A skill your agent uses when users report access denied errors, see wrong data, RLS policies are not working, or when troubleshooting Row-Level Security issues in Butterbase

MITAuto-check passedDevelopment

Install Debug Rls

skills CLI
$ npx skills add butterbase-ai/butterbase-skills --skill debug-rls -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install butterbase-ai/butterbase-skills debug-rls --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/butterbase-ai/butterbase-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/debug-rls .claude/skills/debug-rls && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
debug-rls
GitHub stars
534
Token cost
~3.5k tokens
SKILL.md length
1,638 words
Files
1
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when users report access denied errors, see wrong data, RLS policies are not working, or when troubleshooting Row-Level Security issues in Butterbase

  • Works in 8 steps: Overview → Quick Diagnosis → The Three Roles → …
  • Users report access denied errors
  • SKILL.md covers 1. Overview, 2. Quick Diagnosis, 3. The Three Roles and 4. Four-Step Debugging Protocol, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Debug Rls is an agent skill from butterbase-ai/butterbase-skills. Use when users report access denied errors, see wrong data, RLS policies are not working, or when troubleshooting Row-Level Security issues in Butterbase

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The repository describes itself as: Plugin for Butterbase.ai. The licence is MIT.

When your agent uses it

  • Users report access denied errors
  • RLS policies are not working
  • Troubleshooting Row-Level Security issues in Butterbase

Example prompts

  • “/debug-rls”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Overview
  2. Quick Diagnosis
  3. The Three Roles
  4. Four-Step Debugging Protocol
  5. Common Fixes
  6. Expression Reference
  7. Verification Checklist
  8. Anti-Patterns to Avoid

What it can do on your machine

Read from SKILL.md and the folder at commit aa8ae69. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Debug Rls loads about 3.5k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 1,638 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from butterbase-ai/butterbase-skills at commit aa8ae69, republished under its MIT licence (© butterbase-ai). 1,638 words, ~3,522 tokens.

Download SKILL.mdSave it as .claude/skills/debug-rls/SKILL.md (or your agent's skills folder).
name
debug-rls
description
Use when users report access denied errors, see wrong data, RLS policies are not working, or when troubleshooting Row-Level Security issues in Butterbase

debug-rls

Systematic methodology for debugging Row-Level Security issues in Butterbase. Uses role simulation (as_role/as_user parameters) to verify policy behavior without needing real user sessions.


1. Overview

Row-Level Security (RLS) in Butterbase controls which rows each database role can see or modify. When RLS is misconfigured, users may see no data, too much data, or get unexpected errors on insert. This skill walks through a repeatable four-step process to identify and fix the root cause.

Key principle: MCP tools default to the service key (bb_sk_...), which bypasses all RLS. Always use as_role/as_user to simulate the role your frontend actually uses.


2. Quick Diagnosis

Match the symptom your user reports to the most likely cause before diving into the full protocol.

SymptomLikely cause
User sees no rowsRLS enabled but no policy for butterbase_user role
User sees ALL rowsRLS not enabled on the table, or request uses service key (bb_sk_)
Insert fails with AUTH_RLS_POLICY_VIOLATIONNo INSERT policy, or user_column not auto-populated
User sees other users' dataPolicy USING expression is wrong, or user isolation not set up
Anonymous user gets 403No policy for butterbase_anon role
Works in MCP tools but not from frontendMCP uses service key (bypasses RLS); frontend uses end-user JWT

3. The Three Roles

Butterbase automatically assigns a database role based on the auth header of each request. You never create these roles — they are built in.

Auth headerDatabase roleBehavior
Nonebutterbase_anonDefault deny. Only sees rows allowed by explicit anon policies.
Valid end-user JWTbutterbase_usercurrent_user_id() returns their UUID. Sees rows matching their policies.
API key (bb_sk_...)butterbase_serviceBypasses ALL RLS. Sees everything. Used by MCP tools and admin operations.

Important: When you call select_rows or insert_row without as_role, you are always running as butterbase_service. This means the result tells you nothing about what a real user would see. Use as_role to simulate the correct role.


4. Four-Step Debugging Protocol

Work through these steps in order. Each step narrows down the cause.


Step 1: Check if RLS is enabled

Call manage_rls with action: "list" for the app_id:

manage_rls(app_id: "app_abc123", action: "list")

Returns { policies: [...], tables_with_rls: [...] }. The tables_with_rls array shows which tables have RLS turned on but no policies yet (effective default deny).

  • Look for the table in the response.
  • If the table has no policies, RLS might not be enabled at all — or it was enabled but no policies were added, which causes a default deny for all non-service roles.
  • If the table does appear, move to Step 2 to inspect what the policies actually do.

A table with RLS enabled but zero policies is inaccessible to butterbase_anon and butterbase_user. The butterbase_service role is unaffected.


Step 2: Inspect existing policies

Read each policy's fields carefully:

FieldWhat it means
policynameHuman-readable name for the policy
cmdWhich SQL command it applies to: SELECT, INSERT, UPDATE, DELETE, or ALL
qualThe USING expression — filters which rows are visible or affected
with_checkThe WITH CHECK expression — validates new/updated row data on write
rolesWhich database role(s) this policy applies to

Common issues to look for:

  • Policy exists for butterbase_user but not butterbase_anon (anonymous users blocked)
  • Policy exists for SELECT but not INSERT (reads work, writes fail)
  • USING expression references the wrong column (e.g., owner_id instead of user_id)
  • Policy covers ALL commands but the WITH CHECK expression is missing (inserts may fail silently)

Step 3: Test as different roles

Use the as_role and as_user parameters on select_rows and insert_row to simulate each role. This is the most direct way to reproduce what a real user experiences.

# Test SELECT as an authenticated user
select_rows(
  app_id: "app_abc123",
  table: "posts",
  as_role: "user",
  as_user: "user-uuid-here"
)

# Test SELECT as anonymous
select_rows(
  app_id: "app_abc123",
  table: "posts",
  as_role: "anon"
)

# Test INSERT as an authenticated user
insert_row(
  app_id: "app_abc123",
  table: "posts",
  data: { title: "Hello" },
  as_role: "user",
  as_user: "user-uuid-here"
)

Compare results between roles:

ScenarioExpected result
No as_role (service)All rows returned, inserts succeed — RLS bypassed
as_role: "user"Only the user's own rows (if isolation policy exists)
as_role: "anon"Only publicly readable rows (if anon policy exists), or empty

If results differ from expectations, you have confirmed which role/command combination is misconfigured.

Without as_role, MCP tools always use the service key and bypass RLS. Never use this to validate that RLS is working.


Step 4: Check auto-populate trigger

This step specifically diagnoses AUTH_RLS_POLICY_VIOLATION on INSERT.

  1. Insert a row as a user (using as_role: "user"):
insert_row(
  app_id: "app_abc123",
  table: "posts",
  data: { title: "Test post" },
  as_role: "user",
  as_user: "user-uuid-here"
)
  1. Check if the user_id / author_id column was auto-populated in the returned row.

  2. If the column is NULL or missing from the response, the auto-populate trigger is missing. The RLS policy requires user_id = current_user_id(), but the column was never filled in, so the WITH CHECK fails.

Root cause: enable_rls + create_policy (without user_column) does not install an auto-populate trigger. Clients would need to manually include the user column in every POST body — which most frontends don't do.

Fix: See Fix 1 or Fix 3 in the next section.


5. Common Fixes

Four ready-to-use recipes. Copy the MCP tool call that matches your situation.


Fix 1: Enable basic user isolation

Use this when a table has no RLS at all and you want users to only see their own rows.

manage_rls(
  app_id: "app_abc123",
  action: "create_user_isolation",
  table_name: "posts",
  user_column: "author_id"
)

What this creates automatically:

  • RLS enabled on the table
  • User isolation policy: author_id = current_user_id()::uuid for ALL commands
  • Auto-populate trigger: sets author_id from the JWT on INSERT (clients don't need to send it)
  • Service bypass: butterbase_service always passes through (built into the platform)

This is the recommended starting point for any user-owned data table.


Fix 2: Add public read access

Use this when you want anonymous users (or all authenticated users) to be able to read certain rows — for example, published blog posts or public profiles.

manage_rls(
  app_id: "app_abc123",
  action: "create_policy",
  table_name: "posts",
  policy_name: "public_read_published",
  command: "SELECT",
  role: "anon",
  using_expression: "published = true"
)

This lets anonymous users read posts where published = true. They still cannot read unpublished posts or write anything.

To also allow authenticated (non-anonymous) users to read public rows, add a second policy with role: "user" and the same using_expression.

Alternatively, if you haven't set up user isolation yet, use the public_read_column shorthand:

manage_rls(
  app_id: "app_abc123",
  action: "create_user_isolation",
  table_name: "posts",
  user_column: "author_id",
  public_read_column: "published"
)

This sets up user isolation and adds permissive SELECT policies for both butterbase_user and butterbase_anon to read rows where published = true — in a single call.


Show full SKILL.md (666 more words)Show less
Fix 3: Fix missing auto-populate trigger

Use this when inserts fail with AUTH_RLS_POLICY_VIOLATION and the user column is NULL after insert (diagnosed in Step 4).

Option A — Recommended: replace with create_user_isolation

The cleanest fix if you're starting fresh or can replace the existing policy:

manage_rls(
  app_id: "app_abc123",
  action: "create_user_isolation",
  table_name: "posts",
  user_column: "author_id"
)

Always includes the auto-populate trigger. No manual step needed.

Option B — additive: pass user_column on create_policy

Use this when you want to keep existing policies but just install the trigger:

manage_rls(
  app_id: "app_abc123",
  action: "create_policy",
  table_name: "posts",
  policy_name: "posts_user_insert",
  command: "INSERT",
  role: "user",
  with_check_expression: "author_id = current_user_id()::uuid",
  user_column: "author_id"
)

Passing user_column to create_policy installs the auto-populate trigger alongside the policy.

Without the trigger: clients must include the user column (author_id, user_id, etc.) in every POST body. Most frontends don't do this, causing all inserts to fail with RLS violations.


Fix 4: Add cross-table restrictive check

Use this when you need to enforce a condition that involves another table — for example, only allowing comments on published posts.

manage_rls(
  app_id: "app_abc123",
  action: "create_policy",
  table_name: "comments",
  policy_name: "comments_on_public_posts_only",
  command: "INSERT",
  role: "user",
  with_check_expression: "EXISTS (SELECT 1 FROM posts WHERE posts.id = post_id AND posts.published = true)",
  restrictive: true
)

Why restrictive: true?

A RESTRICTIVE policy is AND'd with all permissive policies. Without it, if the user isolation policy already passes (because user_id = current_user_id()), the cross-table check would never be evaluated — users could comment on private posts.

Setting restrictive: true ensures this check runs in addition to any permissive policies, so both conditions must be satisfied.

Use RESTRICTIVE policies sparingly — only when a condition must never be bypassed by another policy.


6. Expression Reference

Helper functions
ExpressionReturnsUsed in
current_user_id()Authenticated user's UUID as textUSING, WITH CHECK
current_user_id()::uuidSame, cast to UUID typeWhen user_column is UUID type

Use current_user_id() (text) when your user column is TEXT. Use current_user_id()::uuid when your user column is UUID. Mismatched types cause silent policy failures.


Policy clauses
ClausePurposeUsed for commands
USINGFilter which rows are visible or affected by the operationSELECT, UPDATE, DELETE, ALL
WITH CHECKValidate that new or updated row data satisfies the expressionINSERT, UPDATE, ALL

For ALL command policies, both USING and WITH CHECK may apply:

  • On SELECT/DELETE: only USING is evaluated
  • On INSERT: only WITH CHECK is evaluated
  • On UPDATE: both are evaluated (USING for old row, WITH CHECK for new row)

Policy permissiveness
Policy typeBehavior
PERMISSIVE (default)Multiple permissive policies are OR'd — any one passing grants access
RESTRICTIVEAND'd with permissive policies — must pass in addition to at least one permissive

Example: If a table has two permissive policies (user isolation + public read), a row is visible if either passes. If you add a restrictive policy, the row is only visible if the restrictive condition also passes.


7. Verification Checklist

After applying any fix, run through this checklist to confirm correct behavior:

  • manage_rls (action: "list") shows the expected policies for the table
  • select_rows with as_role: "user" returns only the user's own rows
  • select_rows with as_role: "anon" returns only publicly visible rows (or empty if no anon policy)
  • select_rows without as_role (service) returns all rows (confirms RLS is only blocking end-users, not admin)
  • insert_row with as_role: "user" succeeds and the user column is auto-populated
  • insert_row with as_role: "anon" fails (unless you explicitly added an anon INSERT policy)
  • select_rows with as_role: "user" for a different user's UUID does not return the first user's rows

8. Anti-Patterns to Avoid

Anti-patternProblemFix
Using select_rows without as_role to verify RLSService key bypasses RLS — result is meaningless for verificationAlways use as_role: "user" or as_role: "anon"
manage_rls action create_policy without user_columnNo auto-populate trigger; clients must send user column manuallyUse action: "create_user_isolation" or pass user_column to create_policy
Single policy with cmd: "ALL" but no WITH CHECKINSERT/UPDATE may silently pass or fail depending on expressionExplicitly provide with_check_expression for write commands
Relying on butterbase_service policies for end-user accessService bypass is always on; end-users use butterbase_user or butterbase_anonWrite separate policies for each end-user role
Missing policy for one role while having it for anotherAuthenticated users may see data that anonymous users cannot, or vice versa — may be intentional but often a bugAudit all roles with manage_rls (action: "list")

If a docs/butterbase/00-state.md exists in the working directory, prefer invoking via /butterbase-skills:journey-rls so the journey orchestrator stays in sync.

© butterbase-ai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/debug-rls of butterbase-ai/butterbase-skills.

Open the folder on GitHubat commit aa8ae69

Compare with similar skills

Debug Rls next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Debug Rls compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Debug Rls this skillbutterbase-ai/butterbase-skills534—~3.5kAutomated safety check: PassMIT
Vercel Composition Patternssupabase/supabase111k59 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 59 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from butterbase-ai/butterbase-skills

All 39 skills in this repo
  • AI

    butterbase-ai/butterbase-skills

    A skill your agent uses when calling the app's AI gateway from agent tools — chat completions, embeddings, listing models, configuring defaults or BYOK, reading token/cost usage

    534 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Auth Setup

    butterbase-ai/butterbase-skills

    A skill your agent uses when configuring OAuth providers (Google/GitHub/Apple/X/etc.), setting up post-login auth hooks, tuning JWT lifetimes, or generating service API keys

    534 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed
  • Build App

    butterbase-ai/butterbase-skills

    A skill your agent uses when building a new Butterbase app from scratch, creating a full-stack application, or when the user asks to set up a complete backend with database, auth, and deployment

    534 GitHub stars~4.9k tokensUpdated 2 days ago
    Auto-check passed
  • Contributing

    butterbase-ai/butterbase-skills

    A skill your agent uses when contributing to the Butterbase codebase, adding new MCP tools, creating API routes, writing migrations, or understanding the monorepo architecture

    534 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Deploy Frontend

    butterbase-ai/butterbase-skills

    A skill your agent uses when deploying a frontend (React, Next.js, or static HTML) to a live URL on Butterbase, or when troubleshooting deployment issues like MIME type errors or blank pages

    534 GitHub stars~2.8k tokensUpdated 2 days ago
    Auto-check passed
  • Durable Objects

    butterbase-ai/butterbase-skills

    A skill your agent uses when building stateful per-key actors — chat rooms, multiplayer rooms, rate limiters, long-running agents, leaderboards — that need persistent in-memory + storage state…

    534 GitHub stars~2.8k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Debug Rls

What does Debug Rls do?

A skill your agent uses when users report access denied errors, see wrong data, RLS policies are not working, or when troubleshooting Row-Level Security issues in Butterbase. Debug Rls is an agent skill from butterbase-ai/butterbase-skills.

When should I use Debug Rls?

Debug Rls fits situations like: users report access denied errors; RLS policies are not working; troubleshooting Row-Level Security issues in Butterbase.

How do I install Debug Rls in Claude Code?

Run `npx skills add butterbase-ai/butterbase-skills --skill debug-rls -a claude-code`. Or copy the skill folder (skills/debug-rls in butterbase-ai/butterbase-skills) into .claude/skills/debug-rls in your project. Claude Code loads it when a task matches its description.

How do I install Debug Rls in Codex?

Run `npx skills add butterbase-ai/butterbase-skills --skill debug-rls -a codex`. Or copy the skill folder (skills/debug-rls in butterbase-ai/butterbase-skills) into .agents/skills/debug-rls in your project. Codex loads it when a task matches its description.

Can I use Debug Rls in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add butterbase-ai/butterbase-skills --skill debug-rls -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/debug-rls, .gemini/skills/debug-rls, .github/skills/debug-rls and .opencode/skills/debug-rls in your project.

What does Debug Rls need to run?

SKILL.md names no scripts, command-line tools or credentials: Debug Rls is instructions for the agent only.

Does Debug Rls access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Debug Rls safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Debug Rls use?

Debug Rls is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Debug Rls use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Debug Rls?

Skills that share tags, products or a category with Debug Rls: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Debug Rls?

butterbase-ai (a GitHub organization) maintains it in butterbase-ai/butterbase-skills, which has 534 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on October 5, 2026.

Source: butterbase-ai/butterbase-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.