Postgresql Devsec
sickn33/agentic-awesome-skills
Administer PostgreSQL databases. An agent skill from sickn33/agentic-awesome-skills.
Execute a Supabase production deployment checklist covering RLS, key hygiene, connection pooling, backups, monitoring, Edge Functions, and Storage policies.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-prod-checklist -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-prod-checklist --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/supabase-prod-checklist .claude/skills/supabase-prod-checklist && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "supabase-prod-checklist" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-prod-checklist into .claude/skills/supabase-prod-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-prod-checklist", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-prod-checklistType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-prod-checklist -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-prod-checklist --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/.curated/supabase-prod-checklist .agents/skills/supabase-prod-checklist && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "supabase-prod-checklist" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-prod-checklist into .agents/skills/supabase-prod-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-prod-checklist", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-prod-checklist -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-prod-checklist --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/.curated/supabase-prod-checklist .cursor/skills/supabase-prod-checklist && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "supabase-prod-checklist" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-prod-checklist into .cursor/skills/supabase-prod-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-prod-checklist", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path skills/.curated/supabase-prod-checklist--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-prod-checklist -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-prod-checklist --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/.curated/supabase-prod-checklist .gemini/skills/supabase-prod-checklist && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "supabase-prod-checklist" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-prod-checklist into .gemini/skills/supabase-prod-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-prod-checklist", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-prod-checklistInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-prod-checklist -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/.curated/supabase-prod-checklist .github/skills/supabase-prod-checklist && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "supabase-prod-checklist" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-prod-checklist into .github/skills/supabase-prod-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-prod-checklist", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-prod-checklist -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-prod-checklist --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/.curated/supabase-prod-checklist .opencode/skills/supabase-prod-checklist && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "supabase-prod-checklist" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/supabase-prod-checklist into .opencode/skills/supabase-prod-checklist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "supabase-prod-checklist", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
supabase-prod-checklistExecute a Supabase production deployment checklist covering RLS, key hygiene, connection pooling, backups, monitoring, Edge Functions, and Storage policies.
Supabase Prod Checklist is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute a Supabase production deployment checklist covering RLS, key hygiene, connection pooling, backups, monitoring, Edge Functions, and Storage policies. Use when deploying to production, preparing for launch, or auditing a live Supabase project for security and performance gaps. Trigger with "supabase production", "supabase go-live", "supabase launch checklist", "supabase prod ready", "deploy supabase", "supabase production readiness".
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/errors.md`, `references/examples.md` and `references/implementation.md`). Compatibility notes: Designed for Claude Code
It sits in Databases, covering Database administration, Deployment and Backup and disaster recovery. It works with Supabase. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditBash(npx supabase:*)Bash(curl:*)GrepFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
supabase.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SUPABASE_SERVICE_ROLE_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code
From compatibility in the SKILL.md frontmatter.
Supabase Prod Checklist loads about 3.7k tokens when it runs, and up to ~8.3k if it reads all its reference files. Until then it costs about 117 tokens; SKILL.md has 1,507 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 1,507 words, ~3,668 tokens.
.claude/skills/supabase-prod-checklist/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Actionable 14-step checklist for taking a Supabase project to production, based on Supabase's official production guide. Each step below carries its verification checklist inline; the full SQL, TypeScript, and CLI commands for every step live in references/step-commands.md.
@supabase/supabase-js v2+ installednpx supabase --version)Work top to bottom. Every checkbox must be satisfied before go-live. Each step names the commands to run; copy them from references/step-commands.md.
RLS is the single most critical production requirement. Without it, any client with your anon key can read/write every row. Start with the audit query — it must return zero rows before going live:
-- Find tables WITHOUT RLS enabled (must return zero rows before launch)
SELECT schemaname, tablename, rowsecurity
FROM pg_tables
WHERE schemaname = 'public' AND rowsecurity = false;Then ALTER TABLE ... ENABLE ROW LEVEL SECURITY and add per-command policies —
full CREATE POLICY patterns in step-commands.md.
USING (true) without intent (public read tables only)The anon key is safe for client-side code. The service_role key bypasses RLS
entirely and must never leave server-side environments. See the two-client setup
in step-commands.md.
NEXT_PUBLIC_ prefix)grep -r "service_role" dist/)Supabase uses Supavisor for pooling. Serverless functions (Vercel, Netlify, Cloudflare Workers) MUST use the pooled connection string (port 6543) to avoid exhausting the database connection limit — direct connections (port 5432) are for migrations and admin tasks only. Connection strings and client config in step-commands.md.
transaction for serverless, session for long-lived connectionsSupabase provides automatic daily backups on Pro plan. Point-in-time recovery (PITR) enables granular restores.
supabase/migrations/ directory)npx supabase db push tested against a fresh project to verify migrations replay cleanlyRestrict database access to known IP addresses. This prevents unauthorized direct database connections even if credentials leak.
A custom domain replaces the default *.supabase.co URLs with your brand domain
for API and auth endpoints.
Default Supabase auth emails show generic branding. Customize them so users see your domain and brand.
Supabase enforces rate limits that vary by plan. Hitting these in production causes 429 errors.
| Resource | Free | Pro | Team |
|---|---|---|---|
| API requests | 500/min | 1,000/min | 5,000/min |
| Auth emails | 4/hour | 30/hour | 100/hour |
| Realtime connections | 200 concurrent | 500 concurrent | 2,000 concurrent |
| Edge Function invocations | 500K/month | 2M/month | 5M/month |
| Storage bandwidth | 2GB/month | 250GB/month | Custom |
| Database size | 500MB | 8GB | 50GB |
Supabase provides built-in monitoring. Review these before launch to establish baselines, and deploy a health check endpoint (full route handler in step-commands.md).
Edge Functions run on Deno Deploy. Set environment variables via the Supabase CLI or Dashboard, not hardcoded. Secret commands and a webhook function template in step-commands.md.
npx supabase functions deploy)npx supabase secrets set (not hardcoded)SUPABASE_URL and SUPABASE_SERVICE_ROLE_KEY available automatically (no need to set)npx supabase functions serve locally before deployingStorage buckets need explicit policies, similar to RLS on tables. Without policies, buckets are inaccessible (default deny). Inspection queries and example policies in step-commands.md.
file_size_limit in bucket config)allowed_mime_types)auth.uid() to prevent overwritesMissing indexes are the leading cause of slow queries after launch. Add indexes on foreign keys, filter columns, and sort columns. Diagnostic queries (missing-index, slow-query, table-bloat) and index DDL in step-commands.md.
pg_stat_statements enabled for ongoing query monitoringstatement_timeout set for authenticated role to prevent runaway queriesnpx supabase db pushAll schema changes must go through migration files, never manual Dashboard edits in production. Migration commands in step-commands.md.
supabase/migrations/ directory (version controlled)npx supabase db push tested against a fresh projectnpx supabase migration list)Run the final linked-project verification commands in step-commands.md, then confirm:
supabase-load-scale)npx supabase db pushCommon go-live failures and their fixes. Full catalog (with HTTP status codes,
alert thresholds, and a Supabase error-code switch handler) in
references/errors.md.
| Issue | Cause | Solution |
|---|---|---|
403 Forbidden on all API calls | RLS enabled but no policies created | Add SELECT/INSERT/UPDATE/DELETE policies for each role |
429 Too Many Requests | Plan rate limit exceeded | Upgrade plan or implement client-side backoff with retry |
| Connection timeout under load | Using direct connection in serverless | Switch to pooled connection string (port 6543) |
| Auth emails not delivered | Default SMTP rate-limited | Configure custom SMTP provider (SendGrid, Resend, Postmark) |
PGRST301 permission denied | Service role key used where anon expected | Check client initialization — use anon key for client-side |
| Storage upload fails | Missing bucket policy or size limit exceeded | Add INSERT policy and check file_size_limit on bucket |
| Slow queries after launch | Missing indexes on filter/join columns | Run Performance Advisor and add indexes per Step 12 |
| Migration conflicts | Manual Dashboard edits diverged from migration files | Run npx supabase db diff to capture drift, then commit |
Lean patterns below; complete, copy-paste versions (Next.js client setup, health check endpoint, full RLS policy set, storage policies, Edge Functions, rollback) in references/examples.md.
ALTER TABLE public.posts ENABLE ROW LEVEL SECURITY;
CREATE POLICY "Public read published" ON public.posts
FOR SELECT USING (status = 'published');
CREATE POLICY "Authors manage own" ON public.posts
FOR ALL USING (auth.uid() = author_id)
WITH CHECK (auth.uid() = author_id);npx supabase migration new rollback_bad_change # Create reversal SQL
npx supabase db push # Apply rollback
# For data: Dashboard > Database > Backups > PITR
# For app: vercel rollback / netlify deploy --prodsupabase-upgrade-migrationsupabase-load-scalesupabase-monitoringsupabase-edge-functions© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in skills/.curated/supabase-prod-checklist of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit cfae287
Supabase Prod Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Supabase Prod Checklist this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~3.7k | Automated safety check: Pass | MIT | |
| Postgresql Devsecsickn33/agentic-awesome-skills | 47k | 2 repos | ~2.5k | Automated safety check: Notes | MIT | |
| Postgresmagnus919/agent-skills | 115 | — | ~4k | Automated safety check: Pass | MIT | |
| Stash Deploymentcipherstash/stack | 157 | — | ~6.5k | Automated safety check: Pass | MIT | |
| Database Backupssickn33/agentic-awesome-skills | 47k | 2 repos | ~3.1k | Automated safety check: Notes | MIT | |
| Alloydb Basicsgoogle/skills | 21k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 |
sickn33/agentic-awesome-skills
Administer PostgreSQL databases. An agent skill from sickn33/agentic-awesome-skills.
magnus919/agent-skills
Operate PostgreSQL instances safely: configuration review, index and query-plan analysis, vacuum and bloat management, WAL archiving and point-in-time recovery, replication and failover, extensions…
cipherstash/stack
Deploy a CipherStash encryption rollout to a live environment without losing data — the multi-deploy ladder (schema-add + dual-write → backfill → read cutover → stop dual-writes → drop plaintext)…
sickn33/agentic-awesome-skills
Implement database backup strategies. An agent skill from sickn33/agentic-awesome-skills.
google/skills
Manages clusters, instances, and backups for AlloyDB for PostgreSQL, and integrates with AlloyDB Model Context Protocol (MCP) tools for automated database operations.
davila7/claude-code-templates
Manages clusters, instances, and backups for AlloyDB for PostgreSQL, and integrates with AlloyDB MCP tools for automated database operations including AI-powered search and vector capabilities.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Works with
Categories
Execute a Supabase production deployment checklist covering RLS, key hygiene, connection pooling, backups, monitoring, Edge Functions, and Storage policies. Supabase Prod Checklist is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute a Supabase production deployment checklist covering RLS, key hygiene, connection pooling, backups, monitoring, Edge Functions, and Storage policies.
Supabase Prod Checklist fits situations like: deploying to production; preparing for launch; auditing a live Supabase project for security and performance gaps; with supabase production.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-prod-checklist -a claude-code`. Or copy the skill folder (skills/.curated/supabase-prod-checklist in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/supabase-prod-checklist in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-prod-checklist -a codex`. Or copy the skill folder (skills/.curated/supabase-prod-checklist in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/supabase-prod-checklist in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-prod-checklist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supabase-prod-checklist, .gemini/skills/supabase-prod-checklist, .github/skills/supabase-prod-checklist and .opencode/skills/supabase-prod-checklist in your project.
Going by SKILL.md and its folder, Supabase Prod Checklist needs the command-line tools its instructions call (npx) and credentials named SUPABASE_SERVICE_ROLE_KEY. Our summary lists: Node.js; A credential in SUPABASE_SERVICE_ROLE_KEY. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(npx supabase:*), Bash(curl:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.
SKILL.md names 1 domain. As links in the text: supabase.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Supabase Prod Checklist is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Supabase Prod Checklist: Postgresql Devsec (sickn33/agentic-awesome-skills, 47k stars), Postgres (magnus919/agent-skills, 115 stars), Stash Deployment (cipherstash/stack, 157 stars) and Database Backups (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.