Agent skill

Rls Patterns

by bybren-llc in bybren-llc/safe-agentic-workflow

Row Level Security patterns for database operations. An agent skill from bybren-llc/safe-agentic-workflow.

MITAuto-check passedBackend & APIs

Install Rls Patterns

skills CLI
$ npx skills add bybren-llc/safe-agentic-workflow --skill rls-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bybren-llc/safe-agentic-workflow rls-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bybren-llc/safe-agentic-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/rls-patterns .claude/skills/rls-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rls-patterns
GitHub stars
423
Token cost
~1.5k tokens
SKILL.md length
305 words
Files
4 (incl. scripts, references, assets)
Skills in repo
42
Repo updated
First seen
Licence
MIT

At a glance

Row Level Security patterns for database operations. An agent skill from bybren-llc/safe-agentic-workflow.

  • Writing any database query
  • SKILL.md covers Purpose, When This Skill Applies, Critical Rules and Context Helper Reference, plus 5 more sections
  • Creating API routes that access data
  • Implementing webhooks that write to the database

What it does

Rls Patterns is an agent skill from bybren-llc/safe-agentic-workflow. Row Level Security patterns for database operations. Use when writing any database query, creating API routes that access data, implementing webhooks that write to the database, or working with user data. Enforces withUserContext, withAdminContext, or withSystemContext helpers. NEVER use direct ORM/DB calls without RLS context wrappers.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts, reference files and assets.

It sits in Backend & APIs, covering Webhooks, Database administration and ORMs and data access. The repository describes itself as: SAW — SAFe Agentic Workflow AI Agent Harness for Multi-Agent Team Workflows Built on SAFe methodology (Scaled Agile Framework), adapted for AI agent teams (Now With AI-DLC!)… The licence is MIT.

When your agent uses it

  • Writing any database query
  • Creating API routes that access data
  • Implementing webhooks that write to the database
  • Working with user data

Example prompts

  • “/rls-patterns”

What it can do on your machine

Read from SKILL.md and the folder at commit 26ca58b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rls Patterns loads about 1.5k tokens when it runs. Until then it costs about 88 tokens; SKILL.md has 305 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from bybren-llc/safe-agentic-workflow at commit 26ca58b, republished under its MIT licence (© bybren-llc). 305 words, ~1,508 tokens.

Download SKILL.mdSave it as .claude/skills/rls-patterns/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
rls-patterns
description
Row Level Security patterns for database operations. Use when writing any database query, creating API routes that access data, implementing webhooks that write to the database, or working with user data. Enforces withUserContext, withAdminContext, or withSystemContext helpers. NEVER use direct ORM/DB calls without RLS context wrappers.

RLS Patterns Skill

TEMPLATE: This skill uses {{PLACEHOLDER}} tokens. Replace with your project values before use.

Purpose

Enforce Row Level Security (RLS) patterns for all database operations. This skill ensures data isolation and prevents cross-user data access at the database level.

When This Skill Applies

  • Writing any database query (ORM or raw SQL)
  • Creating or modifying API routes that access the database
  • Implementing webhook handlers that write to the database
  • Working with user data, payments, subscriptions, or enrollments
  • Accessing admin-only tables

Critical Rules

NEVER Do This
typescript
// FORBIDDEN - Direct DB calls bypass RLS
const user = await db.user.findUnique({ where: { user_id } });

// FORBIDDEN - No context set
const payments = await db.payments.findMany();

Linting will block direct DB calls. See linting configuration for enforcement rules.

ALWAYS Do This
typescript
import {
  withUserContext,
  withAdminContext,
  withSystemContext,
} from "{{RLS_IMPORT}}";

// CORRECT - User context for user operations
const user = await withUserContext(db, userId, async (client) => {
  return client.user.findUnique({ where: { user_id: userId } });
});

// CORRECT - Admin context for admin operations
const webhooks = await withAdminContext(db, userId, async (client) => {
  return client.webhook_events.findMany();
});

// CORRECT - System context for webhooks/background tasks
const event = await withSystemContext(db, "webhook", async (client) => {
  return client.webhook_events.create({ data: eventData });
});

Context Helper Reference

withUserContext(db, userId, callback)

Use for: All user-facing operations

  • User profile access
  • Payment history
  • Subscription management
  • Enrollments and personal data
typescript
const payments = await withUserContext(db, userId, async (client) => {
  return client.payments.findMany({ where: { user_id: userId } });
});
withAdminContext(db, userId, callback)

Use for: Admin-only operations (requires admin role)

  • Viewing all webhook events
  • Managing disputes
  • Accessing payment failures
typescript
const disputes = await withAdminContext(db, adminUserId, async (client) => {
  return client.disputes.findMany();
});
withSystemContext(db, contextType, callback)

Use for: Webhooks and background jobs

  • Webhook handlers (Stripe, auth provider, etc.)
  • Background job processing
  • System-initiated operations
typescript
await withSystemContext(db, "webhook", async (client) => {
  await client.payments.create({ data: paymentData });
});

Admin Pages: Force Dynamic Rendering

CRITICAL: Admin pages using RLS queries MUST force runtime rendering (in Next.js):

typescript
// REQUIRED - RLS context unavailable at build time
export const dynamic = "force-dynamic";

async function getAdminData() {
  return await withAdminContext(db, userId, async (client) => {
    return client.someTable.findMany();
  });
}

Without forced dynamic rendering, frameworks may try to pre-render at build time, causing "permission denied" errors.

Protected Tables

User Data Tables (User Isolation)
TablePolicy TypeAccess
userUser isolationOwn data only
paymentsUser isolationOwn payments only
subscriptionsUser isolationOwn subscriptions only
invoicesUser isolationOwn invoices only
Admin/System Tables (Role-Based)
TablePolicy TypeAccess
webhook_eventsAdmin+SystemAdmins and webhooks only
disputesAdmin onlyAdmins only
payment_failuresAdmin onlyAdmins only

Testing Requirements

Always test with the application-level DB user role (not a superuser):

bash
# Basic RLS functionality test
{{RLS_TEST_COMMAND}}

# Comprehensive security validation
{{RLS_VALIDATION_COMMAND}}

Common Patterns

API Route with User Context
typescript
import { NextResponse } from "next/server";
import { requireAuth } from "{{AUTH_IMPORT}}";
import { withUserContext } from "{{RLS_IMPORT}}";
import { db } from "{{DB_IMPORT}}";

export async function GET() {
  const { userId } = await requireAuth();

  const payments = await withUserContext(db, userId, async (client) => {
    return client.payments.findMany({
      where: { user_id: userId },
      orderBy: { created_at: "desc" },
    });
  });

  return NextResponse.json(payments);
}
Webhook Handler with System Context
typescript
import { withSystemContext } from "{{RLS_IMPORT}}";
import { db } from "{{DB_IMPORT}}";

export async function POST(req: Request) {
  // Verify webhook signature first...

  await withSystemContext(db, "webhook", async (client) => {
    await client.webhook_events.create({
      data: {
        event_type: event.type,
        payload: event.data,
        processed_at: new Date(),
      },
    });
  });

  return new Response("OK", { status: 200 });
}

Authoritative References

  • RLS Implementation Guide: docs/database/RLS_IMPLEMENTATION_GUIDE.md
  • RLS Policy Catalog: docs/database/RLS_POLICY_CATALOG.md
  • Migration SOP: docs/database/RLS_DATABASE_MIGRATION_SOP.md
  • Linting Rules: Check linting config for direct DB call enforcement
  • RLS Context Helpers: {{RLS_CONTEXT_FILE}}

© bybren-llc, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references, assets) in .agents/skills/rls-patterns of bybren-llc/safe-agentic-workflow.

  • SKILL.md
  • assets/.gitkeep
  • references/.gitkeep
  • scripts/.gitkeep

Open the folder on GitHubat commit 26ca58b

Compare with similar skills

Rls Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rls Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rls Patterns this skillbybren-llc/safe-agentic-workflow423—~1.5kAutomated safety check: PassMIT
Sea Orm 2FlyinPancake/yoink112—~2.9kAutomated safety check: PassApache-2.0
Nestjs Drizzle Crud Generatorgiuseppe-trisciuoglio/developer-kit356—~1.3kAutomated safety check: NotesMIT
Prismablencorp/claude-code-kit106—~2.7kAutomated safety check: PassMIT
Prisma Expertdavila7/claude-code-templates32k7 repos~2.6kAutomated safety check: PassMIT
Frappe Core DatabaseImpertio-Studio/Frappe_Claude_Skill_Package188—~3.8kAutomated safety check: PassMIT

Similar skills

  • Sea Orm 2

    FlyinPancake/yoink

    Expert guidance for SeaORM 2.0, Rust's async ORM with strongly-typed columns, nested ActiveModels, Entity Loader API, and entity-first workflow.

    112 GitHub stars~2.9k tokensUpdated 4 days ago
    DatabasesAuto-check passed
  • Nestjs Drizzle Crud Generator

    giuseppe-trisciuoglio/developer-kit

    Generates complete CRUD modules for NestJS applications with Drizzle ORM.

    356 GitHub stars~1.3k tokensUpdated 28 days ago
    DatabasesAuto-check: notes
  • Prisma

    blencorp/claude-code-kit

    Prisma ORM patterns including Prisma Client usage, queries, mutations, relations, transactions, and schema management.

    106 GitHub stars~2.7k tokensUpdated 10 mo ago
    DatabasesAuto-check passed
  • Prisma Expert

    davila7/claude-code-templates

    Prisma ORM expert for schema design, migrations, query optimization, relations modeling, and database operations.

    32k GitHub starsUsed in 7 repos~2.6k tokens
    DatabasesAuto-check passed
  • Frappe Core Database

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when performing database operations in ERPNext/Frappe v14-v16.

    188 GitHub stars~3.8k tokensUpdated 21 days ago
    DatabasesAuto-check passed
  • Neon Postgres

    aiskillstore/marketplace

    Guides and best practices for working with Neon Serverless Postgres.

    430 GitHub starsUsed in 4 repos~4.2k tokens
    DatabasesAuto-check: notes

More from bybren-llc/safe-agentic-workflow

All 42 skills in this repo
  • Multi-Agent Coordination Template

    bybren-llc/safe-agentic-workflow

    Agent assignment matrix, blocker escalation, and TDM coordination patterns. Use when assigning work to specialist agents, managing blockers across agents…

    423 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • API Route Patterns

    bybren-llc/safe-agentic-workflow

    API route implementation patterns with RLS, validation, and error handling. Use when creating API routes, implementing CRUD endpoints, adding server-side…

    423 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Technical Documentation Templates

    bybren-llc/safe-agentic-workflow

    Documentation templates for ADRs, runbooks, architecture docs, and knowledge transfer documents. Use when creating Architecture Decision Records, writing…

    423 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Deployment SOP Checklist

    bybren-llc/safe-agentic-workflow

    Deployment workflows, pre-deploy validation, smoke testing, and rollback procedures. Use when deploying to staging or production, running smoke tests…

    423 GitHub stars~950 tokensUpdated 2 mo ago
    Auto-check passed
  • Frontend Patterns Template

    bybren-llc/safe-agentic-workflow

    Frontend patterns for modern web frameworks, component libraries, auth flows, and analytics. Use when building UI components, creating pages, implementing…

    423 GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Advanced Git Operations

    bybren-llc/safe-agentic-workflow

    Advanced git operations including rebase, bisect, cherry-pick, and conflict resolution. Use when rebasing feature branches, debugging with bisect…

    423 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Rls Patterns

What does Rls Patterns do?

Row Level Security patterns for database operations. An agent skill from bybren-llc/safe-agentic-workflow. Rls Patterns is an agent skill from bybren-llc/safe-agentic-workflow. Row Level Security patterns for database operations.

When should I use Rls Patterns?

Rls Patterns fits situations like: writing any database query; creating API routes that access data; implementing webhooks that write to the database; working with user data.

How do I install Rls Patterns in Claude Code?

Run `npx skills add bybren-llc/safe-agentic-workflow --skill rls-patterns -a claude-code`. Or copy the skill folder (.agents/skills/rls-patterns in bybren-llc/safe-agentic-workflow) into .claude/skills/rls-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Rls Patterns in Codex?

Run `npx skills add bybren-llc/safe-agentic-workflow --skill rls-patterns -a codex`. Or copy the skill folder (.agents/skills/rls-patterns in bybren-llc/safe-agentic-workflow) into .agents/skills/rls-patterns in your project. Codex loads it when a task matches its description.

Can I use Rls Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bybren-llc/safe-agentic-workflow --skill rls-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rls-patterns, .gemini/skills/rls-patterns, .github/skills/rls-patterns and .opencode/skills/rls-patterns in your project.

What does Rls Patterns need to run?

SKILL.md names no scripts, command-line tools or credentials: Rls Patterns is instructions for the agent only.

Does Rls Patterns access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Rls Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Rls Patterns use?

Rls Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rls Patterns use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rls Patterns?

Skills that share tags, products or a category with Rls Patterns: Sea Orm 2 (FlyinPancake/yoink, 112 stars), Nestjs Drizzle Crud Generator (giuseppe-trisciuoglio/developer-kit, 356 stars), Prisma (blencorp/claude-code-kit, 106 stars) and Prisma Expert (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rls Patterns?

bybren-llc (a GitHub organization) maintains it in bybren-llc/safe-agentic-workflow, which has 423 GitHub stars. The repository holds 42 skills in this directory. The repository was last updated on July 20, 2026.

Source: bybren-llc/safe-agentic-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.