Agent skill

Pocketbase

by pockethost in pockethost/pockethost

Models PocketBase backends: collections, relations, auth, API rules, migrations, and architecture.

MITAuto-check passedDatabases

Install Pocketbase

skills CLI
$ npx skills add pockethost/pockethost --skill pocketbase -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pockethost/pockethost pocketbase --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pockethost/pockethost.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/pocketbase .claude/skills/pocketbase && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pocketbase
GitHub stars
1.4k
Token cost
~1k tokens
SKILL.md length
403 words
Files
2
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Models PocketBase backends: collections, relations, auth, API rules, migrations, and architecture.

  • Works in 2 steps: Add a custom route or record hook in… → Call it from the client via pb.send()…
  • Designing schema
  • SKILL.md covers Which skill to use, Core concepts, Architecture decisions and PocketHost context, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Pocketbase is an agent skill from pockethost/pockethost. Models PocketBase backends: collections, relations, auth, API rules, migrations, and architecture. Use when designing schema, security rules, data modeling, choosing between hooks vs client access, or explaining PocketBase platform concepts — not for npm JS SDK code or pbhooks.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `pockethost-hosting.md`).

It sits in Databases, covering Database schema design. It works with npm. The repository describes itself as: Open source multitenant PocketBase server. The licence is MIT.

When your agent uses it

  • Designing schema
  • Choosing between hooks vs client access
  • Explaining PocketBase platform concepts — not for npm JS SDK code

Example prompts

  • “Use the pocketbase skill to model PocketBase backends: collections, relations, auth, API rules, migrations, and architecture”
  • “/pocketbase”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Add a custom route or record hook in pb_hooks/ (pocketbase-jsvm)
  2. Call it from the client via pb.send() (pocketbase-js-sdk)

What it can do on your machine

Read from SKILL.md and the folder at commit 82c9ba3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • pocketbase.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pocketbase loads about 1k tokens when it runs. Until then it costs about 73 tokens; SKILL.md has 403 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~73
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pockethost/pockethost at commit 82c9ba3, republished under its MIT licence (© pockethost). 403 words, ~1,002 tokens.

Download SKILL.mdSave it as .claude/skills/pocketbase/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
pocketbase
description
Models PocketBase backends: collections, relations, auth, API rules, migrations, and architecture. Use when designing schema, security rules, data modeling, choosing between hooks vs client access, or explaining PocketBase platform concepts — not for npm JS SDK code or pb_hooks.

PocketBase Platform

PocketBase is a single-binary backend: SQLite database, REST + realtime API, auth, file storage, and admin UI.

Official docs: https://pocketbase.io/docs/

Which skill to use

TaskSkill
Design collections, rules, authpocketbase (this skill)
Browser/Node app calling PocketBase over HTTPpocketbase-js-sdk
Server-side hooks in pb_hooks/*.pb.jspocketbase-jsvm
Superuser admin UI extensions (PB ≥0.37)pocketbase-admin-plugins

Core concepts

Collections and records
  • Collections are tables; records are rows.
  • Field types: text, number, bool, email, url, date, select, relation, file, json, etc.
  • Relations link collections; use expand in API queries to include related records.
  • Indexes improve filter/sort performance on large collections.
Auth
  • Auth collections (e.g. users) support registration, login, OAuth2, OTP.
  • Superusers are admin accounts (_superusers); regular auth records live in auth collections.
  • JWT tokens identify authenticated requests; API rules reference @request.auth.
API rules (security)

Rules control list/view/create/update/delete per collection. Write rules as filter expressions:

@request.auth.id != "" && @request.auth.id = user.id
  • Prefer API rules over middleware for access control.
  • @request.auth — current authenticated record (or null).
  • @collection.* — cross-collection lookups in rules.
  • Empty rule = locked; @request.auth.id != "" = any authenticated user.
Migrations

Two migration systems:

TypeLocationLanguageUse for
Go migrationspb_migrations/Go (compiled into binary)Core schema shipped with PocketBase
JS migrationspb_migrations/*.jsJSVM (sync)User/instance schema changes via FTP

JS migrations run in the JSVM — see pocketbase-jsvm for constraints.

Realtime
  • Clients subscribe to collection or record changes via the SDK.
  • Subscription access is governed by the same API rules as list/view.
Files
  • File fields store uploads in pb_data/storage/.
  • Public static assets can be served from pb_public/.
Show full SKILL.md (159 more words)Show less

Architecture decisions

Prefer direct client access

PocketBase is designed for client → PocketBase communication with API rules enforcing security.

Avoid wrapping PocketBase in SvelteKit/Next.js server routes unless necessary:

  • Adds double network hops and latency
  • Complicates JWT/cookie state
  • Concentrates traffic on one IP (rate limits)
Prefer JS hooks for privileged server logic

When clients need elevated operations (payments, external APIs, admin-only mutations):

  1. Add a custom route or record hook in pb_hooks/ (pocketbase-jsvm)
  2. Call it from the client via pb.send() (pocketbase-js-sdk)

Do not instantiate the JS SDK inside hooks to call the same server — use $app APIs directly.

When server-side SDK access is OK
  • CLI tools, admin scripts, mothership internal services
  • Aggregations that cannot be expressed in rules or hooks
  • Integrations that must stay off the client

PocketHost context

This monorepo is the PocketHost platform. For hosting-specific details (FTP dirs, instance URLs, limits), see pockethost-hosting.md.

© pockethost, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .cursor/skills/pocketbase of pockethost/pockethost.

  • SKILL.md
  • pockethost-hosting.md

Open the folder on GitHubat commit 82c9ba3

Compare with similar skills

Pocketbase next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pocketbase compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pocketbase this skillpockethost/pockethost1.4k—~1kAutomated safety check: PassMIT
Mail Timeveliovgroup/mail-time143—~1kAutomated safety check: PassBSD-3-Clause
BackendAlexPEClub/ai-coding-starter-kit383—~992Automated safety check: PassNone
Postgres Migrationspr-pm/prpm1221 repos~3.1kAutomated safety check: PassMIT
Subgraph Development Guidenirholas/three.ws226—~2.1kAutomated safety check: PassMIT
Saleor Django Migration Rulessaleor/saleor23k—~1.6kAutomated safety check: PassBSD-3-Clause

Similar skills

  • Mail Time

    veliovgroup/mail-time

    A skill your agent uses when building, wiring, reviewing, or debugging MailTime and ostrio:mailer email queues for horizontally scaled Node.js, Bun, or Meteor apps.

    143 GitHub stars~1k tokensUpdated 6 days ago
    DatabasesAuto-check passed
  • Backend

    AlexPEClub/ai-coding-starter-kit

    Build APIs, database schemas, and server-side logic with Supabase.

    383 GitHub stars~992 tokensUpdated 4 mo ago
    DatabasesAuto-check passed
  • Comprehensive guide to PostgreSQL migrations - common errors, generated columns, full-text search, indexes, idempotent migrations, and best practices for database schema changes

    122 GitHub starsUsed in 1 repo~3.1k tokens
    DatabasesAuto-check passed
  • Guide to building blockchain data indexes with The Graph — subgraph architecture, schema design, mapping handlers, deployment, and querying.

    226 GitHub stars~2.1k tokensUpdated today
    DatabasesAuto-check passed
  • Rules for writing Django migrations in Saleor that avoid long table locks and stay compatible with zero-downtime rolling deploys.

    23k GitHub stars~1.6k tokensUpdated yesterday
    DatabasesAuto-check passed
  • SQL Optimization Patterns

    ynulihao/AgentSkillOS

    Master SQL query optimization, indexing strategies, and EXPLAIN analysis to dramatically improve database performance and eliminate slow queries.

    617 GitHub starsUsed in 10 repos~3.3k tokens
    DatabasesAuto-check passed

More from pockethost/pockethost

All 11 skills in this repo
  • Blog Voice

    pockethost/pockethost

    Write PocketHost blog posts in Ben Allfree's voice (@cap'n).

    1.4k GitHub stars~977 tokensUpdated 9 days ago
    Auto-check passed
  • Check Push

    pockethost/pockethost

    Run pnpm check:push (lint, types, tests) before git push or PR-ready work.

    1.4k GitHub stars~665 tokensUpdated 9 days ago
    Auto-check passed
  • Commit

    pockethost/pockethost

    Create scoped git commits from the current conversation (e.g.

    1.4k GitHub stars~1.3k tokensUpdated 9 days ago
    Auto-check: notes
  • Feature Blog

    pockethost/pockethost

    Ship user-facing PocketHost features with a blog post instead of semver release notes.

    1.4k GitHub stars~818 tokensUpdated 9 days ago
    Auto-check passed
  • Lemon Squeezy Integration

    pockethost/pockethost

    Full Lemon Squeezy integration — REST API, @lemonsqueezy/lemonsqueezy.js server SDK, Lemon.js checkout overlays, webhooks, customdata, and subscriptions.

    1.4k GitHub stars~1.1k tokensUpdated 9 days ago
    Auto-check passed
  • Pocketbase Admin Plugins

    pockethost/pockethost

    Builds PocketBase superuser admin UI extensions (admin plugins) on PB ≥0.37: ServeEvent.uiExtensions, client main.js, window.app SPA hooks, Shablon UI, reactive stores, CSP, SSE/realtime topics.

    1.4k GitHub stars~1.8k tokensUpdated 9 days ago
    Auto-check passed

Works with

Questions about Pocketbase

What does Pocketbase do?

Models PocketBase backends: collections, relations, auth, API rules, migrations, and architecture. Pocketbase is an agent skill from pockethost/pockethost. Models PocketBase backends: collections, relations, auth, API rules, migrations, and architecture.

When should I use Pocketbase?

Pocketbase fits situations like: designing schema; choosing between hooks vs client access; explaining PocketBase platform concepts — not for npm JS SDK code.

How do I install Pocketbase in Claude Code?

Run `npx skills add pockethost/pockethost --skill pocketbase -a claude-code`. Or copy the skill folder (.cursor/skills/pocketbase in pockethost/pockethost) into .claude/skills/pocketbase in your project. Claude Code loads it when a task matches its description.

How do I install Pocketbase in Codex?

Run `npx skills add pockethost/pockethost --skill pocketbase -a codex`. Or copy the skill folder (.cursor/skills/pocketbase in pockethost/pockethost) into .agents/skills/pocketbase in your project. Codex loads it when a task matches its description.

Can I use Pocketbase in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pockethost/pockethost --skill pocketbase -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pocketbase, .gemini/skills/pocketbase, .github/skills/pocketbase and .opencode/skills/pocketbase in your project.

What does Pocketbase need to run?

SKILL.md names no scripts, command-line tools or credentials: Pocketbase is instructions for the agent only.

Does Pocketbase access the network?

SKILL.md names 1 domain. As links in the text: pocketbase.io. This is read from the text; nothing was executed.

Is Pocketbase safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Pocketbase use?

Pocketbase is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pocketbase use?

About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pocketbase?

Skills that share tags, products or a category with Pocketbase: Mail Time (veliovgroup/mail-time, 143 stars), Backend (AlexPEClub/ai-coding-starter-kit, 383 stars), Postgres Migrations (pr-pm/prpm, 122 stars) and Subgraph Development Guide (nirholas/three.ws, 226 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pocketbase?

pockethost (a GitHub organization) maintains it in pockethost/pockethost, which has 1,444 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on September 28, 2026.

Source: pockethost/pockethost on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.