Supabase Platform
Paste the following prompt into your AI chat to install this skill:
Please follow https://skillhub.cn/install/skillhub.md and install @org-02qudk26/supabase-zh.
About this skill
Problem
Supabase CLI commands, function signatures, config.toml settings, API conventions, and RLS behavior change between versions. Engineers or models relying on memory can make two kinds of mistakes: using outdated flows such as apply_migration or unsupported supabase db query patterns, and missing security checks around public RLS, TO authenticated, view SECURITY INVOKER, user_metadata authorization, storage grants, or key exposure.
How It Works
The skill turns Supabase tasks into an explicit workflow:
- Verify before implementing: check
supabase.com/changelog.mdand relevant docs, preferringsearch_docs,.mddoc pages, or web search over training-data assumptions about APIs. - CLI and MCP troubleshooting: discover commands with
supabase --help, fall back topsqlor MCP tools whensupabase db queryandsupabase db advisorsversion requirements are not met, and debug MCP connectivity via reachability,.mcp.json, and OAuth authentication. - Schema changes: use declarative
supabase/schemas/orschema_pathswhen present; otherwise iterate withexecute_sqlorsupabase db query, then run advisors, generate migrations, and verify before commit. - Security checklist: when touching Auth, RLS, views, Storage, or user data, review
app_metadata,auth.uid(),WITH CHECK,SECURITY DEFINER, StorageINSERT + SELECT + UPDATE, and pinned dependency versions.
Boundaries and Caveats
It fits existing Supabase projects and workflows involving local migrations, Postgres authorization, Auth, Storage, MCP, and CLI operations. It does not replace current version-specific documentation or business implementation; for breaking changes, key management, or sensitive permission policies, still validate against the project environment and review security decisions manually.
Use Cases
- Add Supabase Auth to a Next.js app, then write RLS policies and avoid unsafe user_metadata authorization.
- After local Postgres iteration, run advisors, generate migrations, and verify supabase migration list.
- Debug missing MCP tools by checking curl reachability, .mcp.json, and OAuth login state.
- Build Storage replacement uploads, then add INSERT, SELECT, and UPDATE grants while reviewing SECURITY DEFINER risks.
Best For
- Full-stack engineers reviewing Supabase Auth and RLS who need to prevent BOLA or IDOR issues.
- Platform engineers maintaining Postgres migration flows who need clean migrations after local iteration.
- AI application engineers integrating Supabase MCP who need to debug missing tools and OAuth login.
- Backend engineers handling file uploads and permissions who need correct Storage grants and safer functions.
Related Skills
Analyzes code to extract control and data flow, then outputs Markdown with Mermaid source and high-resolution PNG diagrams.
For development and programming scenarios around VSCode and TypeScript IDE.
A TypeScript-oriented Windmill Wrap development reference.
A Python-based Selenium wrapper for engineering browser automation workflows.