Neon Postgres
usenotra/notra
Guides and best practices for working with Lakebase Postgres, the database behind Neon.
A skill your agent uses when reviewing Supabase code, onboarding developers, auditing an existing project, or debugging unexpected behavior — catches the twelve most common Supabase mistakes…
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-known-pitfalls -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-known-pitfalls --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/supabase-known-pitfalls .claude/skills/supabase-known-pitfalls && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "supabase-known-pitfalls" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-known-pitfalls into .claude/skills/supabase-known-pitfalls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-known-pitfalls", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-known-pitfallsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-known-pitfalls -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-known-pitfalls --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/.curated/supabase-known-pitfalls .agents/skills/supabase-known-pitfalls && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "supabase-known-pitfalls" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-known-pitfalls into .agents/skills/supabase-known-pitfalls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-known-pitfalls", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-known-pitfalls -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-known-pitfalls --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/.curated/supabase-known-pitfalls .cursor/skills/supabase-known-pitfalls && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "supabase-known-pitfalls" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-known-pitfalls into .cursor/skills/supabase-known-pitfalls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-known-pitfalls", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path skills/.curated/supabase-known-pitfalls--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-known-pitfalls -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-known-pitfalls --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/.curated/supabase-known-pitfalls .gemini/skills/supabase-known-pitfalls && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "supabase-known-pitfalls" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-known-pitfalls into .gemini/skills/supabase-known-pitfalls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-known-pitfalls", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-known-pitfallsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-known-pitfalls -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/.curated/supabase-known-pitfalls .github/skills/supabase-known-pitfalls && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "supabase-known-pitfalls" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-known-pitfalls into .github/skills/supabase-known-pitfalls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-known-pitfalls", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-known-pitfalls -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-known-pitfalls --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/.curated/supabase-known-pitfalls .opencode/skills/supabase-known-pitfalls && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "supabase-known-pitfalls" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-known-pitfalls into .opencode/skills/supabase-known-pitfalls/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-known-pitfalls", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
supabase-known-pitfallsA skill your agent uses when reviewing Supabase code, onboarding developers, auditing an existing project, or debugging unexpected behavior — catches the twelve most common Supabase mistakes…
Supabase Known Pitfalls is an agent skill from jeremylongshore/tons-of-skills-marketplace. Use when reviewing Supabase code, onboarding developers, auditing an existing project, or debugging unexpected behavior — catches the twelve most common Supabase mistakes: exposing the servicerole key in client bundles, forgetting to enable RLS, skipping connection pooling in serverless, .single() throwing on empty results, missing .select() after insert/update, ignoring { data, error }, creating multiple client instances, and not using generated types. Trigger with phrases like "supabase mistakes", "supabase…
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `eval-spec.yaml`, `references/errors.md` and `references/examples.md`). Compatibility notes: Designed for Claude Code
It sits in Development, covering Database administration, Serverless and Code review. It works with Supabase. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadGrepFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
supabaseFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
supabase.compostgrest.orgFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
NEXT_PUBLIC_SUPABASE_ANON_KEYSUPABASE_SERVICE_ROLE_KEYSERVICE_ROLE_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code
From compatibility in the SKILL.md frontmatter.
Supabase Known Pitfalls loads about 2.3k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 174 tokens; SKILL.md has 691 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 691 words, ~2,253 tokens.
.claude/skills/supabase-known-pitfalls/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.The twelve most common Supabase mistakes, ranked by severity: security (service_role exposure, missing RLS, permissive policies, no connection pooling), data integrity (ignoring { data, error }, missing .select() after mutations, .single() on optional results), and performance / maintainability (select('*'), N+1 queries, missing FK indexes, multiple client instances, no generated types). Each pitfall shows the broken code, why it fails, and the correct pattern using createClient from @supabase/supabase-js.
This SKILL.md carries the full pitfall table plus one representative fix per category. The verbatim broken-vs-correct code and detection queries for all twelve live in references/pitfalls.md — drill in there for depth.
@supabase/supabase-js v2+ installedWork the pitfalls top-down by severity. Fix every Critical finding before moving on — a single security miss can expose the whole database.
| # | Pitfall | Severity | Fix |
|---|---|---|---|
| 1 | service_role key in client bundle | Critical | anon key on client; service_role server-only, no NEXT_PUBLIC_ |
| 2 | Table without RLS | Critical | ALTER TABLE … ENABLE ROW LEVEL SECURITY right after CREATE TABLE |
| 3 | Overly permissive RLS policy | Critical | scope USING (…) to auth.uid(), never USING (true) for writes |
| 4 | No connection pooling in serverless | Critical | pooled string (Supavisor, port 6543), not the direct 5432 URL |
| 5 | Ignoring { data, error } | High | destructure both; check error before touching data |
| 6 | Missing .select() after mutation | High | chain .select('cols') — mutations return null otherwise |
| 7 | .single() on optional result | High | use .maybeSingle() for 0-or-1; .single() only for guaranteed 1 |
| 8 | select('*') everywhere | Medium | name the columns — smaller payload, typed, no leakage |
| 9 | N+1 query loop | Medium | PostgREST embedded join, or batch with .in() |
| 10 | FK column without index | Medium | CREATE INDEX on every foreign-key column |
| 11 | Multiple client instances | Low | singleton in lib/supabase.ts, imported everywhere |
| 12 | Hand-written DB types | Low | supabase gen types typescript --linked |
The service_role key bypasses all RLS, so it must never reach a browser bundle. Split the client by trust boundary:
// Client (browser): anon key — respects RLS
const supabase = createClient(url, process.env.NEXT_PUBLIC_SUPABASE_ANON_KEY!)
// Server only (API routes, server actions): service_role, NO NEXT_PUBLIC_ prefix
const supabaseAdmin = createClient(url, process.env.SUPABASE_SERVICE_ROLE_KEY!,
{ auth: { autoRefreshToken: false, persistSession: false } })Then confirm RLS is enabled on every table, tighten any USING (true) policy to auth.uid(), and use the pooled connection string in serverless. Full broken-vs-correct code and the SQL detection queries for pitfalls 1-4 are in the Security section of references/pitfalls.md.
Supabase returns { data, error } and mutations return null unless you ask for the row back:
const { data, error } = await supabase
.from('orders').insert(order)
.select('id, status') // without .select(), data is null
.maybeSingle() // .single() throws PGRST116 on 0 rows
if (error) throw new Error(`Order failed: ${error.message}`)See the Data Integrity section of references/pitfalls.md for the .single() vs .maybeSingle() rule of thumb and each failure mode.
Name your columns, collapse N+1 loops into a single embedded join, index foreign keys, share one client instance, and use generated types:
// One query instead of 1 + N — PostgREST embeds the FK relation
const { data } = await supabase
.from('projects')
.select('id, name, tasks (id, title, status)')The full singleton pattern, the FK-index detection query, and the supabase gen types workflow are in the Performance and Maintainability section of references/pitfalls.md.
{ data, error } handling, .select() after mutations, .maybeSingle() usage| Issue | Cause | Solution |
|---|---|---|
PGRST116: JSON object requested, multiple (or no) rows returned | Used .single() when 0 or 2+ rows match | Use .maybeSingle() for optional lookups |
data is null after insert | Missing .select() chain | Add .select('column1, column2') after .insert() |
TypeError: Cannot read property of null | Destructured only data, ignoring error | Always destructure { data, error } and check error first |
too many connections for role | Direct connection from serverless | Use pooled connection string (port 6543) |
permission denied for table | RLS blocking access, no matching policy | Check RLS policies match the authenticated user's JWT claims |
relation does not exist | Table name typo, not caught at compile time | Use generated types for compile-time validation |
More operator-facing failure modes (legacy codebases, false positives, fixes that break tests): references/errors.md.
# Check for the three critical code-level security pitfalls in one pass
echo "=== Pitfall 1: Service role in client code ==="
grep -rn 'SERVICE_ROLE' --include="*.tsx" --include="*.ts" src/ app/ components/ 2>/dev/null || echo "Clean"
echo "=== Pitfall 2: Tables without RLS (run in SQL Editor) ==="
echo "SELECT tablename FROM pg_tables WHERE schemaname='public' AND rowsecurity=false;"
echo "=== Pitfall 3: Overly permissive policies (run in SQL Editor) ==="
echo "SELECT tablename, policyname FROM pg_policies WHERE qual='true' AND cmd!='r';"### Security
- [ ] No SERVICE_ROLE_KEY in client-side code or NEXT_PUBLIC_* vars
- [ ] RLS enabled on all new tables; policies scope to auth.uid() (no USING(true) writes)
### Data Integrity
- [ ] All calls destructure { data, error } and check error
- [ ] .select() chained after insert/update/upsert; .maybeSingle() for optional lookups
### Performance & Maintainability
- [ ] Columns named in .select() (no select('*')); no N+1; FK columns indexed
- [ ] Single createClient instance; generated types; pooled connection string in serverlessMore detection one-liners: references/examples.md. Every pitfall's full before/after code: references/pitfalls.md.
This completes the Supabase pitfalls reference. To start a new project with best practices from day one, see supabase-hello-world.
© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in skills/.curated/supabase-known-pitfalls of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit cfae287
Supabase Known Pitfalls next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Supabase Known Pitfalls this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~2.3k | Automated safety check: Pass | MIT | |
| Neon Postgresusenotra/notra | 260 | — | ~4.1k | Automated safety check: Notes | AGPL-3.0 | |
| Neon Postgresneondatabase/agent-skills | 100 | — | ~4.1k | Automated safety check: Notes | Apache-2.0 | |
| Requesting Code Reviewt1mmen/srtd | 105 | — | ~807 | Automated safety check: Pass | MIT | |
| AWS Auroraalinaqi/maggy | 707 | — | ~3.9k | Automated safety check: Pass | MIT | |
| Cloudbase Code ReviewTencentCloudBase/CloudBase-AI-Toolkit | 1.1k | 2 repos | ~1.1k | Automated safety check: Pass | MIT |
usenotra/notra
Guides and best practices for working with Lakebase Postgres, the database behind Neon.
neondatabase/agent-skills
Guides and best practices for working with Lakebase Postgres on Neon: connections, pooled vs direct, schema migrations, branching, autoscaling, scale-to-zero, instant restore, read replicas, IP…
t1mmen/srtd
Structured code review workflow for SRTD development. An agent skill from t1mmen/srtd.
alinaqi/maggy
AWS Aurora Serverless v2, RDS Proxy, Data API, connection pooling
TencentCloudBase/CloudBase-AI-Toolkit
Code review and validation for CloudBase projects. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.
sickn33/agentic-awesome-skills
Use the @upstash/redis HTTP client for caching, sessions, counters, and Redis data structures from serverless and edge runtimes without connection pooling.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Works with
Categories
A skill your agent uses when reviewing Supabase code, onboarding developers, auditing an existing project, or debugging unexpected behavior — catches the twelve most common Supabase mistakes…. Supabase Known Pitfalls is an agent skill from jeremylongshore/tons-of-skills-marketplace.select() after insert/update, ignoring { data, error }, creating multiple client instances, and not using generated types.
Supabase Known Pitfalls fits situations like: reviewing Supabase code; onboarding developers; auditing an existing project; debugging unexpected behavior — catches the twelve most common Supabase mistakes: exposing the servicerole key in client bundles.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-known-pitfalls -a claude-code`. Or copy the skill folder (skills/.curated/supabase-known-pitfalls in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/supabase-known-pitfalls in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-known-pitfalls -a codex`. Or copy the skill folder (skills/.curated/supabase-known-pitfalls in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/supabase-known-pitfalls in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-known-pitfalls -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supabase-known-pitfalls, .gemini/skills/supabase-known-pitfalls, .github/skills/supabase-known-pitfalls and .opencode/skills/supabase-known-pitfalls in your project.
Going by SKILL.md and its folder, Supabase Known Pitfalls needs the command-line tools its instructions call (supabase) and credentials named NEXT_PUBLIC_SUPABASE_ANON_KEY, SUPABASE_SERVICE_ROLE_KEY and SERVICE_ROLE_KEY. Our summary lists: A credential in NEXT_PUBLIC_SUPABASE_ANON_KEY; A credential in SUPABASE_SERVICE_ROLE_KEY. Its frontmatter pre-approves these tools: Read, Grep. Compatibility (from SKILL.md): Designed for Claude Code.
SKILL.md names 2 domains. As links in the text: supabase.com and postgrest.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Supabase Known Pitfalls is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Supabase Known Pitfalls: Neon Postgres (usenotra/notra, 260 stars), Neon Postgres (neondatabase/agent-skills, 100 stars), Requesting Code Review (t1mmen/srtd, 105 stars) and AWS Aurora (alinaqi/maggy, 707 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.