Agent skill

Supabase Known Pitfalls

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

A skill your agent uses when reviewing Supabase code, onboarding developers, auditing an existing project, or debugging unexpected behavior — catches the twelve most common Supabase mistakes…

MITAuto-check passedDevelopment

Install Supabase Known Pitfalls

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-known-pitfalls -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-known-pitfalls --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/supabase-known-pitfalls .claude/skills/supabase-known-pitfalls && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supabase-known-pitfalls
GitHub stars
2.8k
Token cost
~2.3k tokens
SKILL.md length
691 words
Files
5 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when reviewing Supabase code, onboarding developers, auditing an existing project, or debugging unexpected behavior — catches the twelve most common Supabase mistakes…

  • Works in 3 steps: Security (Critical, pitfalls 1-4) → Data Integrity (High, pitfalls 5-7) → Performance & Maintainability…
  • Reviewing Supabase code
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 4 more sections
  • Calls supabase; needs NEXT_PUBLIC_SUPABASE_ANON_KEY and SUPABASE_SERVICE_ROLE_KEY

What it does

Supabase Known Pitfalls is an agent skill from jeremylongshore/tons-of-skills-marketplace. Use when reviewing Supabase code, onboarding developers, auditing an existing project, or debugging unexpected behavior — catches the twelve most common Supabase mistakes: exposing the servicerole key in client bundles, forgetting to enable RLS, skipping connection pooling in serverless, .single() throwing on empty results, missing .select() after insert/update, ignoring { data, error }, creating multiple client instances, and not using generated types. Trigger with phrases like "supabase mistakes", "supabase…

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `eval-spec.yaml`, `references/errors.md` and `references/examples.md`). Compatibility notes: Designed for Claude Code

It sits in Development, covering Database administration, Serverless and Code review. It works with Supabase. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Reviewing Supabase code
  • Onboarding developers
  • Auditing an existing project
  • Debugging unexpected behavior — catches the twelve most common Supabase mistakes: exposing the servicerole key in client bundles

Example prompts

  • “supabase mistakes”
  • “supabase anti-patterns”
  • “supabase pitfalls”
  • “/supabase-known-pitfalls”

Requirements

  • A credential in NEXT_PUBLIC_SUPABASE_ANON_KEY
  • A credential in SUPABASE_SERVICE_ROLE_KEY
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Grep

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Security (Critical, pitfalls 1-4)
  2. Data Integrity (High, pitfalls 5-7)
  3. Performance & Maintainability (Medium/Low, pitfalls 8-12)

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • supabase

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • supabase.com
    • postgrest.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NEXT_PUBLIC_SUPABASE_ANON_KEY
    • SUPABASE_SERVICE_ROLE_KEY
    • SERVICE_ROLE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Supabase Known Pitfalls loads about 2.3k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 174 tokens; SKILL.md has 691 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~174
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 691 words, ~2,253 tokens.

Download SKILL.mdSave it as .claude/skills/supabase-known-pitfalls/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
supabase-known-pitfalls
description
Use when reviewing Supabase code, onboarding developers, auditing an existing project, or debugging unexpected behavior — catches the twelve most common Supabase mistakes: exposing the service_role key in client bundles, forgetting to enable RLS, skipping connection pooling in serverless, .single() throwing on empty results, missing .select() after insert/update, ignoring { data, error }, creating multiple client instances, and not using generated types. Trigger with phrases like "supabase mistakes", "supabase anti-patterns", "supabase pitfalls", "supabase code review", "supabase gotchas", "supabase debugging", "what not to do supabase", "supabase common errors".
allowed-tools
Read, Grep
compatibility
Designed for Claude Code
version
1.54.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, supabase, anti-patterns, code-review, debugging, security, pitfalls

Supabase Known Pitfalls

Overview

The twelve most common Supabase mistakes, ranked by severity: security (service_role exposure, missing RLS, permissive policies, no connection pooling), data integrity (ignoring { data, error }, missing .select() after mutations, .single() on optional results), and performance / maintainability (select('*'), N+1 queries, missing FK indexes, multiple client instances, no generated types). Each pitfall shows the broken code, why it fails, and the correct pattern using createClient from @supabase/supabase-js.

This SKILL.md carries the full pitfall table plus one representative fix per category. The verbatim broken-vs-correct code and detection queries for all twelve live in references/pitfalls.md — drill in there for depth.

Prerequisites

  • Access to a Supabase project codebase for review
  • @supabase/supabase-js v2+ installed
  • Basic understanding of Row Level Security (RLS)

Instructions

Work the pitfalls top-down by severity. Fix every Critical finding before moving on — a single security miss can expose the whole database.

#PitfallSeverityFix
1service_role key in client bundleCriticalanon key on client; service_role server-only, no NEXT_PUBLIC_
2Table without RLSCriticalALTER TABLE … ENABLE ROW LEVEL SECURITY right after CREATE TABLE
3Overly permissive RLS policyCriticalscope USING (…) to auth.uid(), never USING (true) for writes
4No connection pooling in serverlessCriticalpooled string (Supavisor, port 6543), not the direct 5432 URL
5Ignoring { data, error }Highdestructure both; check error before touching data
6Missing .select() after mutationHighchain .select('cols') — mutations return null otherwise
7.single() on optional resultHighuse .maybeSingle() for 0-or-1; .single() only for guaranteed 1
8select('*') everywhereMediumname the columns — smaller payload, typed, no leakage
9N+1 query loopMediumPostgREST embedded join, or batch with .in()
10FK column without indexMediumCREATE INDEX on every foreign-key column
11Multiple client instancesLowsingleton in lib/supabase.ts, imported everywhere
12Hand-written DB typesLowsupabase gen types typescript --linked
Step 1 — Security (Critical, pitfalls 1-4)

The service_role key bypasses all RLS, so it must never reach a browser bundle. Split the client by trust boundary:

typescript
// Client (browser): anon key — respects RLS
const supabase = createClient(url, process.env.NEXT_PUBLIC_SUPABASE_ANON_KEY!)

// Server only (API routes, server actions): service_role, NO NEXT_PUBLIC_ prefix
const supabaseAdmin = createClient(url, process.env.SUPABASE_SERVICE_ROLE_KEY!,
  { auth: { autoRefreshToken: false, persistSession: false } })

Then confirm RLS is enabled on every table, tighten any USING (true) policy to auth.uid(), and use the pooled connection string in serverless. Full broken-vs-correct code and the SQL detection queries for pitfalls 1-4 are in the Security section of references/pitfalls.md.

Step 2 — Data Integrity (High, pitfalls 5-7)

Supabase returns { data, error } and mutations return null unless you ask for the row back:

typescript
const { data, error } = await supabase
  .from('orders').insert(order)
  .select('id, status')   // without .select(), data is null
  .maybeSingle()          // .single() throws PGRST116 on 0 rows
if (error) throw new Error(`Order failed: ${error.message}`)

See the Data Integrity section of references/pitfalls.md for the .single() vs .maybeSingle() rule of thumb and each failure mode.

Show full SKILL.md (282 more words)Show less
Step 3 — Performance & Maintainability (Medium/Low, pitfalls 8-12)

Name your columns, collapse N+1 loops into a single embedded join, index foreign keys, share one client instance, and use generated types:

typescript
// One query instead of 1 + N — PostgREST embeds the FK relation
const { data } = await supabase
  .from('projects')
  .select('id, name, tasks (id, title, status)')

The full singleton pattern, the FK-index detection query, and the supabase gen types workflow are in the Performance and Maintainability section of references/pitfalls.md.

Output

  • Security pitfalls identified: service_role exposure, missing RLS, permissive policies, no connection pooling
  • Data integrity pitfalls fixed: { data, error } handling, .select() after mutations, .maybeSingle() usage
  • Performance pitfalls resolved: column-specific selects, JOIN queries, FK indexes
  • Maintainability improved: singleton client, generated types
  • Detection commands for automated scanning of each pitfall

Error Handling

IssueCauseSolution
PGRST116: JSON object requested, multiple (or no) rows returnedUsed .single() when 0 or 2+ rows matchUse .maybeSingle() for optional lookups
data is null after insertMissing .select() chainAdd .select('column1, column2') after .insert()
TypeError: Cannot read property of nullDestructured only data, ignoring errorAlways destructure { data, error } and check error first
too many connections for roleDirect connection from serverlessUse pooled connection string (port 6543)
permission denied for tableRLS blocking access, no matching policyCheck RLS policies match the authenticated user's JWT claims
relation does not existTable name typo, not caught at compile timeUse generated types for compile-time validation

More operator-facing failure modes (legacy codebases, false positives, fixes that break tests): references/errors.md.

Examples

Quick Security Audit
bash
# Check for the three critical code-level security pitfalls in one pass
echo "=== Pitfall 1: Service role in client code ==="
grep -rn 'SERVICE_ROLE' --include="*.tsx" --include="*.ts" src/ app/ components/ 2>/dev/null || echo "Clean"

echo "=== Pitfall 2: Tables without RLS (run in SQL Editor) ==="
echo "SELECT tablename FROM pg_tables WHERE schemaname='public' AND rowsecurity=false;"

echo "=== Pitfall 3: Overly permissive policies (run in SQL Editor) ==="
echo "SELECT tablename, policyname FROM pg_policies WHERE qual='true' AND cmd!='r';"
Code Review Checklist
markdown
### Security
- [ ] No SERVICE_ROLE_KEY in client-side code or NEXT_PUBLIC_* vars
- [ ] RLS enabled on all new tables; policies scope to auth.uid() (no USING(true) writes)
### Data Integrity
- [ ] All calls destructure { data, error } and check error
- [ ] .select() chained after insert/update/upsert; .maybeSingle() for optional lookups
### Performance & Maintainability
- [ ] Columns named in .select() (no select('*')); no N+1; FK columns indexed
- [ ] Single createClient instance; generated types; pooled connection string in serverless

More detection one-liners: references/examples.md. Every pitfall's full before/after code: references/pitfalls.md.

Resources

Next Steps

This completes the Supabase pitfalls reference. To start a new project with best practices from day one, see supabase-hello-world.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/.curated/supabase-known-pitfalls of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • eval-spec.yaml
  • references/errors.md
  • references/examples.md
  • references/pitfalls.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Supabase Known Pitfalls next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supabase Known Pitfalls compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supabase Known Pitfalls this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.3kAutomated safety check: PassMIT
Neon Postgresusenotra/notra260—~4.1kAutomated safety check: NotesAGPL-3.0
Neon Postgresneondatabase/agent-skills100—~4.1kAutomated safety check: NotesApache-2.0
Requesting Code Reviewt1mmen/srtd105—~807Automated safety check: PassMIT
AWS Auroraalinaqi/maggy707—~3.9kAutomated safety check: PassMIT
Cloudbase Code ReviewTencentCloudBase/CloudBase-AI-Toolkit1.1k2 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Neon Postgres

    usenotra/notra

    Guides and best practices for working with Lakebase Postgres, the database behind Neon.

    260 GitHub stars~4.1k tokensUpdated today
    DatabasesAuto-check: notes
  • Neon Postgres

    neondatabase/agent-skills

    Official

    Guides and best practices for working with Lakebase Postgres on Neon: connections, pooled vs direct, schema migrations, branching, autoscaling, scale-to-zero, instant restore, read replicas, IP…

    100 GitHub stars~4.1k tokensUpdated 2 days ago
    DatabasesAuto-check: notes
  • Structured code review workflow for SRTD development. An agent skill from t1mmen/srtd.

    105 GitHub stars~807 tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • AWS Aurora

    alinaqi/maggy

    AWS Aurora Serverless v2, RDS Proxy, Data API, connection pooling

    707 GitHub stars~3.9k tokensUpdated 17 days ago
    Backend & APIsAuto-check passed
  • Cloudbase Code Review

    TencentCloudBase/CloudBase-AI-Toolkit

    Code review and validation for CloudBase projects. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.

    1.1k GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Upstash Redis

    sickn33/agentic-awesome-skills

    Use the @upstash/redis HTTP client for caching, sessions, counters, and Redis data structures from serverless and edge runtimes without connection pooling.

    47k GitHub starsUsed in 1 repo~1.5k tokens
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Supabase Known Pitfalls

What does Supabase Known Pitfalls do?

A skill your agent uses when reviewing Supabase code, onboarding developers, auditing an existing project, or debugging unexpected behavior — catches the twelve most common Supabase mistakes…. Supabase Known Pitfalls is an agent skill from jeremylongshore/tons-of-skills-marketplace.select() after insert/update, ignoring { data, error }, creating multiple client instances, and not using generated types.

When should I use Supabase Known Pitfalls?

Supabase Known Pitfalls fits situations like: reviewing Supabase code; onboarding developers; auditing an existing project; debugging unexpected behavior — catches the twelve most common Supabase mistakes: exposing the servicerole key in client bundles.

How do I install Supabase Known Pitfalls in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-known-pitfalls -a claude-code`. Or copy the skill folder (skills/.curated/supabase-known-pitfalls in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/supabase-known-pitfalls in your project. Claude Code loads it when a task matches its description.

How do I install Supabase Known Pitfalls in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-known-pitfalls -a codex`. Or copy the skill folder (skills/.curated/supabase-known-pitfalls in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/supabase-known-pitfalls in your project. Codex loads it when a task matches its description.

Can I use Supabase Known Pitfalls in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-known-pitfalls -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supabase-known-pitfalls, .gemini/skills/supabase-known-pitfalls, .github/skills/supabase-known-pitfalls and .opencode/skills/supabase-known-pitfalls in your project.

What does Supabase Known Pitfalls need to run?

Going by SKILL.md and its folder, Supabase Known Pitfalls needs the command-line tools its instructions call (supabase) and credentials named NEXT_PUBLIC_SUPABASE_ANON_KEY, SUPABASE_SERVICE_ROLE_KEY and SERVICE_ROLE_KEY. Our summary lists: A credential in NEXT_PUBLIC_SUPABASE_ANON_KEY; A credential in SUPABASE_SERVICE_ROLE_KEY. Its frontmatter pre-approves these tools: Read, Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Supabase Known Pitfalls access the network?

SKILL.md names 2 domains. As links in the text: supabase.com and postgrest.org. This is read from the text; nothing was executed.

Is Supabase Known Pitfalls safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Supabase Known Pitfalls use?

Supabase Known Pitfalls is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supabase Known Pitfalls use?

About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to Supabase Known Pitfalls?

Skills that share tags, products or a category with Supabase Known Pitfalls: Neon Postgres (usenotra/notra, 260 stars), Neon Postgres (neondatabase/agent-skills, 100 stars), Requesting Code Review (t1mmen/srtd, 105 stars) and AWS Aurora (alinaqi/maggy, 707 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supabase Known Pitfalls?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.