Supabase Agent Skill
Master agent skill for Supabase — core principles, security checklist, CLI gotchas, schema workflows, docs lookup
- What
- Master agent skill for Supabase — core principles, security checklist, CLI gotchas, schema workflows, docs lookup
- Cost
- Free
- Needs
- a Muse account with skill installation enabled
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — the master agent skill for all Supabase work from the Supabase team, applying to any task touching the database, Auth, Edge Functions, Realtime, Storage, Vectors, Cron, or Queues: three non-negotiable core principles — verify against the changelog and current docs before implementing (Supabase changes frequently; never trust training data), verify every fix with a test query (a fix without verification is incomplete), and recover from errors instead of looping (after 2–3 failed attempts, reconsider the approach). It ships a Supabase-specific security checklist the agent must run on any auth/RLS/view/storage/user-data task — never use `user_metadata` claims for authorization (user-editable; use `app_metadata`), never expose the `service_role` key in public clients, remember views bypass RLS (use `security_invoker = true` on Postgres 15+), UPDATE requires a SELECT policy, `auth.role()` is deprecated (use the `TO` clause, and `TO authenticated` alone is authentication without authorization — combine it with an ownership predicate in `USING`, plus `WITH CHECK` on UPDATE policies), `SECURITY DEFINER` functions bypass RLS and are callable by all roles in `public`, storage upsert needs INSERT + SELECT + UPDATE, and always pin package versions with lockfiles. It also covers CLI gotchas (discover via `--help` — never guess; `db query` needs CLI v2.79.0+, `db advisors` v2.81.3+; scoped personal access tokens over full-access classic tokens in CI), MCP server setup and connection troubleshooting (401 on the health endpoint is expected; OAuth 2.1 auth flow), docs lookup priority (MCP `search_docs`, then docs pages fetched as markdown), and schema workflows — declarative schemas edited first then migrated, or imperative migrations where `execute_sql`/`supabase db query` iterate freely and migrations are only generated when ready (`supabase migration new`, never invented filenames; never use `apply_migration` to iterate). By @supabase, listed here with credit to its creator. Honest caveats: this is a master policy skill, not a step-by-step product tutorial — pair it with the product docs it points to; the Data API vs RLS distinction (exposing tables is separate from row visibility) and the security checklist are the parts most people get wrong, so read them before touching auth or policies. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Prerequisites: a Muse account with skill installation enabled Install "Supabase Agent Skill" for me. Master agent skill for Supabase — core principles, security checklist, CLI gotchas, schema workflows, docs lookup Repository: https://github.com/supabase/agent-skills/blob/main/skills/supabase/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "supabase-agent-skill". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. save my API key in the vault). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.