Agent skill

Rls Patterns

by bybren-llc in bybren-llc/safe-agentic-workflow

Row Level Security patterns for database operations. An agent skill from bybren-llc/safe-agentic-workflow.

MITAuto-check passedDatabases

Install Rls Patterns

skills CLI
$ npx skills add bybren-llc/safe-agentic-workflow --skill rls-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bybren-llc/safe-agentic-workflow rls-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bybren-llc/safe-agentic-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/rls-patterns .claude/skills/rls-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rls-patterns
GitHub stars
423
Token cost
~1.6k tokens
SKILL.md length
295 words
Files
2
Skills in repo
42
Repo updated
First seen
Licence
MIT

At a glance

Row Level Security patterns for database operations. An agent skill from bybren-llc/safe-agentic-workflow.

  • Writing Prisma/database code
  • SKILL.md covers Purpose, When This Skill Applies, Critical Rules and Context Helper Reference, plus 5 more sections
  • Calls node and docker
  • Creating API routes that access data

What it does

Rls Patterns is an agent skill from bybren-llc/safe-agentic-workflow. Row Level Security patterns for database operations. Use when writing Prisma/database code, creating API routes that access data, or implementing webhooks. Enforces withUserContext, withAdminContext, or withSystemContext helpers. NEVER use direct prisma calls.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `README.md`).

It sits in Databases, covering Webhooks, ORMs and data access and Database administration. It works with Prisma. The repository describes itself as: SAW — SAFe Agentic Workflow AI Agent Harness for Multi-Agent Team Workflows Built on SAFe methodology (Scaled Agile Framework), adapted for AI agent teams (Now With AI-DLC!)… The licence is MIT.

When your agent uses it

  • Writing Prisma/database code
  • Creating API routes that access data
  • Implementing webhooks

Example prompts

  • “/rls-patterns”

Requirements

  • Docker
  • Pre-approved tools (allowed-tools): Read, Grep, Glob

What it can do on your machine

Read from SKILL.md and the folder at commit 26ca58b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rls Patterns loads about 1.6k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 295 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from bybren-llc/safe-agentic-workflow at commit 26ca58b, republished under its MIT licence (© bybren-llc). 295 words, ~1,620 tokens.

Download SKILL.mdSave it as .claude/skills/rls-patterns/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
rls-patterns
description
Row Level Security patterns for database operations. Use when writing Prisma/database code, creating API routes that access data, or implementing webhooks. Enforces withUserContext, withAdminContext, or withSystemContext helpers. NEVER use direct prisma calls.
allowed-tools
Read, Grep, Glob
user-invocable
false

RLS Patterns Skill

Purpose

Enforce Row Level Security (RLS) patterns for all database operations. This skill ensures data isolation and prevents cross-user data access at the database level.

When This Skill Applies

Invoke this skill when:

  • Writing any Prisma database query
  • Creating or modifying API routes that access the database
  • Implementing webhook handlers that write to the database
  • Working with user data, payments, subscriptions, or enrollments
  • Accessing admin-only tables (disputes, webhook_events)

Critical Rules

NEVER Do This
typescript
// ❌ FORBIDDEN - Direct Prisma calls bypass RLS
const user = await prisma.user.findUnique({ where: { user_id } });

// ❌ FORBIDDEN - No context set
const payments = await prisma.payments.findMany();

ESLint will block direct Prisma calls. See eslint.config.mjs for enforcement rules.

ALWAYS Do This
typescript
import {
  withUserContext,
  withAdminContext,
  withSystemContext,
} from "@/lib/rls-context";

// ✅ CORRECT - User context for user operations
const user = await withUserContext(prisma, userId, async (client) => {
  return client.user.findUnique({ where: { user_id: userId } });
});

// ✅ CORRECT - Admin context for admin operations
const webhooks = await withAdminContext(prisma, userId, async (client) => {
  return client.webhook_events.findMany();
});

// ✅ CORRECT - System context for webhooks/background tasks
const event = await withSystemContext(prisma, "webhook", async (client) => {
  return client.webhook_events.create({ data: eventData });
});

Context Helper Reference

withUserContext(prisma, userId, callback)

Use for: All user-facing operations

  • User profile access
  • Payment history
  • Subscription management
  • Course enrollments
typescript
const payments = await withUserContext(prisma, userId, async (client) => {
  return client.payments.findMany({ where: { user_id: userId } });
});
withAdminContext(prisma, userId, callback)

Use for: Admin-only operations (requires admin role in user_roles table)

  • Viewing all webhook events
  • Managing disputes
  • Accessing payment failures
typescript
const disputes = await withAdminContext(prisma, adminUserId, async (client) => {
  return client.disputes.findMany();
});
withSystemContext(prisma, contextType, callback)

Use for: Webhooks and background jobs

  • Stripe webhook handlers
  • Clerk webhook handlers
  • Background job processing
typescript
// Stripe webhook handler
await withSystemContext(prisma, "webhook", async (client) => {
  await client.payments.create({ data: paymentData });
});

Admin Pages: Force Dynamic Rendering

CRITICAL: Admin pages using RLS queries MUST force runtime rendering:

typescript
// app/admin/some-page/page.tsx
import { withAdminContext } from "@/lib/rls-context";
import { prisma } from "@/lib/prisma";

// REQUIRED - RLS context unavailable at build time
export const dynamic = "force-dynamic";

async function getAdminData() {
  return await withAdminContext(prisma, userId, async (client) => {
    return client.someTable.findMany();
  });
}

Without export const dynamic = 'force-dynamic', Next.js will try to pre-render at build time, causing "permission denied" errors.

Protected Tables

User Data Tables (User Isolation)
TablePolicy TypeAccess
userUser isolationOwn data only
paymentsUser isolationOwn payments only
subscriptionsUser isolationOwn subscriptions only
invoicesUser isolationOwn invoices only
course_enrollmentUser isolationOwn enrollments only
Admin/System Tables (Role-Based)
TablePolicy TypeAccess
webhook_eventsAdmin+SystemAdmins and webhooks only
disputesAdmin onlyAdmins only
payment_failuresAdmin onlyAdmins only
trial_notificationsAdmin+SystemAdmins and system only

Testing Requirements

Always test with {{PROJECT}}_app_user role (not {{PROJECT}}_user superuser):

bash
# Basic RLS functionality test
node scripts/test-rls-phase3-simple.js

# Comprehensive security validation
cat scripts/rls-phase4-final-validation.sql | \
  docker exec -i {{PROJECT_NAME}}-postgres-1 psql -U {{PROJECT}}_app_user -d {{PROJECT}}_dev

Common Patterns

API Route with User Context
typescript
// app/api/user/payments/route.ts
import { NextResponse } from "next/server";
import { requireAuth } from "@/lib/auth";
import { withUserContext } from "@/lib/rls-context";
import { prisma } from "@/lib/prisma";

export async function GET() {
  const { userId } = await requireAuth();

  const payments = await withUserContext(prisma, userId, async (client) => {
    return client.payments.findMany({
      where: { user_id: userId },
      orderBy: { created_at: "desc" },
    });
  });

  return NextResponse.json(payments);
}
Webhook Handler with System Context
typescript
// app/api/webhooks/stripe/route.ts
import { withSystemContext } from "@/lib/rls-context";
import { prisma } from "@/lib/prisma";

export async function POST(req: Request) {
  // Verify webhook signature first...

  await withSystemContext(prisma, "webhook", async (client) => {
    await client.webhook_events.create({
      data: {
        event_type: event.type,
        payload: event.data,
        processed_at: new Date(),
      },
    });
  });

  return new Response("OK", { status: 200 });
}

Authoritative References

  • Implementation Guide: docs/database/RLS_IMPLEMENTATION_GUIDE.md
  • Policy Catalog: docs/database/RLS_POLICY_CATALOG.md
  • Migration SOP: docs/database/RLS_DATABASE_MIGRATION_SOP.md
  • ESLint Rules: eslint.config.mjs (direct Prisma call enforcement)
  • RLS Context: lib/rls-context.ts

© bybren-llc, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .claude/skills/rls-patterns of bybren-llc/safe-agentic-workflow.

  • SKILL.md
  • README.md

Open the folder on GitHubat commit 26ca58b

Compare with similar skills

Rls Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rls Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rls Patterns this skillbybren-llc/safe-agentic-workflow423—~1.6kAutomated safety check: PassMIT
Prismablencorp/claude-code-kit106—~2.7kAutomated safety check: PassMIT
Prisma Expertdavila7/claude-code-templates32k7 repos~2.6kAutomated safety check: PassMIT
Database Expertcin12211/orca-q224—~2.8kAutomated safety check: PassMIT
DB SculptorEliasOulkadi/shokunin114—~3.1kAutomated safety check: NotesMIT
Neon Postgresdavila7/claude-code-templates32k4 repos~396Automated safety check: PassMIT

Similar skills

  • Prisma

    blencorp/claude-code-kit

    Prisma ORM patterns including Prisma Client usage, queries, mutations, relations, transactions, and schema management.

    106 GitHub stars~2.7k tokensUpdated 10 mo ago
    DatabasesAuto-check passed
  • Prisma Expert

    davila7/claude-code-templates

    Prisma ORM expert for schema design, migrations, query optimization, relations modeling, and database operations.

    32k GitHub starsUsed in 7 repos~2.6k tokens
    DatabasesAuto-check passed
  • Database Expert

    cin12211/orca-q

    Database performance optimization, schema design, query analysis, and connection management across PostgreSQL, MySQL, MongoDB, and SQLite with ORM integration.

    224 GitHub stars~2.8k tokensUpdated 18 days ago
    DatabasesAuto-check passed
  • DB Sculptor

    EliasOulkadi/shokunin

    Design database schemas with Prisma/Drizzle, PostgreSQL index strategy (B-tree, GIN, GiST, BRIN, Hash), query optimization (EXPLAIN ANALYZE), migration safety (expand/contract, zero-downtime), and…

    114 GitHub stars~3.1k tokensUpdated 4 days ago
    DatabasesAuto-check: notes
  • Neon Postgres

    davila7/claude-code-templates

    Expert patterns for Neon serverless Postgres, branching, connection pooling, and Prisma/Drizzle integration Use when: neon database, serverless postgres, database branching, neon postgres, postgres…

    32k GitHub starsUsed in 4 repos~396 tokens
    DatabasesAuto-check passed
  • Infra Audit

    SethGammon/Citadel

    Reads docker-compose, env files, ORM configs, and connection strings to map current infrastructure.

    923 GitHub stars~2.1k tokensUpdated yesterday
    DatabasesAuto-check: notes

More from bybren-llc/safe-agentic-workflow

All 42 skills in this repo
  • Multi-Agent Coordination Template

    bybren-llc/safe-agentic-workflow

    Agent assignment matrix, blocker escalation, and TDM coordination patterns. Use when assigning work to specialist agents, managing blockers across agents…

    423 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • API Route Patterns

    bybren-llc/safe-agentic-workflow

    API route implementation patterns with RLS, validation, and error handling. Use when creating API routes, implementing CRUD endpoints, adding server-side…

    423 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Technical Documentation Templates

    bybren-llc/safe-agentic-workflow

    Documentation templates for ADRs, runbooks, architecture docs, and knowledge transfer documents. Use when creating Architecture Decision Records, writing…

    423 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Deployment SOP Checklist

    bybren-llc/safe-agentic-workflow

    Deployment workflows, pre-deploy validation, smoke testing, and rollback procedures. Use when deploying to staging or production, running smoke tests…

    423 GitHub stars~950 tokensUpdated 2 mo ago
    Auto-check passed
  • Frontend Patterns Template

    bybren-llc/safe-agentic-workflow

    Frontend patterns for modern web frameworks, component libraries, auth flows, and analytics. Use when building UI components, creating pages, implementing…

    423 GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Advanced Git Operations

    bybren-llc/safe-agentic-workflow

    Advanced git operations including rebase, bisect, cherry-pick, and conflict resolution. Use when rebasing feature branches, debugging with bisect…

    423 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Questions about Rls Patterns

What does Rls Patterns do?

Row Level Security patterns for database operations. An agent skill from bybren-llc/safe-agentic-workflow. Rls Patterns is an agent skill from bybren-llc/safe-agentic-workflow. Row Level Security patterns for database operations.

When should I use Rls Patterns?

Rls Patterns fits situations like: writing Prisma/database code; creating API routes that access data; implementing webhooks.

How do I install Rls Patterns in Claude Code?

Run `npx skills add bybren-llc/safe-agentic-workflow --skill rls-patterns -a claude-code`. Or copy the skill folder (.claude/skills/rls-patterns in bybren-llc/safe-agentic-workflow) into .claude/skills/rls-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Rls Patterns in Codex?

Run `npx skills add bybren-llc/safe-agentic-workflow --skill rls-patterns -a codex`. Or copy the skill folder (.claude/skills/rls-patterns in bybren-llc/safe-agentic-workflow) into .agents/skills/rls-patterns in your project. Codex loads it when a task matches its description.

Can I use Rls Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bybren-llc/safe-agentic-workflow --skill rls-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rls-patterns, .gemini/skills/rls-patterns, .github/skills/rls-patterns and .opencode/skills/rls-patterns in your project.

What does Rls Patterns need to run?

Going by SKILL.md and its folder, Rls Patterns needs the command-line tools its instructions call (node and docker). Our summary lists: Docker. Its frontmatter pre-approves these tools: Read, Grep, Glob.

Does Rls Patterns access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Rls Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rls Patterns use?

Rls Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Rls Patterns use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rls Patterns?

Skills that share tags, products or a category with Rls Patterns: Prisma (blencorp/claude-code-kit, 106 stars), Prisma Expert (davila7/claude-code-templates, 32k stars), Database Expert (cin12211/orca-q, 224 stars) and DB Sculptor (EliasOulkadi/shokunin, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rls Patterns?

bybren-llc (a GitHub organization) maintains it in bybren-llc/safe-agentic-workflow, which has 423 GitHub stars. The repository holds 42 skills in this directory. The repository was last updated on July 20, 2026.

Source: bybren-llc/safe-agentic-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.