Agent skill

Supabase Policy Guardrails

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Enforce organizational governance for Supabase projects: shared RLS policy library with reusable templates, table and column naming conventions, migration review process with CI checks, cost alert…

MITAuto-check passedSecurity

Install Supabase Policy Guardrails

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-policy-guardrails -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-policy-guardrails --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/supabase-policy-guardrails .claude/skills/supabase-policy-guardrails && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supabase-policy-guardrails
GitHub stars
2.8k
Token cost
~2.8k tokens
SKILL.md length
454 words
Files
5 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Enforce organizational governance for Supabase projects: shared RLS policy library with reusable templates, table and column naming conventions, migration review process with CI checks, cost alert…

  • Works in 2 steps: Shared RLS Policy Library and Naming… → Migration Review Process with CI Checks
  • Establishing Supabase standards across teams
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 4 more sections
  • Calls supabase; needs SUPABASE_ACCESS_TOKEN

What it does

Supabase Policy Guardrails is an agent skill from jeremylongshore/tons-of-skills-marketplace. Enforce organizational governance for Supabase projects: shared RLS policy library with reusable templates, table and column naming conventions, migration review process with CI checks, cost alert thresholds, and security audit scripts scanning for common misconfigurations. Use when establishing Supabase standards across teams, creating RLS policy templates, setting up migration review workflows, or auditing existing projects for security and cost issues. Trigger with phrases like "supabase governance", "supabase…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/ci-cost-security.md`, `references/errors.md` and `references/eslint-rules.md`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Security review and LLM guardrails. It works with Supabase. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Establishing Supabase standards across teams
  • Creating RLS policy templates
  • Setting up migration review workflows
  • Auditing existing projects for security and cost issues

Example prompts

  • “supabase governance”
  • “supabase policy library”
  • “supabase naming convention”
  • “/supabase-policy-guardrails”

Requirements

  • A credential in SUPABASE_ACCESS_TOKEN
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(supabase:*), Bash(psql:*), Bash(npx:*), Grep

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Shared RLS Policy Library and Naming Conventions
  2. Migration Review Process with CI Checks

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(supabase:*)
    • Bash(psql:*)
    • Bash(npx:*)
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • supabase

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • supabase.com
    • postgresql.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SUPABASE_ACCESS_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Supabase Policy Guardrails loads about 2.8k tokens when it runs, and up to ~7.1k if it reads all its reference files. Until then it costs about 174 tokens; SKILL.md has 454 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~174
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 454 words, ~2,837 tokens.

Download SKILL.mdSave it as .claude/skills/supabase-policy-guardrails/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
supabase-policy-guardrails
description
Enforce organizational governance for Supabase projects: shared RLS policy library with reusable templates, table and column naming conventions, migration review process with CI checks, cost alert thresholds, and security audit scripts scanning for common misconfigurations. Use when establishing Supabase standards across teams, creating RLS policy templates, setting up migration review workflows, or auditing existing projects for security and cost issues. Trigger with phrases like "supabase governance", "supabase policy library", "supabase naming convention", "supabase migration review", "supabase cost alert", "supabase security audit", "supabase RLS template".
allowed-tools
Read, Write, Edit, Bash(supabase:*), Bash(psql:*), Bash(npx:*), Grep
compatibility
Designed for Claude Code
version
1.54.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, supabase, governance, security, rls, naming-conventions, cost-management

Supabase Policy Guardrails

Overview

Organizational governance for Supabase at scale: a shared RLS policy library (reusable templates for common access patterns), naming conventions (tables, columns, functions, policies), migration review process (CI checks ensuring RLS, preventing destructive operations, enforcing naming), cost alert configuration (billing thresholds and usage monitoring), and security audit scripts (scanning for exposed keys, missing RLS, overly permissive policies). All patterns use real createClient from @supabase/supabase-js and Supabase CLI commands.

Prerequisites

  • Supabase project with supabase CLI installed and linked
  • @supabase/supabase-js v2+ installed
  • CI/CD pipeline (GitHub Actions recommended)
  • Database access via psql or Supabase SQL Editor
  • Pro plan recommended for cost alerts and usage API

Instructions

Step 1 — Shared RLS Policy Library and Naming Conventions
RLS Policy Templates

Create reusable RLS policy templates that teams apply to new tables. This prevents each developer from writing ad-hoc policies and ensures consistent access control.

sql
-- supabase/migrations/00000000000000_rls_policy_library.sql
-- Shared RLS policy library — apply these templates to new tables

-- ============================================================
-- Template 1: Owner-only access (user owns the row)
-- Usage: tables with a user_id column (todos, profiles, settings)
-- ============================================================
CREATE OR REPLACE FUNCTION public.rls_owner_only(table_name text, user_column text DEFAULT 'user_id')
RETURNS void AS $$
BEGIN
  EXECUTE format('ALTER TABLE public.%I ENABLE ROW LEVEL SECURITY', table_name);

  EXECUTE format(
    'CREATE POLICY "owner_select" ON public.%I FOR SELECT USING (%I = auth.uid())',
    table_name, user_column
  );
  EXECUTE format(
    'CREATE POLICY "owner_insert" ON public.%I FOR INSERT WITH CHECK (%I = auth.uid())',
    table_name, user_column
  );
  EXECUTE format(
    'CREATE POLICY "owner_update" ON public.%I FOR UPDATE USING (%I = auth.uid())',
    table_name, user_column
  );
  EXECUTE format(
    'CREATE POLICY "owner_delete" ON public.%I FOR DELETE USING (%I = auth.uid())',
    table_name, user_column
  );
END;
$$ LANGUAGE plpgsql;

-- ============================================================
-- Template 2: Organization-scoped access (user is member of org)
-- Usage: tables with org_id referencing org_members
-- ============================================================
CREATE OR REPLACE FUNCTION public.rls_org_scoped(
  table_name text,
  org_column text DEFAULT 'org_id',
  allow_delete boolean DEFAULT false
)
RETURNS void AS $$
BEGIN
  EXECUTE format('ALTER TABLE public.%I ENABLE ROW LEVEL SECURITY', table_name);

  EXECUTE format(
    'CREATE POLICY "org_select" ON public.%I FOR SELECT USING (
      %I IN (SELECT org_id FROM public.org_members WHERE user_id = auth.uid())
    )', table_name, org_column
  );
  EXECUTE format(
    'CREATE POLICY "org_insert" ON public.%I FOR INSERT WITH CHECK (
      %I IN (SELECT org_id FROM public.org_members WHERE user_id = auth.uid())
    )', table_name, org_column
  );
  EXECUTE format(
    'CREATE POLICY "org_update" ON public.%I FOR UPDATE USING (
      %I IN (SELECT org_id FROM public.org_members WHERE user_id = auth.uid() AND role IN (''admin'', ''editor''))
    )', table_name, org_column
  );

  IF allow_delete THEN
    EXECUTE format(
      'CREATE POLICY "org_delete" ON public.%I FOR DELETE USING (
        %I IN (SELECT org_id FROM public.org_members WHERE user_id = auth.uid() AND role = ''admin'')
      )', table_name, org_column
    );
  END IF;
END;
$$ LANGUAGE plpgsql;

-- ============================================================
-- Template 3: Public read, authenticated write
-- Usage: blog posts, product listings, public content
-- ============================================================
CREATE OR REPLACE FUNCTION public.rls_public_read_auth_write(
  table_name text,
  owner_column text DEFAULT 'created_by'
)
RETURNS void AS $$
BEGIN
  EXECUTE format('ALTER TABLE public.%I ENABLE ROW LEVEL SECURITY', table_name);

  EXECUTE format(
    'CREATE POLICY "public_select" ON public.%I FOR SELECT USING (true)',
    table_name
  );
  EXECUTE format(
    'CREATE POLICY "auth_insert" ON public.%I FOR INSERT WITH CHECK (auth.uid() IS NOT NULL)',
    table_name
  );
  EXECUTE format(
    'CREATE POLICY "owner_update" ON public.%I FOR UPDATE USING (%I = auth.uid())',
    table_name, owner_column
  );
  EXECUTE format(
    'CREATE POLICY "owner_delete" ON public.%I FOR DELETE USING (%I = auth.uid())',
    table_name, owner_column
  );
END;
$$ LANGUAGE plpgsql;

-- Apply templates to tables:
-- SELECT public.rls_owner_only('todos');
-- SELECT public.rls_org_scoped('projects', 'org_id', true);
-- SELECT public.rls_public_read_auth_write('blog_posts', 'author_id');
Naming Conventions
sql
-- supabase/migrations/00000000000001_naming_convention_check.sql
-- Validation function that checks naming conventions at migration time

CREATE OR REPLACE FUNCTION public.validate_naming_conventions()
RETURNS TABLE(issue text, object_name text, suggestion text) AS $$
BEGIN
  -- Tables must be snake_case, plural
  RETURN QUERY
  SELECT
    'Table name should be plural snake_case'::text,
    t.tablename::text,
    regexp_replace(t.tablename, '([A-Z])', '_\1', 'g')::text
  FROM pg_tables t
  WHERE t.schemaname = 'public'
  AND (
    t.tablename ~ '[A-Z]'           -- contains uppercase
    OR t.tablename ~ '-'             -- contains hyphens
    OR t.tablename !~ 's$'           -- not plural (heuristic)
  )
  AND t.tablename NOT LIKE '\_%';   -- skip internal tables

  -- Columns must be snake_case
  RETURN QUERY
  SELECT
    'Column name should be snake_case'::text,
    (c.table_name || '.' || c.column_name)::text,
    regexp_replace(c.column_name, '([A-Z])', '_\1', 'g')::text
  FROM information_schema.columns c
  WHERE c.table_schema = 'public'
  AND (c.column_name ~ '[A-Z]' OR c.column_name ~ '-');

  -- Foreign key columns should end with _id
  RETURN QUERY
  SELECT
    'Foreign key column should end with _id'::text,
    (tc.table_name || '.' || kcu.column_name)::text,
    (kcu.column_name || '_id')::text
  FROM information_schema.table_constraints tc
  JOIN information_schema.key_column_usage kcu
    ON tc.constraint_name = kcu.constraint_name
  WHERE tc.constraint_type = 'FOREIGN KEY'
  AND tc.table_schema = 'public'
  AND kcu.column_name NOT LIKE '%_id';

  -- Boolean columns should start with is_ or has_
  RETURN QUERY
  SELECT
    'Boolean column should start with is_ or has_'::text,
    (c.table_name || '.' || c.column_name)::text,
    ('is_' || c.column_name)::text
  FROM information_schema.columns c
  WHERE c.table_schema = 'public'
  AND c.data_type = 'boolean'
  AND c.column_name NOT LIKE 'is_%'
  AND c.column_name NOT LIKE 'has_%';
END;
$$ LANGUAGE plpgsql;

-- Run: SELECT * FROM public.validate_naming_conventions();
Naming Convention Reference
ObjectConventionExample
TablesPlural snake_caseuser_profiles, order_items
Columnssnake_casecreated_at, full_name
Foreign keys{referenced_table_singular}_iduser_id, order_id
Booleansis_ or has_ prefixis_active, has_verified_email
Timestamps_at suffixcreated_at, updated_at, deleted_at
RLS policies{scope}_{operation}owner_select, org_insert
Functionsverb_nouncreate_user, get_dashboard_metrics
Indexesidx_{table}_{columns}idx_orders_user_id_created_at
Migrations{timestamp}_{verb}_{description}20250322000000_create_orders_table.sql
Step 2 — Migration Review Process with CI Checks

See CI checks, cost alerts, and security audits for GitHub Actions migration guardrails (RLS enforcement, naming checks, destructive operation blocks), pre-commit hooks, cost monitoring with Slack alerts, security audit scripts, and scheduled Edge Function audits.

Output

  • Shared RLS policy library with owner-only, org-scoped, and public-read templates
  • Naming convention validation function checking tables, columns, FKs, and booleans
  • CI pipeline enforcing RLS, naming, and destructive operation controls
  • Pre-commit hook blocking hardcoded secrets and tables without RLS
  • Cost monitoring script with configurable thresholds and Slack alerting
  • Security audit script detecting missing RLS, permissive policies, and missing indexes
  • Scheduled Edge Function for continuous security monitoring
Show full SKILL.md (153 more words)Show less

Error Handling

IssueCauseSolution
CI RLS check fails on new tableMigration missing ENABLE ROW LEVEL SECURITYAdd ALTER TABLE after CREATE TABLE in same migration
Naming convention false positiveTable is intentionally singular (e.g., config)Add to exclusion list in validation function
Cost alert not firingMissing SUPABASE_ACCESS_TOKENGenerate token at supabase.com/dashboard/account/tokens
Security audit times outToo many tables to scanRun audit on specific schemas or paginate results
Pre-commit blocks legitimate JWT in testTest fixture contains JWT-like stringAdd test file path to exclusion pattern
RLS template function not foundMigration not appliedRun supabase db reset or apply migration manually

Examples

See CI, cost, and security reference for full examples including applying RLS templates, running security audits, and checking naming conventions.

Resources

Next Steps

For architecture patterns across different app types, see supabase-architecture-variants.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/.curated/supabase-policy-guardrails of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/ci-cost-security.md
  • references/errors.md
  • references/eslint-rules.md
  • references/examples.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Supabase Policy Guardrails next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supabase Policy Guardrails compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supabase Policy Guardrails this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.8kAutomated safety check: PassMIT
Memstack Security Rls Checkercwinvestments/memstack423—~2.9kAutomated safety check: NotesProprietary
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
Vibe Checkbenavlabs/vibe-check118—~1.1kAutomated safety check: NotesMIT
Security Reviewaffaan-m/ECC277k3 repos~2.5kAutomated safety check: NotesMIT
Security Reviewaffaan-m/ECC277k2 repos~2.5kAutomated safety check: NotesMIT

Similar skills

  • Memstack Security Rls Checker

    cwinvestments/memstack

    A skill your agent uses when the user says 'check RLS', 'audit RLS', 'RLS policies', 'row level security', 'Supabase security audit', or needs to verify table-level access control.

    423 GitHub stars~2.9k tokensUpdated 14 days ago
    SecurityAuto-check: notes
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • Vibe Check

    benavlabs/vibe-check

    Security audit for web apps, especially AI-built ("vibe coded") ones.

    118 GitHub stars~1.1k tokensUpdated 22 days ago
    SecurityAuto-check: notes
  • Security Review

    affaan-m/ECC

    在添加身份验证、处理用户输入、处理机密信息、创建API端点或实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。

    277k GitHub starsUsed in 3 repos~2.5k tokens
    SecurityAuto-check: notes
  • Security Review

    affaan-m/ECC

    認証の追加、ユーザー入力の処理、シークレットの操作、APIエンドポイントの作成、支払い/機密機能の実装時にこのスキルを使用します。包括的なセキュリティチェックリストとパターンを提供します。

    277k GitHub starsUsed in 2 repos~2.5k tokens
    SecurityAuto-check: notes
  • Security Review

    affaan-m/ECC

    인증 추가, 사용자 입력 처리, 시크릿 관리, API 엔드포인트 생성, 결제/민감한 기능 구현 시 이 스킬을 사용하세요.

    277k GitHub starsUsed in 2 repos~2.7k tokens
    SecurityAuto-check: notes

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Supabase Policy Guardrails

What does Supabase Policy Guardrails do?

Enforce organizational governance for Supabase projects: shared RLS policy library with reusable templates, table and column naming conventions, migration review process with CI checks, cost alert…. Supabase Policy Guardrails is an agent skill from jeremylongshore/tons-of-skills-marketplace. Enforce organizational governance for Supabase projects: shared RLS policy library with reusable templates, table and column naming conventions, migration review process with CI checks, cost alert thresholds, and security audit scripts scanning for common misconfigurations.

When should I use Supabase Policy Guardrails?

Supabase Policy Guardrails fits situations like: establishing Supabase standards across teams; creating RLS policy templates; setting up migration review workflows; auditing existing projects for security and cost issues.

How do I install Supabase Policy Guardrails in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-policy-guardrails -a claude-code`. Or copy the skill folder (skills/.curated/supabase-policy-guardrails in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/supabase-policy-guardrails in your project. Claude Code loads it when a task matches its description.

How do I install Supabase Policy Guardrails in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-policy-guardrails -a codex`. Or copy the skill folder (skills/.curated/supabase-policy-guardrails in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/supabase-policy-guardrails in your project. Codex loads it when a task matches its description.

Can I use Supabase Policy Guardrails in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-policy-guardrails -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supabase-policy-guardrails, .gemini/skills/supabase-policy-guardrails, .github/skills/supabase-policy-guardrails and .opencode/skills/supabase-policy-guardrails in your project.

What does Supabase Policy Guardrails need to run?

Going by SKILL.md and its folder, Supabase Policy Guardrails needs the command-line tools its instructions call (supabase) and credentials named SUPABASE_ACCESS_TOKEN. Our summary lists: A credential in SUPABASE_ACCESS_TOKEN. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(supabase:*), Bash(psql:*), Bash(npx:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Supabase Policy Guardrails access the network?

SKILL.md names 2 domains. As links in the text: supabase.com and postgresql.org. This is read from the text; nothing was executed.

Is Supabase Policy Guardrails safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Supabase Policy Guardrails use?

Supabase Policy Guardrails is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supabase Policy Guardrails use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.3k tokens, read only when the agent opens those files.

What are the alternatives to Supabase Policy Guardrails?

Skills that share tags, products or a category with Supabase Policy Guardrails: Memstack Security Rls Checker (cwinvestments/memstack, 423 stars), Security Review (jewbetcha/opentrace, 116 stars), Vibe Check (benavlabs/vibe-check, 118 stars) and Security Review (affaan-m/ECC, 277k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supabase Policy Guardrails?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.