows up in a diff, and catching it means knowing lock semantics and doing table-size arithmetic in your head.
Twelve deterministic rules (LS001–LS012) decide what is risky. Every statement is replayed in PGlite, an in-process Postgres, so the lock is read from pg_locks rather than guessed. Declared table sizes turn each lock into a blocking-time estimate. IBM Bob, through a custom mode and skill shipped in the repo, rewrites flagged migrations into expand → backfill → contract steps, and the same gate re-checks Bob's output before CI lets the deploy through.
Solo builder.
12 deterministic rules, LS001–LS012, over parsed SQL
Lock proof: each statement replayed in embedded Postgres (PGlite), read from pg_locks
Table-rewrite detection by comparing relfilenode before and after
Blocking-time estimate from declared table sizes
IBM Bob custom mode and skill that rewrite one migration per subagent
CLI gate that exits 1 while any critical finding remains
Paste-a-migration analyser that runs SQL only in a throwaway in-memory instance
Shipped on lablab.ai, GitHub and Vercel.
Submitted to IBM Bob 2.0 Hackathon on lablab.ai, 27 Sep 2026.
Result pending
Built with Teqprotech · Custom Web Applications.