Agent skill

Supabase Prod Checklist

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Execute a Supabase production deployment checklist covering RLS, key hygiene, connection pooling, backups, monitoring, Edge Functions, and Storage policies.

MITAuto-check passedDatabases

Install Supabase Prod Checklist

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-prod-checklist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-prod-checklist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/supabase-prod-checklist .claude/skills/supabase-prod-checklist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supabase-prod-checklist
GitHub stars
2.8k
Token cost
~3.7k tokens
SKILL.md length
1,507 words
Files
5 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Execute a Supabase production deployment checklist covering RLS, key hygiene, connection pooling, backups, monitoring, Edge Functions, and Storage policies.

  • Works in 12 steps: Enforce Row Level Security on ALL Tables → Enforce Key Separation — Anon vs Service… → Configure Connection Pooling (Supavisor) → …
  • Deploying to production
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 4 more sections
  • Calls npx; needs SUPABASE_SERVICE_ROLE_KEY

What it does

Supabase Prod Checklist is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute a Supabase production deployment checklist covering RLS, key hygiene, connection pooling, backups, monitoring, Edge Functions, and Storage policies. Use when deploying to production, preparing for launch, or auditing a live Supabase project for security and performance gaps. Trigger with "supabase production", "supabase go-live", "supabase launch checklist", "supabase prod ready", "deploy supabase", "supabase production readiness".

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/errors.md`, `references/examples.md` and `references/implementation.md`). Compatibility notes: Designed for Claude Code

It sits in Databases, covering Database administration, Deployment and Backup and disaster recovery. It works with Supabase. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Deploying to production
  • Preparing for launch
  • Auditing a live Supabase project for security and performance gaps
  • With supabase production

Example prompts

  • “supabase production”
  • “supabase go-live”
  • “supabase launch checklist”
  • “/supabase-prod-checklist”

Requirements

  • Node.js
  • A credential in SUPABASE_SERVICE_ROLE_KEY
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(npx supabase:*), Bash(curl:*), Grep

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Enforce Row Level Security on ALL Tables
  2. Enforce Key Separation — Anon vs Service Role
  3. Configure Connection Pooling (Supavisor)
  4. Enable Database Backups
  5. Configure Network Restrictions
  6. Configure Custom Domain
  7. Customize Auth Email Templates
  8. Understand Rate Limits Per Tier
  9. Review Monitoring Dashboards
  10. Deploy Edge Functions with Proper Env Vars
  11. Verify Storage Bucket Policies
  12. Add Database Indexes on Frequently Queried Columns

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(npx supabase:*)
    • Bash(curl:*)
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • supabase.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SUPABASE_SERVICE_ROLE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Supabase Prod Checklist loads about 3.7k tokens when it runs, and up to ~8.3k if it reads all its reference files. Until then it costs about 117 tokens; SKILL.md has 1,507 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 1,507 words, ~3,668 tokens.

Download SKILL.mdSave it as .claude/skills/supabase-prod-checklist/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
supabase-prod-checklist
description
Execute a Supabase production deployment checklist covering RLS, key hygiene, connection pooling, backups, monitoring, Edge Functions, and Storage policies. Use when deploying to production, preparing for launch, or auditing a live Supabase project for security and performance gaps. Trigger with "supabase production", "supabase go-live", "supabase launch checklist", "supabase prod ready", "deploy supabase", "supabase production readiness".
allowed-tools
Read, Write, Edit, Bash(npx supabase:*), Bash(curl:*), Grep
compatibility
Designed for Claude Code
version
1.54.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, supabase, deployment, production, security, rls

Supabase Production Deployment Checklist

Overview

Actionable 14-step checklist for taking a Supabase project to production, based on Supabase's official production guide. Each step below carries its verification checklist inline; the full SQL, TypeScript, and CLI commands for every step live in references/step-commands.md.

Prerequisites

  • Supabase project on Pro plan or higher (required for PITR, network restrictions)
  • Separate production project (never share dev/prod)
  • @supabase/supabase-js v2+ installed
  • Supabase CLI installed (npx supabase --version)
  • Domain and DNS configured for custom domain
  • Deployment platform ready (Vercel, Netlify, Cloudflare, etc.)

Instructions

Work top to bottom. Every checkbox must be satisfied before go-live. Each step names the commands to run; copy them from references/step-commands.md.

Step 1: Enforce Row Level Security on ALL Tables

RLS is the single most critical production requirement. Without it, any client with your anon key can read/write every row. Start with the audit query — it must return zero rows before going live:

sql
-- Find tables WITHOUT RLS enabled (must return zero rows before launch)
SELECT schemaname, tablename, rowsecurity
FROM pg_tables
WHERE schemaname = 'public' AND rowsecurity = false;

Then ALTER TABLE ... ENABLE ROW LEVEL SECURITY and add per-command policies — full CREATE POLICY patterns in step-commands.md.

  • RLS enabled on every public table (zero rows from audit query above)
  • SELECT, INSERT, UPDATE, DELETE policies defined for each table
  • Policies tested with both authenticated and anonymous roles
  • No tables use USING (true) without intent (public read tables only)
Step 2: Enforce Key Separation — Anon vs Service Role

The anon key is safe for client-side code. The service_role key bypasses RLS entirely and must never leave server-side environments. See the two-client setup in step-commands.md.

  • Anon key used in all client-side code (NEXT_PUBLIC_ prefix)
  • Service role key used only in server-side code (API routes, Edge Functions)
  • Service role key not in any client bundle (verify with grep -r "service_role" dist/)
  • Database password changed from the auto-generated default
Step 3: Configure Connection Pooling (Supavisor)

Supabase uses Supavisor for pooling. Serverless functions (Vercel, Netlify, Cloudflare Workers) MUST use the pooled connection string (port 6543) to avoid exhausting the database connection limit — direct connections (port 5432) are for migrations and admin tasks only. Connection strings and client config in step-commands.md.

  • Application code uses pooled connection string (port 6543)
  • Direct connection reserved for migrations and admin tasks only
  • Connection string in deployment platform env vars (not hardcoded)
  • Verified pool mode: transaction for serverless, session for long-lived connections
Step 4: Enable Database Backups

Supabase provides automatic daily backups on Pro plan. Point-in-time recovery (PITR) enables granular restores.

  • Automatic daily backups enabled (Pro plan — verify in Dashboard > Database > Backups)
  • Point-in-time recovery configured (Dashboard > Database > Backups > PITR)
  • Tested restore procedure on a staging project (do not skip this)
  • Migration files committed to version control (supabase/migrations/ directory)
  • npx supabase db push tested against a fresh project to verify migrations replay cleanly
Step 5: Configure Network Restrictions

Restrict database access to known IP addresses. This prevents unauthorized direct database connections even if credentials leak.

  • IP allowlist configured (Dashboard > Database > Network Restrictions)
  • Only deployment platform IPs and team office IPs are allowed
  • Verified that application still connects after restrictions applied
  • Documented which IPs are allowed and why
Step 6: Configure Custom Domain

A custom domain replaces the default *.supabase.co URLs with your brand domain for API and auth endpoints.

  • Custom domain configured (Dashboard > Settings > Custom Domains)
  • DNS CNAME record added and verified
  • SSL certificate provisioned and active
  • Application code updated to use custom domain URL
  • OAuth redirect URLs updated to use custom domain
Step 7: Customize Auth Email Templates

Default Supabase auth emails show generic branding. Customize them so users see your domain and brand.

  • Confirmation email template customized (Dashboard > Auth > Email Templates)
  • Password reset email template customized
  • Magic link email template customized
  • Invite email template customized
  • Custom SMTP configured (Dashboard > Auth > SMTP Settings) — avoids rate limits and improves deliverability
  • Email confirmation enabled (Dashboard > Auth > Settings)
  • OAuth redirect URLs restricted to production domains only
  • Unused auth providers disabled
Step 8: Understand Rate Limits Per Tier

Supabase enforces rate limits that vary by plan. Hitting these in production causes 429 errors.

ResourceFreeProTeam
API requests500/min1,000/min5,000/min
Auth emails4/hour30/hour100/hour
Realtime connections200 concurrent500 concurrent2,000 concurrent
Edge Function invocations500K/month2M/month5M/month
Storage bandwidth2GB/month250GB/monthCustom
Database size500MB8GB50GB
  • Rate limits documented for your plan tier
  • Client-side retry logic with exponential backoff for 429 responses
  • Auth email rate limits understood (use custom SMTP to increase)
  • Realtime connection limits planned for expected concurrent users
Step 9: Review Monitoring Dashboards

Supabase provides built-in monitoring. Review these before launch to establish baselines, and deploy a health check endpoint (full route handler in step-commands.md).

  • Dashboard > Reports reviewed (API requests, auth, storage, realtime)
  • Dashboard > Logs > API checked for error patterns
  • Dashboard > Database > Performance Advisor reviewed and recommendations applied
  • Health check endpoint deployed and monitored (uptime service)
  • Error tracking configured (Sentry, LogRocket, etc.)
  • Alerts set for: error rate spikes, high latency, connection pool exhaustion
Step 10: Deploy Edge Functions with Proper Env Vars

Edge Functions run on Deno Deploy. Set environment variables via the Supabase CLI or Dashboard, not hardcoded. Secret commands and a webhook function template in step-commands.md.

  • All Edge Functions deployed to production (npx supabase functions deploy)
  • Environment secrets set via npx supabase secrets set (not hardcoded)
  • SUPABASE_URL and SUPABASE_SERVICE_ROLE_KEY available automatically (no need to set)
  • Edge Functions tested with npx supabase functions serve locally before deploying
  • CORS headers configured for Edge Functions that receive browser requests
Show full SKILL.md (629 more words)Show less
Step 11: Verify Storage Bucket Policies

Storage buckets need explicit policies, similar to RLS on tables. Without policies, buckets are inaccessible (default deny). Inspection queries and example policies in step-commands.md.

  • Each bucket has explicit SELECT/INSERT/UPDATE/DELETE policies
  • Public buckets are intentionally public (not accidentally open)
  • File size limits set per bucket (file_size_limit in bucket config)
  • Allowed MIME types restricted per bucket (allowed_mime_types)
  • User upload paths scoped to auth.uid() to prevent overwrites
Step 12: Add Database Indexes on Frequently Queried Columns

Missing indexes are the leading cause of slow queries after launch. Add indexes on foreign keys, filter columns, and sort columns. Diagnostic queries (missing-index, slow-query, table-bloat) and index DDL in step-commands.md.

  • Indexes on all foreign key columns
  • Indexes on columns used in WHERE, ORDER BY, and JOIN clauses
  • pg_stat_statements enabled for ongoing query monitoring
  • Performance Advisor reviewed (Dashboard > Database > Performance)
  • statement_timeout set for authenticated role to prevent runaway queries
  • Table bloat checked — VACUUM if dead tuple percentage > 10%
Step 13: Apply Migrations with npx supabase db push

All schema changes must go through migration files, never manual Dashboard edits in production. Migration commands in step-commands.md.

  • All schema changes in supabase/migrations/ directory (version controlled)
  • npx supabase db push tested against a fresh project
  • Migration history matches between local and remote (npx supabase migration list)
  • Rollback migration prepared for risky schema changes
  • No manual schema edits in production Dashboard
Step 14: Pre-Launch Final Verification

Run the final linked-project verification commands in step-commands.md, then confirm:

  • CORS settings match production domain (Dashboard > API > CORS)
  • Environment variables set correctly in deployment platform
  • Realtime enabled only on tables that need it (reduces connection usage)
  • Webhook endpoints registered and tested
  • Load test completed on staging (see supabase-load-scale)
  • SSL enforcement enabled (Dashboard > Database > Settings > SSL)
  • DNS and custom domain verified end-to-end

Output

  • All 14 checklist sections verified with zero unchecked items
  • RLS enforced on every public table with tested policies
  • Key separation verified (anon client-side, service_role server-side only)
  • Connection pooling via Supavisor (port 6543) for all application code
  • Backups, PITR, monitoring, Edge Functions, Storage policies, indexes all verified
  • Migrations applied cleanly via npx supabase db push

Error Handling

Common go-live failures and their fixes. Full catalog (with HTTP status codes, alert thresholds, and a Supabase error-code switch handler) in references/errors.md.

IssueCauseSolution
403 Forbidden on all API callsRLS enabled but no policies createdAdd SELECT/INSERT/UPDATE/DELETE policies for each role
429 Too Many RequestsPlan rate limit exceededUpgrade plan or implement client-side backoff with retry
Connection timeout under loadUsing direct connection in serverlessSwitch to pooled connection string (port 6543)
Auth emails not deliveredDefault SMTP rate-limitedConfigure custom SMTP provider (SendGrid, Resend, Postmark)
PGRST301 permission deniedService role key used where anon expectedCheck client initialization — use anon key for client-side
Storage upload failsMissing bucket policy or size limit exceededAdd INSERT policy and check file_size_limit on bucket
Slow queries after launchMissing indexes on filter/join columnsRun Performance Advisor and add indexes per Step 12
Migration conflictsManual Dashboard edits diverged from migration filesRun npx supabase db diff to capture drift, then commit

Examples

Lean patterns below; complete, copy-paste versions (Next.js client setup, health check endpoint, full RLS policy set, storage policies, Edge Functions, rollback) in references/examples.md.

RLS Policy Pattern
sql
ALTER TABLE public.posts ENABLE ROW LEVEL SECURITY;
CREATE POLICY "Public read published" ON public.posts
  FOR SELECT USING (status = 'published');
CREATE POLICY "Authors manage own" ON public.posts
  FOR ALL USING (auth.uid() = author_id)
  WITH CHECK (auth.uid() = author_id);
Rollback
bash
npx supabase migration new rollback_bad_change  # Create reversal SQL
npx supabase db push                             # Apply rollback
# For data: Dashboard > Database > Backups > PITR
# For app: vercel rollback / netlify deploy --prod

Resources

Next Steps

  • For SDK version upgrades, see supabase-upgrade-migration
  • For load testing before launch, see supabase-load-scale
  • For monitoring in production, see supabase-monitoring
  • For Edge Function patterns, see supabase-edge-functions

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/.curated/supabase-prod-checklist of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/errors.md
  • references/examples.md
  • references/implementation.md
  • references/step-commands.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Supabase Prod Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supabase Prod Checklist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supabase Prod Checklist this skilljeremylongshore/tons-of-skills-marketplace2.8k—~3.7kAutomated safety check: PassMIT
Postgresql Devsecsickn33/agentic-awesome-skills47k2 repos~2.5kAutomated safety check: NotesMIT
Postgresmagnus919/agent-skills115—~4kAutomated safety check: PassMIT
Stash Deploymentcipherstash/stack157—~6.5kAutomated safety check: PassMIT
Database Backupssickn33/agentic-awesome-skills47k2 repos~3.1kAutomated safety check: NotesMIT
Alloydb Basicsgoogle/skills21k—~1.7kAutomated safety check: PassApache-2.0

Similar skills

  • Postgresql Devsec

    sickn33/agentic-awesome-skills

    Administer PostgreSQL databases. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.5k tokens
    DatabasesAuto-check: notes
  • Postgres

    magnus919/agent-skills

    Operate PostgreSQL instances safely: configuration review, index and query-plan analysis, vacuum and bloat management, WAL archiving and point-in-time recovery, replication and failover, extensions…

    115 GitHub stars~4k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Stash Deployment

    cipherstash/stack

    Deploy a CipherStash encryption rollout to a live environment without losing data — the multi-deploy ladder (schema-add + dual-write → backfill → read cutover → stop dual-writes → drop plaintext)…

    157 GitHub stars~6.5k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Database Backups

    sickn33/agentic-awesome-skills

    Implement database backup strategies. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3.1k tokens
    DatabasesAuto-check: notes
  • Alloydb Basics

    google/skills

    Official

    Manages clusters, instances, and backups for AlloyDB for PostgreSQL, and integrates with AlloyDB Model Context Protocol (MCP) tools for automated database operations.

    21k GitHub stars~1.7k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Alloydb Basics

    davila7/claude-code-templates

    Manages clusters, instances, and backups for AlloyDB for PostgreSQL, and integrates with AlloyDB MCP tools for automated database operations including AI-powered search and vector capabilities.

    33k GitHub stars~611 tokensUpdated yesterday
    DatabasesAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Questions about Supabase Prod Checklist

What does Supabase Prod Checklist do?

Execute a Supabase production deployment checklist covering RLS, key hygiene, connection pooling, backups, monitoring, Edge Functions, and Storage policies. Supabase Prod Checklist is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute a Supabase production deployment checklist covering RLS, key hygiene, connection pooling, backups, monitoring, Edge Functions, and Storage policies.

When should I use Supabase Prod Checklist?

Supabase Prod Checklist fits situations like: deploying to production; preparing for launch; auditing a live Supabase project for security and performance gaps; with supabase production.

How do I install Supabase Prod Checklist in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-prod-checklist -a claude-code`. Or copy the skill folder (skills/.curated/supabase-prod-checklist in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/supabase-prod-checklist in your project. Claude Code loads it when a task matches its description.

How do I install Supabase Prod Checklist in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-prod-checklist -a codex`. Or copy the skill folder (skills/.curated/supabase-prod-checklist in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/supabase-prod-checklist in your project. Codex loads it when a task matches its description.

Can I use Supabase Prod Checklist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-prod-checklist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supabase-prod-checklist, .gemini/skills/supabase-prod-checklist, .github/skills/supabase-prod-checklist and .opencode/skills/supabase-prod-checklist in your project.

What does Supabase Prod Checklist need to run?

Going by SKILL.md and its folder, Supabase Prod Checklist needs the command-line tools its instructions call (npx) and credentials named SUPABASE_SERVICE_ROLE_KEY. Our summary lists: Node.js; A credential in SUPABASE_SERVICE_ROLE_KEY. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(npx supabase:*), Bash(curl:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Supabase Prod Checklist access the network?

SKILL.md names 1 domain. As links in the text: supabase.com. This is read from the text; nothing was executed.

Is Supabase Prod Checklist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Supabase Prod Checklist use?

Supabase Prod Checklist is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supabase Prod Checklist use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.6k tokens, read only when the agent opens those files.

What are the alternatives to Supabase Prod Checklist?

Skills that share tags, products or a category with Supabase Prod Checklist: Postgresql Devsec (sickn33/agentic-awesome-skills, 47k stars), Postgres (magnus919/agent-skills, 115 stars), Stash Deployment (cipherstash/stack, 157 stars) and Database Backups (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supabase Prod Checklist?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.