Dev supabase
Skill christopherlouet/claude-base/.claude/skills/dev-supabase
Opinionated Claude Code foundation — Explore → TDD → Audit workflow, auto-detected stack presets (nextjs, fastapi, astro, ...), curl | bash install. MIT.
npx -y skills add christopherlouet/claude-base --skill dev-supabaseAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 5 stars5 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Backend development with Supabase. Trigger when the user wants to configure auth, the database, or Supabase storage.
SKILL.md
3.3 KB, as published. Nobody here has run it
Supabase (pointer)
Supabase publishes the canonical agent skills at supabase/agent-skills — maintained by the Supabase team, in sync with current API (Auth, DB, Edge Functions, Realtime, Storage). The repo ships two skills that stay current with every API release; the prior foundation skill (224 lines) drifted on each Supabase version.
Delegate to the vendor skills
# Vendor publishes via marketplace (verify on their README):
claude plugin install supabase@supabase
# Fallback — clone and symlink both skills:
git clone --depth 1 https://github.com/supabase/agent-skills ~/dev/vendor-skills/supabase
ln -s ~/dev/vendor-skills/supabase/skills/supabase ./.claude/skills/supabase
ln -s ~/dev/vendor-skills/supabase/skills/supabase-postgres-best-practices \
./.claude/skills/supabase-postgres-best-practices
supabase— Auth, DB, Edge Functions, Realtime, Storage with current API patterns.supabase-postgres-best-practices— 30 rules across 8 categories (indexing, RLS perf, schema design, pg_* extensions).
Recipe entry: docs/recipes/recommended-vendor-skills.md §"Supabase — supabase/agent-skills". Reduction rationale: specs/foundation-positioning-review/spec.md Wave 1.
Foundation-unique angle preserved: cross-cutting discipline
The vendor covers the Supabase API surface. The foundation enforces version-agnostic conventions that survive across releases:
- Auth: Supabase Auth is one option among many — cross-ref the
dev-authskill for framework-agnostic patterns (sessions, OAuth, magic links) before deciding on Supabase-specific flows. - ORM interop: Prisma operates against the same Postgres, and Supabase RLS coexists with Prisma queries — cross-ref the
dev-prismaskill. - General Postgres: the vendor's
supabase-postgres-best-practicesskill is useful for any Postgres project, not just Supabase-managed — cross-ref theops-databaseskill. - Security: RLS on every public table; never disable it to "make a query work" — cross-ref
.claude/rules/security.md.
Foundation rules preserved
- YOU MUST enable Row Level Security on every public-schema table before exposing it via PostgREST. No exceptions.
- YOU MUST use the Supavisor pooler (port 6543) for serverless / edge runtimes. Direct connections (5432) exhaust limits.
- NEVER
SELECT *in production queries — specify columns (security + perf + payload size). - YOU MUST store monetary amounts as
INTEGERcents, neverFLOAT/NUMERICrounded — avoids drift footgun. - YOU MUST index every foreign key and every column in frequent WHERE clauses.
- YOU MUST use cursor-based pagination (
gt('created_at', ...)) for large tables, neverrange()/ OFFSET (slow scan). - NEVER commit
.envwithSUPABASE_URL/ service-role key. Always.env.examplewith placeholders. - NEVER expose the
service_rolekey client-side — it bypasses RLS. Use it only in server-side code (Edge Functions, API routes).