AI Agent Hub
Back to skills
💻

Supabase Platform

Development Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please follow https://skillhub.cn/install/skillhub.md and install @org-02qudk26/supabase-zh.

About this skill

Problem

Supabase CLI commands, function signatures, config.toml settings, API conventions, and RLS behavior change between versions. Engineers or models relying on memory can make two kinds of mistakes: using outdated flows such as apply_migration or unsupported supabase db query patterns, and missing security checks around public RLS, TO authenticated, view SECURITY INVOKER, user_metadata authorization, storage grants, or key exposure.

How It Works

The skill turns Supabase tasks into an explicit workflow:

  • Verify before implementing: check supabase.com/changelog.md and relevant docs, preferring search_docs, .md doc pages, or web search over training-data assumptions about APIs.
  • CLI and MCP troubleshooting: discover commands with supabase --help, fall back to psql or MCP tools when supabase db query and supabase db advisors version requirements are not met, and debug MCP connectivity via reachability, .mcp.json, and OAuth authentication.
  • Schema changes: use declarative supabase/schemas/ or schema_paths when present; otherwise iterate with execute_sql or supabase db query, then run advisors, generate migrations, and verify before commit.
  • Security checklist: when touching Auth, RLS, views, Storage, or user data, review app_metadata, auth.uid(), WITH CHECK, SECURITY DEFINER, Storage INSERT + SELECT + UPDATE, and pinned dependency versions.

Boundaries and Caveats

It fits existing Supabase projects and workflows involving local migrations, Postgres authorization, Auth, Storage, MCP, and CLI operations. It does not replace current version-specific documentation or business implementation; for breaking changes, key management, or sensitive permission policies, still validate against the project environment and review security decisions manually.

Use Cases

  • Add Supabase Auth to a Next.js app, then write RLS policies and avoid unsafe user_metadata authorization.
  • After local Postgres iteration, run advisors, generate migrations, and verify supabase migration list.
  • Debug missing MCP tools by checking curl reachability, .mcp.json, and OAuth login state.
  • Build Storage replacement uploads, then add INSERT, SELECT, and UPDATE grants while reviewing SECURITY DEFINER risks.

Best For

  • Full-stack engineers reviewing Supabase Auth and RLS who need to prevent BOLA or IDOR issues.
  • Platform engineers maintaining Postgres migration flows who need clean migrations after local iteration.
  • AI application engineers integrating Supabase MCP who need to debug missing tools and OAuth login.
  • Backend engineers handling file uploads and permissions who need correct Storage grants and safer functions.