Agent skill

Supabase

by magnus919 in magnus919/agent-skills

A skill your agent uses when developing applications with Supabase, running the Supabase CLI, designing migrations and RLS policies, testing database behavior, generating client types, deploying the…

MITAuto-check passedDevOps & Cloud

Install Supabase

skills CLI
$ npx skills add magnus919/agent-skills --skill supabase -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install magnus919/agent-skills supabase --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/supabase .claude/skills/supabase && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supabase
GitHub stars
116
Token cost
~2.2k tokens
SKILL.md length
895 words
Files
12 (incl. references)
Skills in repo
130
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when developing applications with Supabase, running the Supabase CLI, designing migrations and RLS policies, testing database behavior, generating client types, deploying the…

  • Works in 6 steps: Discover the target and current state… → Confirm target, scope, and rollback path… → Keep publishable keys client-side and… → …
  • Developing applications with Supabase
  • SKILL.md covers Operating contract, Choose the path, First read-only discovery and Development loop, plus 4 more sections
  • Calls supabase, docker and sh

What it does

Supabase is an agent skill from magnus919/agent-skills. Use this skill when developing applications with Supabase, running the Supabase CLI, designing migrations and RLS policies, testing database behavior, generating client types, deploying the official self-hosted Docker stack, or administering its Postgres, Auth, Storage, Realtime, Functions, API gateway, backups, upgrades, and security. Use it for managed and self-hosted projects. Do not use for generic PostgreSQL work with no Supabase services or conventions.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including reference files (for example `README.md`, `evals/evals.json` and `references/administration-and-recovery.md`). Compatibility notes: Requires network access for documentation lookup. Local development requires the Supabase CLI and a Docker-compatible runtime; self-hosting requires Linux…

It sits in DevOps & Cloud, covering Backup and disaster recovery, Microservices and Containers. It works with Supabase, PostgreSQL and Docker. The repository describes itself as: Curated collection of AI agent skills for Hermes and other agent frameworks. The licence is MIT.

When your agent uses it

  • Developing applications with Supabase
  • Running the Supabase CLI
  • Designing migrations and RLS policies
  • Testing database behavior

Example prompts

  • “/supabase”

Requirements

  • Docker
  • Compatibility (from SKILL.md): Requires network access for documentation lookup. Local development requires the Supabase CLI and a Docker-compatible runtime; self-hosting requires Linux, Git, Docker Engine, and Docker Compose.

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Discover the target and current state before changing it: managed project, CLI local stack, or self-hosted Compose; CLI and service…
  2. Confirm target, scope, and rollback path before the first mutation. Read-only discovery may proceed without confirmation. An explicit user…
  3. Keep publishable keys client-side and secret/service-role keys server-side only. Never print, commit, or place secret keys, database…
  4. Make database changes through versioned migrations. Review generated diffs as drafts, replay the full chain, test RLS negative cases, and…
  5. For self-hosting, use the official supabase/supabase Docker directory and its setup.sh, run.sh, update notes, and tests. Do not invent a…
  6. Verify at the delivery boundary: container health is not API health; an API response is not authorization proof; a backup is not recovery…

What it can do on your machine

Read from SKILL.md and the folder at commit c545c2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • supabase
    • docker
    • sh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use supabase and docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires network access for documentation lookup. Local development requires the Supabase CLI and a Docker-compatible runtime; self-hosting requires Linux, Git, Docker Engine, and Docker Compose.

    From compatibility in the SKILL.md frontmatter.

Context cost

Supabase loads about 2.2k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 118 tokens; SKILL.md has 895 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~118
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~17k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from magnus919/agent-skills at commit c545c2b, republished under its MIT licence (© magnus919). 895 words, ~2,183 tokens.

Download SKILL.mdSave it as .claude/skills/supabase/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.
name
supabase
description
Use this skill when developing applications with Supabase, running the Supabase CLI, designing migrations and RLS policies, testing database behavior, generating client types, deploying the official self-hosted Docker stack, or administering its Postgres, Auth, Storage, Realtime, Functions, API gateway, backups, upgrades, and security. Use it for managed and self-hosted projects. Do not use for generic PostgreSQL work with no Supabase services or conventions.
compatibility
Requires network access for documentation lookup. Local development requires the Supabase CLI and a Docker-compatible runtime; self-hosting requires Linux, Git, Docker Engine, and Docker Compose.
license
MIT
metadata.source
https://supabase.com/docs
metadata.research_checked
2026-07-16

Supabase

Treat Supabase as a Postgres-centered system with multiple independently versioned services, not as one opaque backend. The managed platform, CLI local stack, and official self-hosted Compose stack share concepts but are different operating environments. Identify which one the task targets before choosing commands.

Operating contract

  1. Discover the target and current state before changing it: managed project, CLI local stack, or self-hosted Compose; CLI and service versions; project link; database and migration state; enabled services; public URLs; backup and rollback path.
  2. Confirm target, scope, and rollback path before the first mutation. Read-only discovery may proceed without confirmation. An explicit user directive to deploy or change the named target satisfies this gate.
  3. Keep publishable keys client-side and secret/service-role keys server-side only. Never print, commit, or place secret keys, database passwords, JWT signing material, SMTP credentials, or connection strings containing passwords in reports.
  4. Make database changes through versioned migrations. Review generated diffs as drafts, replay the full chain, test RLS negative cases, and regenerate client types before deployment.
  5. For self-hosting, use the official supabase/supabase Docker directory and its setup.sh, run.sh, update notes, and tests. Do not invent a reduced Compose stack unless the user explicitly wants one and accepts the lost capabilities.
  6. Verify at the delivery boundary: container health is not API health; an API response is not authorization proof; a backup is not recovery evidence.

Choose the path

NeedRead first
Understand services, trust boundaries, keys, and environment differencesarchitecture and boundaries
Install/use the CLI, establish a local workflow, or operate managed Functions, secrets, branches, SSL enforcement, CIDR restrictions, and network banslocal development and CLI
Create schemas, migrations, seed data, RLS policies, tests, and generated typesdatabase development and testing
Build with Auth, REST, Realtime, Storage, and Edge Functionsapplication services
Deploy or harden the official Docker stackself-hosting deployment
Back up, restore, update, upgrade, monitor, or recover a self-hosted instanceadministration and recovery
Diagnose unhealthy containers, bad URLs, auth failures, drift, or migration failurestroubleshooting
Evaluate how well an agent can use Supabase with scored scenariosagent evals harness
Check claim currency or authoritative source coveragesource index

First read-only discovery

sh
supabase --version
supabase status --output json       # CLI local project; may fail when stopped
supabase migration list            # linked/local migration comparison when configured
docker compose config --quiet       # self-hosted project directory
docker compose ps --format json

For a managed project, also establish the project reference, linked status, target environment, and whether direct production changes have created drift. For self-hosting, inspect docker/CHANGELOG.md, docker/versions.md, the active COMPOSE_FILE, disk/memory headroom, and backup evidence before updates.

Development loop

Use one schema-authoring mode per project:

sh
# Declarative: edit supabase/schemas/*.sql first
supabase db diff -f change-name

# Imperative: write the generated migration directly
supabase migration new change-name

# Both paths converge on the same checks
supabase db reset
supabase test db
supabase gen types --lang typescript --local > database.types.ts

Review every generated migration. db diff does not capture DML and has known gaps around policy renames, views, and some privileges. db reset is destructive to the local database but is the reproducibility proof: migrations in order, then seed data.

Before a linked deployment:

sh
supabase migration list
supabase db push --dry-run
supabase db push

Never use db reset --linked or db push --include-seed against production. Pass --local or --linked explicitly when ambiguity could hit the wrong database; command defaults differ.

Self-hosted lifecycle

Use the checked-in official helper scripts from the deployment directory:

sh
sh run.sh config
sh run.sh compose-config >/dev/null
docker compose config --quiet
sh run.sh start
sh run.sh status
sh tests/test-self-hosted.sh http://localhost:8000

Production requires real secrets, correct external URLs, TLS termination, WebSocket forwarding, protected database ports, SMTP/provider configuration as needed, backups, and restore tests. The official default stack exposes Kong on 8000, Kong TLS on 8443, and Supavisor on 5432/6543; bind or firewall them deliberately.

Show full SKILL.md (368 more words)Show less

Verification matrix

LayerMinimum evidence
Configurationdocker compose config --quiet; no placeholder secrets; URLs agree with proxy/auth callbacks
RuntimeEvery required service is running and healthy; bounded logs show no current failure loop
DatabaseExpected Postgres version; migration history matches; representative query succeeds
API gatewayStudio auth boundary, Auth health, REST with correct key role, JWKS endpoint
AuthorizationPositive and negative RLS tests as anon/authenticated users; service-role bypass never used as proof
StorageBucket/object upload, download, integrity, signed URL, and cleanup
RealtimeWebSocket subscription and database-change delivery, not just an HTTP route
FunctionsInvoke a real function through /functions/v1; verify auth behavior and logs
RecoveryIndependent logical/physical backup plus restore into a separate test target

Hard boundaries and gotchas

  • The CLI local stack is development-only: default credentials, no TLS, and no production rate limiting. Do not expose it publicly.
  • RLS must be enabled on every table in an exposed schema. A publishable key is safe in a client only when grants and RLS policies are correct. Test denial paths.
  • Secret/service-role keys bypass RLS. They never belong in browser bundles, mobile apps, logs, examples, or chat output.
  • API_EXTERNAL_URL includes /auth/v1 in the current self-hosted configuration. SITE_URL is the application landing URL, not necessarily the Supabase hostname.
  • Update the Compose configuration as a tested release set. Pulling arbitrary latest images independently can create incompatible service combinations.
  • Postgres 17 is the current default for new self-hosted deployments. Never point it at a Postgres 15 data directory. Preserve both database data and the db-config volume containing the pgsodium root key.
  • docker compose down -v, reset.sh, remote reset, key regeneration, and migration-history repair can destroy data, access, or sessions. Treat them as separate confirmed operations with recovery evidence.
  • Self-hosted feature parity is not managed-platform parity. Backups, availability, upgrades, abuse controls, SMTP, observability, and support are operator responsibilities.

Exit criteria

The task is complete only when the requested artifact or state exists and the relevant boundary has been exercised: a local project replays from migrations and passes tests; a deployment passes configuration, health, and service-level smoke tests; an update has rollback evidence and post-update checks; a backup has been restored into a separate target; and no secret material appears in committed or reported output.

© magnus919, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 11 other files (references) in supabase of magnus919/agent-skills.

  • SKILL.md
  • README.md
  • evals/evals.json
  • references/administration-and-recovery.md
  • references/agent-evals.md
  • references/application-services.md
  • references/architecture-and-boundaries.md
  • references/database-development-and-testing.md
  • references/local-development-and-cli.md
  • references/self-hosting-deployment.md
  • references/source-index.md
  • references/troubleshooting.md

Open the folder on GitHubat commit c545c2b

Compare with similar skills

Supabase next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supabase compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supabase this skillmagnus919/agent-skills116—~2.2kAutomated safety check: PassMIT
Mg Local DB Restoremodelguide/modelguide108—~645Automated safety check: PassMIT
Postgres Adoptgarrytan/gbrain31k—~2.1kAutomated safety check: PassMIT
Postgres Backup Restorefmflurry/settings-opencode171—~2.3kAutomated safety check: PassMIT
Dr Jskilljdubois/dr-jskill342—~4.6kAutomated safety check: NotesApache-2.0
Monstermq Broker Configvogler75/monster-mq143—~2.2kAutomated safety check: PassGPL-3.0

Similar skills

  • Mg Local DB Restore

    modelguide/modelguide

    Trigger phrases - "reset local db", "recreate local postgres", "restore dump to local", "reset local database", "load backup locally"

    108 GitHub stars~645 tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Postgres Adopt

    garrytan/gbrain

    Detect which gbrain engine is in use (PGLite vs Postgres), prefer Postgres for agent-harness installs, install/provision Postgres (Supabase discovery via SUPABASEACCESSTOKEN, local Postgres, opt-in…

    31k GitHub stars~2.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Postgres Backup Restore

    fmflurry/settings-opencode

    PostgreSQL backup & restore playbook for the docker instance: pgdump/pgdumpall recipes, WAL archiving + PITR setup (archivemode, archivecommand, recovery.signal, recoverytargettime, timelines)…

    171 GitHub stars~2.3k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Dr Jskill

    jdubois/dr-jskill

    Creates Java + Spring Boot projects: Web applications, full-stack apps with Vue.js or Angular or React or vanilla JS, PostgreSQL, REST APIs, and Docker.

    342 GitHub stars~4.6k tokensUpdated 10 days ago
    Backend & APIsAuto-check: notes
  • Monstermq Broker Config

    vogler75/monster-mq

    Guide for configuring, deploying, and operating the MonsterMQ broker.

    143 GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Code Patterns

    Aedelon/claude-code-blueprint

    Reference patterns for REST APIs, pytest/vitest testing, Docker multi-stage builds, GitHub Actions CI/CD, PostgreSQL, TypeScript generics, Python async, and React Server Components.

    120 GitHub stars~1.2k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed

More from magnus919/agent-skills

All 130 skills in this repo
  • Artifact Pyramids

    magnus919/agent-skills

    Organize durable agent research outputs as summaries, analysis, and evidence dossiers.

    116 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Ascii City Engine

    magnus919/agent-skills

    Build portable, first-person colored ASCII city engines and small GIS-derived city packs.

    116 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Color Management

    magnus919/agent-skills

    Manage color workflows with ICC profiles, working spaces, gamut mapping, and color science.

    116 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check: notes
  • Data Scientist

    magnus919/agent-skills

    A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…

    116 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • Docker Compose

    magnus919/agent-skills

    Use Docker Compose to define, run, debug, and harden multi-container applications.

    116 GitHub stars~2k tokensUpdated yesterday
    Auto-check: notes
  • Fpga Development

    magnus919/agent-skills

    Design, review, simulate, and verify FPGA logic using explicit RTL contracts, clock and reset models, CDC analysis, timing constraints, and reproducible implementation evidence.

    116 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed

Questions about Supabase

What does Supabase do?

A skill your agent uses when developing applications with Supabase, running the Supabase CLI, designing migrations and RLS policies, testing database behavior, generating client types, deploying the…. Supabase is an agent skill from magnus919/agent-skills. Use this skill when developing applications with Supabase, running the Supabase CLI, designing migrations and RLS policies, testing database behavior, generating client types, deploying the official self-hosted Docker stack, or administering its Postgres, Auth, Storage, Realtime, Functions, API gateway, backups, upgrades, and security.

When should I use Supabase?

Supabase fits situations like: developing applications with Supabase; running the Supabase CLI; designing migrations and RLS policies; testing database behavior.

How do I install Supabase in Claude Code?

Run `npx skills add magnus919/agent-skills --skill supabase -a claude-code`. Or copy the skill folder (supabase in magnus919/agent-skills) into .claude/skills/supabase in your project. Claude Code loads it when a task matches its description.

How do I install Supabase in Codex?

Run `npx skills add magnus919/agent-skills --skill supabase -a codex`. Or copy the skill folder (supabase in magnus919/agent-skills) into .agents/skills/supabase in your project. Codex loads it when a task matches its description.

Can I use Supabase in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add magnus919/agent-skills --skill supabase -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supabase, .gemini/skills/supabase, .github/skills/supabase and .opencode/skills/supabase in your project.

What does Supabase need to run?

Going by SKILL.md and its folder, Supabase needs the command-line tools its instructions call (supabase, docker and sh). Our summary lists: Docker. Compatibility (from SKILL.md): Requires network access for documentation lookup. Local development requires the Supabase CLI and a Docker-compatible runtime; self-hosting requires Linux, Git, Docker Engine, and Docker Compose..

Does Supabase access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Supabase safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Supabase use?

Supabase is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supabase use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.

What are the alternatives to Supabase?

Skills that share tags, products or a category with Supabase: Mg Local DB Restore (modelguide/modelguide, 108 stars), Postgres Adopt (garrytan/gbrain, 31k stars), Postgres Backup Restore (fmflurry/settings-opencode, 171 stars) and Dr Jskill (jdubois/dr-jskill, 342 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supabase?

magnus919 (a GitHub user) maintains it in magnus919/agent-skills, which has 116 GitHub stars. The repository holds 130 skills in this directory. The repository was last updated on October 8, 2026.

Source: magnus919/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.