agentsclimarketplace

Storage upload

Skill m-binimran/dev-pack/skills/storage-upload

Guardrails, skills, loops, hooks & review agents for database + website builders on Claude Code (Next.js + Supabase).

Install
npx -y skills add m-binimran/dev-pack --skill storage-upload

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Handle file uploads with Supabase Storage in Next.js — buckets, RLS on objects, signed URLs, image handling, and size/type validation. Use when adding avatars, portfolio images, document uploads, or any user file.

SKILL.md

1.5 KB, as published. Nobody here has run it

storage-upload

User files are untrusted input. Validate, scope access, and never expose a writable public bucket.

Process

  1. Bucket per purpose, private by default. Public bucket only for genuinely public assets. Set fileSizeLimit and allowedMimeTypes on the bucket.
  2. RLS on storage.objects: users may only write/read paths they own — e.g. key prefixed with their auth.uid(). Policies mirror the rls-policy skill (using + with check).
  3. Validate before upload: size and MIME on the client for UX, and again server-side / via bucket limits for safety. Reject executables and oversized files.
  4. Serve privately via signed URLs: createSignedUrl(path, expiresIn) with a short TTL. Don't hand out permanent public URLs for private content.
  5. Images: store an original; render through next/image (or a transform) — sized to avoid CLS. Strip EXIF if privacy matters.

Output

  • Bucket config, the storage RLS policies, the upload handler (with validation), and how files are served (signed URL vs public).

Guardrails

  • Never make a user-writable bucket public-read without considering what else lands in it.
  • Path scoping by auth.uid() is mandatory for private user files.
  • Size/type limits enforced server-side (bucket), not just in the UI.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.