Supabase security basics: RLS, key separation, hardening - **name_fr:** Bases de sécurité Supabase : RLS, séparation des clés, durcissement - **tl_en:** Secure a Supabase project — anon vs service_role keys, RLS policies, JWT verification, API hardening - **tl_fr:** Sécuriser un projet Supabase — clés anon vs service_role, politiques RLS, vérification JWT, durcissement API - **creator:** @jeremylongshore - **type:** Agent skill - **url:** https://github.com/jeremylongshore/tons-of-skills-marketplace - **cat:** Security - **kws:** supabase, security, rls, row level security, api keys, jwt, postgres, hardening - **license:** MIT **Description EN:** Curated by Skill Harbor — a Supabase security primer built around the most common mistake: confusing the anon and service_role keys. Covers the two-key model (anon is public, respects RLS; service_role bypasses everything and must never touch the client), Row Level Security policy patterns, JWT verification, and API surface hardening, framed as a production security checklist for auditing a Supabase project. By @jeremylongshore, listed here with credit to its creator. Honest caveats: requires a Supabase project (free tier available — usable for this) and `@supabase/supabase-js`; security guidance only — it tells the agent what to lock down, but you must run the checklist yourself; tables without RLS are publicly readable with just the anon key — this is the whole point of the skill. Discovered via skills.sh. Skill Harbor never reviews the code, review it yourself before use. **Description FR:** Sélectionné par Skill Harbor — un amorce de sécurité Supabase construite autour de l'erreur la plus courante : confondre les clés anon et service_role. Couvre le modèle à deux clés (anon est publique, respecte RLS ; service_role contourne tout et ne doit jamais toucher le client), les patterns de politiques Row Level Security, la vérification JWT et le durcissement de la surface API, le tout comme checklist de sécurité production pour auditer un projet Supabase. Crédit : @jeremylongshore. Bémols honnêtes : nécessite un projet Supabase (niveau gratuit disponible — utilisable ici) et `@supabase/supabase-js` ; conseils de sécurité seulement — il dit à l'agent quoi verrouiller, mais vous devez exécuter la checklist vous-même ; les tables sans RLS sont lisibles publiquement avec la seule clé anon — c'est tout le propos du skill. Découvert via skills.sh. Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. **Install prompt EN:** ``` Prerequisites: a Supabase project (free tier available — usable for this); `@supabase/supabase-js` installed; SUPABASE_URL and SUPABASE_ANON_KEY available to the agent — the service_role key stays server-side only, never in chat Install "Supabase security basics: RLS, key separation, hardening" for me. Give my agent the Supabase security primer — the two-key model, RLS policy patterns, JWT verification and API hardening, framed as a production security checklist Repository: https://github.com/jeremylongshore/tons-of-skills-marketplace/blob/main/plugins/saas-packs/supabase-pack/skills/supabase-security-basics/SKILL.md 1. Fetch the SKILL.md file for the jeremylongshore-tons-of-skills-marketplace-supabase-security-basics skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md into the agent's skills directory, in a folder named "jeremylongshore-tons-of-skills-marketplace-supabase-security-basics". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. run the security checklist against my project, rotate any exposed service_role key). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : un projet Supabase (niveau gratuit disponible — utilisable ici) ; `@supabase/supabase-js` installé ; SUPABASE_URL et SUPABASE_ANON_KEY disponibles pour l'agent — la clé service_role reste côté serveur uniquement, jamais dans le chat Installe-moi « Bases de sécurité Supabase : RLS, séparation des clés, durcissement ». Donne à mon agent l'amorce de sécurité Supabase — le modèle à deux clés, les patterns de politiques RLS, la vérification JWT et le durcissement API, le tout comme checklist de sécurité production Dépôt : https://github.com/jeremylongshore/tons-of-skills-marketplace/blob/main/plugins/saas-packs/supabase-pack/skills/supabase-security-basics/SKILL.md 1. Récupère le fichier SKILL.md du skill jeremylongshore-tons-of-skills-marketplace-supabase-security-basics depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md dans le répertoire des skills de l'agent, dans un dossier nommé « jeremylongshore-tons-of-skills-marketplace-supabase-security-basics ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. exécuter la checklist de sécurité sur mon projet, renouveler toute clé service_role exposée). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Ne me demande jamais de coller des secrets dans le chat — les identifiants passent par le coffre sécurisé ou les variables d'environnement. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
Secure a Supabase project — anon vs service_role keys, RLS policies, JWT verification, API hardening - **tl_fr:** Sécuriser un projet Supabase — clés anon vs service_role, politiques RLS, vérification JWT, durcissement API - **creator:** @jeremylongshore - **type:** Agent skill - **url:** https://github.com/jeremylongshore/tons-of-skills-marketplace - **cat:** Security - **kws:** supabase, security, rls, row level security, api keys, jwt, postgres, hardening - **license:** MIT **Description EN:** Curated by Skill Harbor — a Supabase security primer built around the most common mistake: confusing the anon and service_role keys. Covers the two-key model (anon is public, respects RLS; service_role bypasses everything and must never touch the client), Row Level Security policy patterns, JWT verification, and API surface hardening, framed as a production security checklist for auditing a Supabase project. By @jeremylongshore, listed here with credit to its creator. Honest caveats: requires a Supabase project (free tier available — usable for this) and `@supabase/supabase-js`; security guidance only — it tells the agent what to lock down, but you must run the checklist yourself; tables without RLS are publicly readable with just the anon key — this is the whole point of the skill. Discovered via skills.sh. Skill Harbor never reviews the code, review it yourself before use. **Description FR:** Sélectionné par Skill Harbor — un amorce de sécurité Supabase construite autour de l'erreur la plus courante : confondre les clés anon et service_role. Couvre le modèle à deux clés (anon est publique, respecte RLS ; service_role contourne tout et ne doit jamais toucher le client), les patterns de politiques Row Level Security, la vérification JWT et le durcissement de la surface API, le tout comme checklist de sécurité production pour auditer un projet Supabase. Crédit : @jeremylongshore. Bémols honnêtes : nécessite un projet Supabase (niveau gratuit disponible — utilisable ici) et `@supabase/supabase-js` ; conseils de sécurité seulement — il dit à l'agent quoi verrouiller, mais vous devez exécuter la checklist vous-même ; les tables sans RLS sont lisibles publiquement avec la seule clé anon — c'est tout le propos du skill. Découvert via skills.sh. Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. **Install prompt EN:** ``` Prerequisites: a Supabase project (free tier available — usable for this); `@supabase/supabase-js` installed; SUPABASE_URL and SUPABASE_ANON_KEY available to the agent — the service_role key stays server-side only, never in chat Install "Supabase security basics: RLS, key separation, hardening" for me. Give my agent the Supabase security primer — the two-key model, RLS policy patterns, JWT verification and API hardening, framed as a production security checklist Repository: https://github.com/jeremylongshore/tons-of-skills-marketplace/blob/main/plugins/saas-packs/supabase-pack/skills/supabase-security-basics/SKILL.md 1. Fetch the SKILL.md file for the jeremylongshore-tons-of-skills-marketplace-supabase-security-basics skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md into the agent's skills directory, in a folder named "jeremylongshore-tons-of-skills-marketplace-supabase-security-basics". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. run the security checklist against my project, rotate any exposed service_role key). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : un projet Supabase (niveau gratuit disponible — utilisable ici) ; `@supabase/supabase-js` installé ; SUPABASE_URL et SUPABASE_ANON_KEY disponibles pour l'agent — la clé service_role reste côté serveur uniquement, jamais dans le chat Installe-moi « Bases de sécurité Supabase : RLS, séparation des clés, durcissement ». Donne à mon agent l'amorce de sécurité Supabase — le modèle à deux clés, les patterns de politiques RLS, la vérification JWT et le durcissement API, le tout comme checklist de sécurité production Dépôt : https://github.com/jeremylongshore/tons-of-skills-marketplace/blob/main/plugins/saas-packs/supabase-pack/skills/supabase-security-basics/SKILL.md 1. Récupère le fichier SKILL.md du skill jeremylongshore-tons-of-skills-marketplace-supabase-security-basics depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md dans le répertoire des skills de l'agent, dans un dossier nommé « jeremylongshore-tons-of-skills-marketplace-supabase-security-basics ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. exécuter la checklist de sécurité sur mon projet, renouveler toute clé service_role exposée). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Ne me demande jamais de coller des secrets dans le chat — les identifiants passent par le coffre sécurisé ou les variables d'environnement. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
- What
- Secure a Supabase project — anon vs service_role keys, RLS policies, JWT verification, API hardening - **tl_fr:** Sécuriser un projet Supabase — clés anon vs service_role, politiques RLS, vérification JWT, durcissement API - **creator:** @jeremylongshore - **type:** Agent skill - **url:** https://github.com/jeremylongshore/tons-of-skills-marketplace - **cat:** Security - **kws:** supabase, security, rls, row level security, api keys, jwt, postgres, hardening - **license:** MIT **Description EN:** Curated by Skill Harbor — a Supabase security primer built around the most common mistake: confusing the anon and service_role keys. Covers the two-key model (anon is public, respects RLS; service_role bypasses everything and must never touch the client), Row Level Security policy patterns, JWT verification, and API surface hardening, framed as a production security checklist for auditing a Supabase project. By @jeremylongshore, listed here with credit to its creator. Honest caveats: requires a Supabase project (free tier available — usable for this) and `@supabase/supabase-js`; security guidance only — it tells the agent what to lock down, but you must run the checklist yourself; tables without RLS are publicly readable with just the anon key — this is the whole point of the skill. Discovered via skills.sh. Skill Harbor never reviews the code, review it yourself before use. **Description FR:** Sélectionné par Skill Harbor — un amorce de sécurité Supabase construite autour de l'erreur la plus courante : confondre les clés anon et service_role. Couvre le modèle à deux clés (anon est publique, respecte RLS ; service_role contourne tout et ne doit jamais toucher le client), les patterns de politiques Row Level Security, la vérification JWT et le durcissement de la surface API, le tout comme checklist de sécurité production pour auditer un projet Supabase. Crédit : @jeremylongshore. Bémols honnêtes : nécessite un projet Supabase (niveau gratuit disponible — utilisable ici) et `@supabase/supabase-js` ; conseils de sécurité seulement — il dit à l'agent quoi verrouiller, mais vous devez exécuter la checklist vous-même ; les tables sans RLS sont lisibles publiquement avec la seule clé anon — c'est tout le propos du skill. Découvert via skills.sh. Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. **Install prompt EN:** ``` Prerequisites: a Supabase project (free tier available — usable for this); `@supabase/supabase-js` installed; SUPABASE_URL and SUPABASE_ANON_KEY available to the agent — the service_role key stays server-side only, never in chat Install "Supabase security basics: RLS, key separation, hardening" for me. Give my agent the Supabase security primer — the two-key model, RLS policy patterns, JWT verification and API hardening, framed as a production security checklist Repository: https://github.com/jeremylongshore/tons-of-skills-marketplace/blob/main/plugins/saas-packs/supabase-pack/skills/supabase-security-basics/SKILL.md 1. Fetch the SKILL.md file for the jeremylongshore-tons-of-skills-marketplace-supabase-security-basics skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md into the agent's skills directory, in a folder named "jeremylongshore-tons-of-skills-marketplace-supabase-security-basics". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. run the security checklist against my project, rotate any exposed service_role key). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : un projet Supabase (niveau gratuit disponible — utilisable ici) ; `@supabase/supabase-js` installé ; SUPABASE_URL et SUPABASE_ANON_KEY disponibles pour l'agent — la clé service_role reste côté serveur uniquement, jamais dans le chat Installe-moi « Bases de sécurité Supabase : RLS, séparation des clés, durcissement ». Donne à mon agent l'amorce de sécurité Supabase — le modèle à deux clés, les patterns de politiques RLS, la vérification JWT et le durcissement API, le tout comme checklist de sécurité production Dépôt : https://github.com/jeremylongshore/tons-of-skills-marketplace/blob/main/plugins/saas-packs/supabase-pack/skills/supabase-security-basics/SKILL.md 1. Récupère le fichier SKILL.md du skill jeremylongshore-tons-of-skills-marketplace-supabase-security-basics depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md dans le répertoire des skills de l'agent, dans un dossier nommé « jeremylongshore-tons-of-skills-marketplace-supabase-security-basics ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. exécuter la checklist de sécurité sur mon projet, renouveler toute clé service_role exposée). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Ne me demande jamais de coller des secrets dans le chat — les identifiants passent par le coffre sécurisé ou les variables d'environnement. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
- Cost
- Free
- Needs
- a Supabase project (free tier available — usable for this); `@supabase/supabase-js` installed; SUPABASE_URL and SUPABASE_ANON_KEY available to the agent — the service_role key stays server-side only, never in chat
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — a Supabase security primer built around the most common mistake: confusing the anon and service_role keys. Covers the two-key model (anon is public, respects RLS; service_role bypasses everything and must never touch the client), Row Level Security policy patterns, JWT verification, and API surface hardening, framed as a production security checklist for auditing a Supabase project. By @jeremylongshore, listed here with credit to its creator. Honest caveats: requires a Supabase project (free tier available — usable for this) and `@supabase/supabase-js`; security guidance only — it tells the agent what to lock down, but you must run the checklist yourself; tables without RLS are publicly readable with just the anon key — this is the whole point of the skill. Discovered via skills.sh. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Prerequisites: a Supabase project (free tier available — usable for this); `@supabase/supabase-js` installed; SUPABASE_URL and SUPABASE_ANON_KEY available to the agent — the service_role key stays server-side only, never in chat Install "Supabase security basics: RLS, key separation, hardening" for me. Give my agent the Supabase security primer — the two-key model, RLS policy patterns, JWT verification and API hardening, framed as a production security checklist Repository: https://github.com/jeremylongshore/tons-of-skills-marketplace/blob/main/plugins/saas-packs/supabase-pack/skills/supabase-security-basics/SKILL.md 1. Fetch the SKILL.md file for the jeremylongshore-tons-of-skills-marketplace-supabase-security-basics skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md into the agent's skills directory, in a folder named "jeremylongshore-tons-of-skills-marketplace-supabase-security-basics". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. run the security checklist against my project, rotate any exposed service_role key). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. Never ask me to paste secrets in chat — credentials go through the secure vault or environment variables. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.