agentsclimarketplace

Dev supabase

Skill christopherlouet/claude-base/.claude/skills/dev-supabase

Opinionated Claude Code foundation — Explore → TDD → Audit workflow, auto-detected stack presets (nextjs, fastapi, astro, ...), curl | bash install. MIT.

Install
npx -y skills add christopherlouet/claude-base --skill dev-supabase

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 5 stars5 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Backend development with Supabase. Trigger when the user wants to configure auth, the database, or Supabase storage.

SKILL.md

3.3 KB, as published. Nobody here has run it

Supabase (pointer)

Supabase publishes the canonical agent skills at supabase/agent-skills — maintained by the Supabase team, in sync with current API (Auth, DB, Edge Functions, Realtime, Storage). The repo ships two skills that stay current with every API release; the prior foundation skill (224 lines) drifted on each Supabase version.

Delegate to the vendor skills

# Vendor publishes via marketplace (verify on their README):
claude plugin install supabase@supabase

# Fallback — clone and symlink both skills:
git clone --depth 1 https://github.com/supabase/agent-skills ~/dev/vendor-skills/supabase
ln -s ~/dev/vendor-skills/supabase/skills/supabase ./.claude/skills/supabase
ln -s ~/dev/vendor-skills/supabase/skills/supabase-postgres-best-practices \
      ./.claude/skills/supabase-postgres-best-practices
  • supabase — Auth, DB, Edge Functions, Realtime, Storage with current API patterns.
  • supabase-postgres-best-practices — 30 rules across 8 categories (indexing, RLS perf, schema design, pg_* extensions).

Recipe entry: docs/recipes/recommended-vendor-skills.md §"Supabase — supabase/agent-skills". Reduction rationale: specs/foundation-positioning-review/spec.md Wave 1.

Foundation-unique angle preserved: cross-cutting discipline

The vendor covers the Supabase API surface. The foundation enforces version-agnostic conventions that survive across releases:

  • Auth: Supabase Auth is one option among many — cross-ref the dev-auth skill for framework-agnostic patterns (sessions, OAuth, magic links) before deciding on Supabase-specific flows.
  • ORM interop: Prisma operates against the same Postgres, and Supabase RLS coexists with Prisma queries — cross-ref the dev-prisma skill.
  • General Postgres: the vendor's supabase-postgres-best-practices skill is useful for any Postgres project, not just Supabase-managed — cross-ref the ops-database skill.
  • Security: RLS on every public table; never disable it to "make a query work" — cross-ref .claude/rules/security.md.

Foundation rules preserved

  • YOU MUST enable Row Level Security on every public-schema table before exposing it via PostgREST. No exceptions.
  • YOU MUST use the Supavisor pooler (port 6543) for serverless / edge runtimes. Direct connections (5432) exhaust limits.
  • NEVER SELECT * in production queries — specify columns (security + perf + payload size).
  • YOU MUST store monetary amounts as INTEGER cents, never FLOAT / NUMERIC rounded — avoids drift footgun.
  • YOU MUST index every foreign key and every column in frequent WHERE clauses.
  • YOU MUST use cursor-based pagination (gt('created_at', ...)) for large tables, never range() / OFFSET (slow scan).
  • NEVER commit .env with SUPABASE_URL / service-role key. Always .env.example with placeholders.
  • NEVER expose the service_role key client-side — it bypasses RLS. Use it only in server-side code (Edge Functions, API routes).

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.