Agent skill

Supabase Admin

by curiositech in curiositech/some_claude_skills

Supabase administration, RLS policies, migrations, and schema design.

MITAuto-check: notesDatabases

Install Supabase Admin

skills CLI
$ npx skills add curiositech/some_claude_skills --skill supabase-admin -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install curiositech/some_claude_skills supabase-admin --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/curiositech/some_claude_skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/supabase-admin .claude/skills/supabase-admin && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supabase-admin
GitHub stars
243
Token cost
~1.9k tokens
SKILL.md length
236 words
Files
4 (incl. references)
Skills in repo
108
Repo updated
First seen
Licence
MIT

At a glance

Supabase administration, RLS policies, migrations, and schema design.

  • Works in 5 steps: Row Level Security (RLS) → Migration Best Practices → Auth Integration → …
  • Database architecture
  • SKILL.md covers When to Use, Core Competencies, Quick Reference and References
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Supabase Admin is an agent skill from curiositech/some_claude_skills. Supabase administration, RLS policies, migrations, and schema design. Use for database architecture, Row Level Security, performance tuning, auth integration. Activate on "Supabase", "RLS", "migration", "policy", "schema", "auth.uid()". NOT for Supabase Auth UI configuration (use dashboard), edge functions (use cloudflare-worker-dev), or general SQL without Supabase context.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `.claude-plugin/plugin.json`, `references/rls-patterns.md` and `references/social-schema.md`).

It sits in Databases, covering Database schema design and SQL. It works with Supabase, SQL and Cloudflare Workers. The repository describes itself as: Claude skills that make my life easier. The licence is MIT.

When your agent uses it

  • Database architecture
  • Row Level Security
  • Performance tuning
  • Auth integration

Example prompts

  • “Supabase”
  • “migration”
  • “policy”
  • “/supabase-admin”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash, Grep, Glob, mcp__supabase__*

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Row Level Security (RLS)
  2. Migration Best Practices
  3. Auth Integration
  4. Common Schema Patterns
  5. Debugging RLS Issues

What it can do on your machine

Read from SKILL.md and the folder at commit 6713fc7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash
    • Grep
    • Glob
    • mcp__supabase__*

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are sql).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Supabase Admin loads about 1.9k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 236 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Bash, Grep, Glob, mcp__supabase__*

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from curiositech/some_claude_skills at commit 6713fc7, republished under its MIT licence (© curiositech). 236 words, ~1,889 tokens.

Download SKILL.mdSave it as .claude/skills/supabase-admin/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
supabase-admin
description
Supabase administration, RLS policies, migrations, and schema design. Use for database architecture, Row Level Security, performance tuning, auth integration. Activate on "Supabase", "RLS", "migration", "policy", "schema", "auth.uid()". NOT for Supabase Auth UI configuration (use dashboard), edge functions (use cloudflare-worker-dev), or general SQL without Supabase context.
allowed-tools
Read, Write, Edit, Bash, Grep, Glob, mcp__supabase__*
metadata.category
DevOps & Site Reliability
metadata.tags
supabase, rls, database, postgres, migration, schema, security

Supabase Administration Expert

Master Supabase schema design, Row Level Security policies, migrations, and performance optimization for production applications.

When to Use

✅ USE this skill for:

  • Row Level Security (RLS) policy design and debugging
  • Database migrations and schema changes
  • Auth integration (triggers, profile creation)
  • Query performance optimization
  • Supabase-specific SQL patterns (auth.uid(), auth.jwt())

❌ DO NOT use for:

  • Supabase Auth UI configuration → use Supabase dashboard docs
  • Edge Functions → use cloudflare-worker-dev skill
  • General PostgreSQL without Supabase context → use standard SQL resources
  • Client-side Supabase SDK usage → use Supabase JS docs

Core Competencies

1. Row Level Security (RLS)

Always Enable RLS on User Tables:

sql
ALTER TABLE your_table ENABLE ROW LEVEL SECURITY;

Policy Patterns:

sql
-- Public read, authenticated write
CREATE POLICY "Public read" ON posts FOR SELECT USING (true);
CREATE POLICY "Owners can write" ON posts FOR INSERT
  WITH CHECK (auth.uid() = user_id);

-- Owner-only access
CREATE POLICY "Users own their data" ON profiles
  FOR ALL USING (auth.uid() = id);

-- Role-based access
CREATE POLICY "Admins can do anything" ON content
  FOR ALL USING (
    EXISTS (
      SELECT 1 FROM profiles
      WHERE profiles.id = auth.uid()
      AND profiles.role = 'admin'
    )
  );

Performance-Critical: Index auth.uid() Columns:

sql
-- 100x performance improvement for RLS policies
CREATE INDEX idx_posts_user_id ON posts(user_id);
CREATE INDEX idx_profiles_id ON profiles(id);

Subquery Optimization for JWT Functions:

sql
-- BAD: JWT parsed for every row
CREATE POLICY "slow" ON posts FOR SELECT
  USING (user_id = auth.uid());

-- GOOD: JWT parsed once via subquery
CREATE POLICY "fast" ON posts FOR SELECT
  USING (user_id = (SELECT auth.uid()));
2. Migration Best Practices

File Naming Convention:

supabase/migrations/
├── 001_initial_schema.sql
├── 002_add_profiles_trigger.sql
├── 003_forum_tables.sql
└── 004_add_rls_policies.sql

Migration Template:

sql
-- Migration: 005_feature_name
-- Description: What this migration does
-- Author: name
-- Date: YYYY-MM-DD

-- Up migration
BEGIN;

-- Your DDL here
CREATE TABLE ...;
ALTER TABLE ...;
CREATE POLICY ...;

COMMIT;

-- Down migration (as comment for reference)
-- DROP TABLE ...;
-- DROP POLICY ...;

Safe Migration Patterns:

sql
-- Add column with default (no table lock)
ALTER TABLE users ADD COLUMN status text DEFAULT 'active';

-- Add NOT NULL constraint safely
ALTER TABLE users ADD COLUMN email text;
UPDATE users SET email = 'unknown@example.com' WHERE email IS NULL;
ALTER TABLE users ALTER COLUMN email SET NOT NULL;

-- Create index concurrently (no lock)
CREATE INDEX CONCURRENTLY idx_users_email ON users(email);
3. Auth Integration

Auto-create Profile on Signup:

sql
-- Function to create profile
CREATE OR REPLACE FUNCTION public.handle_new_user()
RETURNS TRIGGER AS $$
BEGIN
  INSERT INTO public.profiles (id, email, display_name)
  VALUES (
    NEW.id,
    NEW.email,
    COALESCE(NEW.raw_user_meta_data->>'display_name', split_part(NEW.email, '@', 1))
  );
  RETURN NEW;
END;
$$ LANGUAGE plpgsql SECURITY DEFINER;

-- Trigger on auth.users
CREATE TRIGGER on_auth_user_created
  AFTER INSERT ON auth.users
  FOR EACH ROW EXECUTE FUNCTION public.handle_new_user();

Check Auth Status in Policies:

sql
-- Authenticated users only
CREATE POLICY "Authenticated access" ON data
  FOR SELECT USING (auth.role() = 'authenticated');

-- Get current user's ID
SELECT auth.uid();

-- Get current user's JWT claims
SELECT auth.jwt();
4. Common Schema Patterns

Timestamps with Defaults:

sql
CREATE TABLE posts (
  id uuid PRIMARY KEY DEFAULT gen_random_uuid(),
  user_id uuid REFERENCES auth.users(id) ON DELETE CASCADE,
  content text NOT NULL,
  created_at timestamptz DEFAULT now(),
  updated_at timestamptz DEFAULT now()
);

-- Auto-update updated_at
CREATE OR REPLACE FUNCTION update_updated_at()
RETURNS TRIGGER AS $$
BEGIN
  NEW.updated_at = now();
  RETURN NEW;
END;
$$ LANGUAGE plpgsql;

CREATE TRIGGER update_posts_updated_at
  BEFORE UPDATE ON posts
  FOR EACH ROW EXECUTE FUNCTION update_updated_at();

Soft Delete Pattern:

sql
ALTER TABLE posts ADD COLUMN deleted_at timestamptz;

CREATE POLICY "Hide deleted" ON posts
  FOR SELECT USING (deleted_at IS NULL);

Full-Text Search:

sql
-- Add search vector column
ALTER TABLE posts ADD COLUMN search_vector tsvector;

-- Create GIN index
CREATE INDEX idx_posts_search ON posts USING GIN(search_vector);

-- Update function
CREATE OR REPLACE FUNCTION posts_search_update()
RETURNS TRIGGER AS $$
BEGIN
  NEW.search_vector := to_tsvector('english', COALESCE(NEW.title, '') || ' ' || COALESCE(NEW.content, ''));
  RETURN NEW;
END;
$$ LANGUAGE plpgsql;

-- Search query
SELECT * FROM posts
WHERE search_vector @@ plainto_tsquery('english', 'search terms');
5. Debugging RLS Issues

Common Problem: Empty Results, No Error

sql
-- Check if RLS is enabled
SELECT tablename, rowsecurity FROM pg_tables WHERE schemaname = 'public';

-- List all policies
SELECT * FROM pg_policies WHERE tablename = 'your_table';

-- Test as specific role
SET ROLE anon;
SELECT * FROM your_table LIMIT 1;
RESET ROLE;

-- Test with specific user
SET request.jwt.claims TO '{"sub": "user-uuid-here"}';
SELECT * FROM your_table;

Diagnostic Query:

sql
-- Check what the current user can see
SELECT
  auth.uid() as current_user,
  auth.role() as current_role,
  (SELECT count(*) FROM your_table) as visible_rows;

Quick Reference

TaskCommand
Enable RLSALTER TABLE t ENABLE ROW LEVEL SECURITY;
Create policyCREATE POLICY "name" ON t FOR action USING (condition);
Drop policyDROP POLICY "name" ON t;
Check policiesSELECT * FROM pg_policies WHERE tablename = 't';
Current userSELECT auth.uid();
Force RLS for ownerALTER TABLE t FORCE ROW LEVEL SECURITY;

References

See /references/ for detailed guides:

  • rls-patterns.md - Advanced RLS policy patterns
  • migration-checklist.md - Pre-deployment checklist
  • performance-tuning.md - Query and index optimization
  • social-schema.md - Schema patterns for social features

© curiositech, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in .claude/skills/supabase-admin of curiositech/some_claude_skills.

  • SKILL.md
  • .claude-plugin/plugin.json
  • references/rls-patterns.md
  • references/social-schema.md

Open the folder on GitHubat commit 6713fc7

Compare with similar skills

Supabase Admin next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supabase Admin compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supabase Admin this skillcuriositech/some_claude_skills243—~1.9kAutomated safety check: NotesMIT
Replica ArchitectJakeschincariol/replica-skill734—~1.1kAutomated safety check: PassMIT
Expert DatabaseReJeCtAll/ExpertTeam-Codex113—~692Automated safety check: PassMIT
Memstack Security Rls Guardiancwinvestments/memstack423—~3.4kAutomated safety check: PassProprietary
Drizzle Orm D1secondsky/claude-skills227—~2.4kAutomated safety check: PassMIT
Firebaseericrisco/rsc-harness156—~3.3kAutomated safety check: PassMIT

Similar skills

  • Replica Architect

    Jakeschincariol/replica-skill

    Plans the stack, database schema and API for an app clone, from the recon map replica-recon wrote.

    734 GitHub stars~1.1k tokensUpdated 4 days ago
    DatabasesAuto-check passed
  • Expert Database

    ReJeCtAll/ExpertTeam-Codex

    数据库优化专家入口。用于 Codex CLI 的 $expert-database 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.

    113 GitHub stars~692 tokensUpdated 3 mo ago
    DatabasesAuto-check passed
  • Memstack Security Rls Guardian

    cwinvestments/memstack

    A skill your agent uses when creating or altering database tables in Supabase or PostgreSQL projects.

    423 GitHub stars~3.4k tokensUpdated 11 days ago
    DatabasesAuto-check passed
  • Drizzle Orm D1

    secondsky/claude-skills

    | Type-safe ORM for Cloudflare D1 databases using Drizzle. An agent skill from secondsky/claude-skills.

    227 GitHub stars~2.4k tokensUpdated 9 days ago
    DatabasesAuto-check passed
  • Firebase

    ericrisco/rsc-harness

    A skill your agent uses when building on Firebase — Firestore data modeling, Security Rules, Auth and custom claims, Cloud Functions, Storage, modular Web/Admin SDK imports — including symptoms like…

    156 GitHub stars~3.3k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Official

    Gives the agent Postgres rules to consult before writing or changing tables, queries, indexes, RLS policies or migrations, and when diagnosing slow queries.

    2.7k GitHub starsUsed in 24 repos~808 tokens
    DatabasesAuto-check passed

More from curiositech/some_claude_skills

All 108 skills in this repo
  • Crisis Detection Intervention AI

    curiositech/some_claude_skills

    Detect crisis signals in user content using NLP, mental health sentiment analysis, and safe intervention protocols.

    243 GitHub starsUsed in 3 repos~3.8k tokens
    Auto-check passed
  • Form Validation Architect

    curiositech/some_claude_skills

    End-to-end form handling with react-hook-form, Zod schemas, validation patterns, error messaging, field arrays, and multi-step wizards.

    243 GitHub stars~3.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Competitive Cartographer

    curiositech/some_claude_skills

    Strategic analyst that maps competitive landscapes, identifies white space opportunities, and provides positioning recommendations.

    243 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • GitHub Actions Pipeline Builder

    curiositech/some_claude_skills

    Build production CI/CD pipelines with GitHub Actions. An agent skill from curiositech/some_claude_skills.

    243 GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • Computer Vision Pipeline

    curiositech/some_claude_skills

    Build production computer vision pipelines for object detection, tracking, and video analysis.

    243 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Design Archivist

    curiositech/some_claude_skills

    Long-running design anthropologist that builds comprehensive visual databases from 500-1000 real-world examples, extracting color palettes, typography patterns, layout systems, and interaction…

    243 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check passed

Categories

Questions about Supabase Admin

What does Supabase Admin do?

Supabase administration, RLS policies, migrations, and schema design. Supabase Admin is an agent skill from curiositech/some_claude_skills. Supabase administration, RLS policies, migrations, and schema design.

When should I use Supabase Admin?

Supabase Admin fits situations like: database architecture; row Level Security; performance tuning; auth integration.

How do I install Supabase Admin in Claude Code?

Run `npx skills add curiositech/some_claude_skills --skill supabase-admin -a claude-code`. Or copy the skill folder (.claude/skills/supabase-admin in curiositech/some_claude_skills) into .claude/skills/supabase-admin in your project. Claude Code loads it when a task matches its description.

How do I install Supabase Admin in Codex?

Run `npx skills add curiositech/some_claude_skills --skill supabase-admin -a codex`. Or copy the skill folder (.claude/skills/supabase-admin in curiositech/some_claude_skills) into .agents/skills/supabase-admin in your project. Codex loads it when a task matches its description.

Can I use Supabase Admin in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add curiositech/some_claude_skills --skill supabase-admin -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supabase-admin, .gemini/skills/supabase-admin, .github/skills/supabase-admin and .opencode/skills/supabase-admin in your project.

What does Supabase Admin need to run?

SKILL.md names no scripts, command-line tools or credentials: Supabase Admin is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash, Grep, Glob, mcp__supabase__*.

Does Supabase Admin access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Supabase Admin safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Supabase Admin use?

Supabase Admin is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supabase Admin use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.3k tokens, read only when the agent opens those files.

What are the alternatives to Supabase Admin?

Skills that share tags, products or a category with Supabase Admin: Replica Architect (Jakeschincariol/replica-skill, 734 stars), Expert Database (ReJeCtAll/ExpertTeam-Codex, 113 stars), Memstack Security Rls Guardian (cwinvestments/memstack, 423 stars) and Drizzle Orm D1 (secondsky/claude-skills, 227 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supabase Admin?

curiositech (a GitHub organization) maintains it in curiositech/some_claude_skills, which has 243 GitHub stars. The repository holds 108 skills in this directory. The repository was last updated on September 6, 2026.

Source: curiositech/some_claude_skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.