Agent skill

Supabase

by alinaqi in alinaqi/maggy

Core Supabase CLI, migrations, RLS, Edge Functions. An agent skill from alinaqi/maggy.

MITAuto-check: notesDatabases

Install Supabase

skills CLI
$ npx skills add alinaqi/maggy --skill supabase -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alinaqi/maggy supabase --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alinaqi/maggy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/supabase .claude/skills/supabase && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supabase
GitHub stars
707
Token cost
~2.4k tokens
SKILL.md length
214 words
Files
1
Skills in repo
71
Repo updated
First seen
Licence
MIT

At a glance

Core Supabase CLI, migrations, RLS, Edge Functions. An agent skill from alinaqi/maggy.

  • Databases work in your project
  • SKILL.md covers Core Principle, Supabase Stack, CLI Setup and Migration Workflow, plus 5 more sections
  • Calls supabase, brew and npm; reaches supabase.com and xxxxx.supabase.co; needs SUPABASE_ANON_KEY and SUPABASE_ACCESS_TOKEN

What it does

Supabase is an agent skill from alinaqi/maggy. Core Supabase CLI, migrations, RLS, Edge Functions

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Databases. It works with Supabase. The repository describes itself as: What started as an opinionated Claude Code setup kit is now an autonomous AI engineering command center. The licence is MIT.

When your agent uses it

  • Databases work in your project

Example prompts

  • “/supabase”

Requirements

  • Node.js
  • A credential in SUPABASE_ANON_KEY
  • A credential in SUPABASE_SERVICE_ROLE_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 72a456e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • supabase
    • brew
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • supabase.com
    • xxxxx.supabase.co
    • deno.land
    • esm.sh

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SUPABASE_ANON_KEY
    • SUPABASE_ACCESS_TOKEN
    • SUPABASE_DB_PASSWORD
    • SUPABASE_SERVICE_ROLE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Supabase loads about 2.4k tokens when it runs. Until then it costs about 15 tokens; SKILL.md has 214 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~15
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:6
    hs: ["supabase/**", "**/supabase.*", "**/.env*"]
  • NoteMentions a .env fileSKILL.md:226
    # .env.local (local development)
  • NoteMentions a .env fileSKILL.md:231
    # .env.production (remote)
  • NoteMentions a .env fileSKILL.md:426
    - **Committing .env** - Add to .gitignore

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alinaqi/maggy at commit 72a456e, republished under its MIT licence (© alinaqi). 214 words, ~2,439 tokens.

Download SKILL.mdSave it as .claude/skills/supabase/SKILL.md (or your agent's skills folder).
name
supabase
description
Core Supabase CLI, migrations, RLS, Edge Functions
when-to-use
When working with Supabase - database, auth, storage, or edge functions
user-invocable
false
paths
supabase/**, **/supabase.*, **/.env*
effort
medium

Supabase Core Skill

Core concepts, CLI workflow, and patterns common to all Supabase projects.

Sources: Supabase Docs | Supabase CLI


Core Principle

Local-first, migrations in version control, never touch production directly.

Develop locally with the Supabase CLI, capture all changes as migrations, and deploy through CI/CD.


Supabase Stack

ServicePurpose
DatabasePostgreSQL with extensions
AuthUser authentication, OAuth providers
StorageFile storage with RLS
Edge FunctionsServerless Deno functions
RealtimeWebSocket subscriptions
VectorAI embeddings (pgvector)

CLI Setup

Install & Login
bash
# macOS
brew install supabase/tap/supabase

# npm (alternative)
npm install -g supabase

# Login
supabase login
Initialize Project
bash
# In your project directory
supabase init

# Creates:
# supabase/
# ├── config.toml      # Local config
# ├── seed.sql         # Seed data
# └── migrations/      # SQL migrations
bash
# Get project ref from dashboard URL: https://supabase.com/dashboard/project/<ref>
supabase link --project-ref <project-id>

# Pull existing schema
supabase db pull
Start Local Stack
bash
supabase start

# Output:
# API URL: http://localhost:54321
# GraphQL URL: http://localhost:54321/graphql/v1
# DB URL: postgresql://postgres:postgres@localhost:54322/postgres
# Studio URL: http://localhost:54323
# Anon key: eyJ...
# Service role key: eyJ...

Migration Workflow

Option 1: Dashboard + Diff (Quick Prototyping)
bash
# 1. Make changes in local Studio (localhost:54323)
# 2. Generate migration from diff
supabase db diff -f <migration_name>

# 3. Review generated SQL
cat supabase/migrations/*_<migration_name>.sql

# 4. Reset to test
supabase db reset
bash
# 1. Create empty migration
supabase migration new create_users_table

# 2. Edit the migration file
# supabase/migrations/<timestamp>_create_users_table.sql

# 3. Apply locally
supabase db reset
Option 3: ORM Migrations (Best DX)

Use Drizzle (TypeScript) or SQLAlchemy (Python) - see framework-specific skills.

Deploy Migrations
bash
# Push to remote (staging/production)
supabase db push

# Check migration status
supabase migration list

Database Patterns

Enable RLS on All Tables
sql
-- Always enable RLS
ALTER TABLE public.profiles ENABLE ROW LEVEL SECURITY;

-- Default deny - must create policies
CREATE POLICY "Users can view own profile"
  ON public.profiles
  FOR SELECT
  USING (auth.uid() = id);
Common RLS Policies
sql
-- Public read
CREATE POLICY "Public read access"
  ON public.posts FOR SELECT
  USING (true);

-- Authenticated users only
CREATE POLICY "Authenticated users can insert"
  ON public.posts FOR INSERT
  WITH CHECK (auth.role() = 'authenticated');

-- Owner access
CREATE POLICY "Users can update own records"
  ON public.posts FOR UPDATE
  USING (auth.uid() = user_id);

-- Admin access (using custom claim)
CREATE POLICY "Admins have full access"
  ON public.posts FOR ALL
  USING (auth.jwt() ->> 'role' = 'admin');
sql
-- Profile table linked to auth
CREATE TABLE public.profiles (
  id UUID PRIMARY KEY REFERENCES auth.users(id) ON DELETE CASCADE,
  username TEXT UNIQUE NOT NULL,
  avatar_url TEXT,
  created_at TIMESTAMPTZ DEFAULT NOW()
);

-- Auto-create profile on signup
CREATE OR REPLACE FUNCTION public.handle_new_user()
RETURNS TRIGGER AS $$
BEGIN
  INSERT INTO public.profiles (id, username)
  VALUES (NEW.id, NEW.email);
  RETURN NEW;
END;
$$ LANGUAGE plpgsql SECURITY DEFINER;

CREATE TRIGGER on_auth_user_created
  AFTER INSERT ON auth.users
  FOR EACH ROW EXECUTE FUNCTION public.handle_new_user();

Seed Data

supabase/seed.sql
sql
-- Runs on `supabase db reset`
-- Use ON CONFLICT for idempotency

INSERT INTO public.profiles (id, username, avatar_url)
VALUES
  ('d0e1f2a3-b4c5-6d7e-8f9a-0b1c2d3e4f5a', 'testuser', null),
  ('a1b2c3d4-e5f6-7a8b-9c0d-1e2f3a4b5c6d', 'admin', null)
ON CONFLICT (id) DO NOTHING;

Environment Variables

Required Variables
bash
# Public (safe for client-side)
SUPABASE_URL=https://xxxxx.supabase.co
SUPABASE_ANON_KEY=eyJ...

# Private (server-side only - NEVER expose)
SUPABASE_SERVICE_ROLE_KEY=eyJ...
DATABASE_URL=postgresql://postgres.[ref]:[password]@aws-0-region.pooler.supabase.com:6543/postgres
Local vs Production
bash
# .env.local (local development)
SUPABASE_URL=http://localhost:54321
SUPABASE_ANON_KEY=<from supabase start>
DATABASE_URL=postgresql://postgres:postgres@localhost:54322/postgres

# .env.production (remote)
SUPABASE_URL=https://xxxxx.supabase.co
SUPABASE_ANON_KEY=<from dashboard>
DATABASE_URL=<connection pooler URL>
Connection Pooling
bash
# Transaction mode (recommended for serverless)
# Add ?pgbouncer=true to URL
DATABASE_URL=postgresql://...@pooler.supabase.com:6543/postgres?pgbouncer=true

# Session mode (for migrations, long transactions)
DATABASE_URL=postgresql://...@pooler.supabase.com:5432/postgres

Edge Functions

Create Function
bash
supabase functions new hello-world
Basic Structure
typescript
// supabase/functions/hello-world/index.ts
import { serve } from 'https://deno.land/std@0.168.0/http/server.ts';

serve(async (req) => {
  const { name } = await req.json();

  return new Response(
    JSON.stringify({ message: `Hello ${name}!` }),
    { headers: { 'Content-Type': 'application/json' } }
  );
});
With Auth Context
typescript
import { serve } from 'https://deno.land/std@0.168.0/http/server.ts';
import { createClient } from 'https://esm.sh/@supabase/supabase-js@2';

serve(async (req) => {
  const supabase = createClient(
    Deno.env.get('SUPABASE_URL') ?? '',
    Deno.env.get('SUPABASE_ANON_KEY') ?? '',
    {
      global: {
        headers: { Authorization: req.headers.get('Authorization')! },
      },
    }
  );

  const { data: { user } } = await supabase.auth.getUser();

  if (!user) {
    return new Response('Unauthorized', { status: 401 });
  }

  return new Response(JSON.stringify({ user_id: user.id }));
});
Deploy
bash
# Serve locally
supabase functions serve

# Deploy single function
supabase functions deploy hello-world

# Deploy all
supabase functions deploy

Storage

Create Bucket (in migration)
sql
INSERT INTO storage.buckets (id, name, public)
VALUES ('avatars', 'avatars', true);

-- Storage policies
CREATE POLICY "Avatar images are publicly accessible"
  ON storage.objects FOR SELECT
  USING (bucket_id = 'avatars');

CREATE POLICY "Users can upload own avatar"
  ON storage.objects FOR INSERT
  WITH CHECK (
    bucket_id = 'avatars' AND
    auth.uid()::text = (storage.foldername(name))[1]
  );

CLI Quick Reference

bash
# Lifecycle
supabase start                   # Start local stack
supabase stop                    # Stop local stack
supabase status                  # Show status & credentials

# Database
supabase db reset                # Reset + migrations + seed
supabase db push                 # Push to remote
supabase db pull                 # Pull remote schema
supabase db diff -f <name>       # Generate migration from diff
supabase db lint                 # Check for issues

# Migrations
supabase migration new <name>    # Create migration
supabase migration list          # List migrations
supabase migration up            # Apply pending (remote)

# Functions
supabase functions new <name>    # Create function
supabase functions serve         # Local dev
supabase functions deploy        # Deploy all

# Types
supabase gen types typescript --local > types/database.ts

# Project
supabase link --project-ref <id> # Link to remote
supabase projects list           # List projects

CI/CD Template

yaml
# .github/workflows/supabase.yml
name: Supabase CI/CD

on:
  push:
    branches: [main]
  pull_request:

env:
  SUPABASE_ACCESS_TOKEN: ${{ secrets.SUPABASE_ACCESS_TOKEN }}
  SUPABASE_DB_PASSWORD: ${{ secrets.SUPABASE_DB_PASSWORD }}
  SUPABASE_PROJECT_ID: ${{ secrets.SUPABASE_PROJECT_ID }}

jobs:
  test:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: supabase/setup-cli@v1

      - name: Start Supabase
        run: supabase start

      - name: Run migrations
        run: supabase db reset

      - name: Lint database
        run: supabase db lint

  deploy:
    needs: test
    if: github.ref == 'refs/heads/main'
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: supabase/setup-cli@v1

      - name: Link project
        run: supabase link --project-ref $SUPABASE_PROJECT_ID

      - name: Push migrations
        run: supabase db push

      - name: Deploy functions
        run: supabase functions deploy

Anti-Patterns

  • Direct production changes - Always use migrations
  • Disabled RLS - Enable on all user-data tables
  • Service key in client - Never expose service role key
  • No connection pooling - Use pooler for serverless
  • Committing .env - Add to .gitignore
  • Skipping migration review - Always check generated SQL
  • No seed data - Use seed.sql for consistent local dev

© alinaqi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/supabase of alinaqi/maggy.

Open the folder on GitHubat commit 72a456e

Compare with similar skills

Supabase next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supabase compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supabase this skillalinaqi/maggy707—~2.4kAutomated safety check: NotesMIT
Supabase Cost Tuningjeremylongshore/tons-of-skills-marketplace2.8k—~2kAutomated safety check: PassMIT
Supabase Load Scalejeremylongshore/tons-of-skills-marketplace2.8k—~1.7kAutomated safety check: PassMIT
Supabase Migration Deep Divejeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: PassMIT
Supabase Performance Tuningjeremylongshore/tons-of-skills-marketplace2.8k—~3.2kAutomated safety check: PassMIT
Take Doc Screenshotspgplex/pgconsole155—~841Automated safety check: PassApache-2.0

Similar skills

  • Supabase Cost Tuning

    jeremylongshore/tons-of-skills-marketplace

    Optimize Supabase costs through plan selection, database tuning, storage cleanup, connection pooling, and Edge Function optimization.

    2.8k GitHub stars~2k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Supabase Load Scale

    jeremylongshore/tons-of-skills-marketplace

    A skill your agent uses when preparing a Supabase project for production load — traffic spikes, connection-limit tuning, read replicas for analytics queries, CDN caching for Storage, regional Edge…

    2.8k GitHub stars~1.7k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Supabase Migration Deep Dive

    jeremylongshore/tons-of-skills-marketplace

    Database migration patterns with the Supabase CLI: npx supabase migration new, zero-downtime migrations, data backfill strategies, schema versioning, rollback strategies, and TypeScript type…

    2.8k GitHub stars~1.9k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Supabase Performance Tuning

    jeremylongshore/tons-of-skills-marketplace

    Optimize Supabase query performance with indexes, EXPLAIN ANALYZE, connection pooling, column selection, pagination, RPC functions, materialized views, and diagnostics.

    2.8k GitHub stars~3.2k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Take Doc Screenshots

    pgplex/pgconsole

    Take screenshots of the running pgconsole app for documentation.

    155 GitHub stars~841 tokensUpdated 1 mo ago
    DatabasesAuto-check passed
  • Test The Docs

    supabase/supabase

    Official

    Execute runnable docs snippets and examples inside a disposable Docker Compose sandbox (runner container + local Supabase stack via supabase start).

    111k GitHub stars~1.3k tokensUpdated today
    DatabasesAuto-check passed

More from alinaqi/maggy

All 71 skills in this repo
  • Aeo Optimization

    alinaqi/maggy

    AI Engine Optimization - semantic triples, page templates, content clusters for AI citations

    707 GitHub stars~3.7k tokensUpdated 15 days ago
    Auto-check passed
  • Agent Teams

    alinaqi/maggy

    Claude Code Agent Teams - default team-based development with strict TDD pipeline enforcement

    707 GitHub stars~5k tokensUpdated 15 days ago
    Auto-check: notes
  • AI Models

    alinaqi/maggy

    Latest AI models reference - Claude, OpenAI, Gemini, Eleven Labs, Replicate

    707 GitHub stars~4.1k tokensUpdated 15 days ago
    Auto-check passed
  • Android Java

    alinaqi/maggy

    Android Java development with MVVM, ViewBinding, and Espresso testing

    707 GitHub stars~3.9k tokensUpdated 15 days ago
    Auto-check: notes
  • Android Kotlin

    alinaqi/maggy

    Android Kotlin development with Coroutines, Jetpack Compose, Hilt, and MockK testing

    707 GitHub stars~3k tokensUpdated 15 days ago
    Auto-check passed
  • Autonomous Testing

    alinaqi/maggy

    AI-driven testing agent that auto-discovers, generates, executes, evaluates, and fixes tests for any project type

    707 GitHub stars~1.1k tokensUpdated 15 days ago
    Auto-check passed

Works with

Categories

Questions about Supabase

What does Supabase do?

Core Supabase CLI, migrations, RLS, Edge Functions. An agent skill from alinaqi/maggy. Supabase is an agent skill from alinaqi/maggy.

When should I use Supabase?

Supabase fits situations like: databases work in your project.

How do I install Supabase in Claude Code?

Run `npx skills add alinaqi/maggy --skill supabase -a claude-code`. Or copy the skill folder (skills/supabase in alinaqi/maggy) into .claude/skills/supabase in your project. Claude Code loads it when a task matches its description.

How do I install Supabase in Codex?

Run `npx skills add alinaqi/maggy --skill supabase -a codex`. Or copy the skill folder (skills/supabase in alinaqi/maggy) into .agents/skills/supabase in your project. Codex loads it when a task matches its description.

Can I use Supabase in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alinaqi/maggy --skill supabase -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supabase, .gemini/skills/supabase, .github/skills/supabase and .opencode/skills/supabase in your project.

What does Supabase need to run?

Going by SKILL.md and its folder, Supabase needs the command-line tools its instructions call (supabase, brew and npm) and credentials named SUPABASE_ANON_KEY, SUPABASE_ACCESS_TOKEN, SUPABASE_DB_PASSWORD and SUPABASE_SERVICE_ROLE_KEY. Our summary lists: Node.js; A credential in SUPABASE_ANON_KEY; A credential in SUPABASE_SERVICE_ROLE_KEY.

Does Supabase access the network?

SKILL.md names 4 domains. In commands or code: supabase.com, xxxxx.supabase.co, deno.land and esm.sh; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Supabase safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Supabase use?

Supabase is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supabase use?

About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Supabase?

Skills that share tags, products or a category with Supabase: Supabase Cost Tuning (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Supabase Load Scale (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Supabase Migration Deep Dive (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Supabase Performance Tuning (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supabase?

alinaqi (a GitHub user) maintains it in alinaqi/maggy, which has 707 GitHub stars. The repository holds 71 skills in this directory. The repository was last updated on September 24, 2026.

Source: alinaqi/maggy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.