Supabase Agent Skills
Expert Postgres optimization and Supabase development guidance for modern apps
What You Can Do
Leverage Supabase-maintained best practices to optimize Postgres queries, design secure schemas, and configure Row-Level Security (RLS) policies. Debug performance issues with EXPLAIN plan analysis and connection pooling diagnostics. Navigate Supabase-specific patterns for auth, Edge Functions, Storage, and real-time integrations. Implement advanced features like pgvector semantic search and pg_cron scheduled jobs with confidence and security.
Features
Comprehensive strategies for indexes, EXPLAIN plan analysis, query tuning, and identifying performance bottlenecks with measurable metrics
Secure RLS policy patterns, authorization best practices, BOLA/IDOR prevention, and security audit checklists for multi-tenant applications
Best practices for table design, column type selection, safe schema alterations, declarative schemas, and production migration patterns
Connection pooling configuration with pgbouncer, session lifecycle management, connection exhaustion prevention, and serverless optimization
Tools and techniques to diagnose slow queries, high CPU usage, lock contention, and connection pool issues with actionable solutions
Auth (JWT security, session management), Edge Functions, Storage access control, real-time subscriptions, and client-side integration
pgvector for semantic search, pg_cron for scheduled jobs, custom triggers, database functions, and queue systems like pgmq
JWT token safety, API key management, SECURITY DEFINER pitfalls, storage permissions, and supply-chain security for Supabase packages
Example Output
Optimize slow product query
Help me optimize this slow product search query:
SELECT * FROM products WHERE category = 'electronics' AND price > 100 AND created_at > now() - interval '30 days';
This takes 2 seconds. What indexes should I create? Show me the EXPLAIN plans before and after.
The skill identified missing composite indexes on (category, created_at), provided CREATE INDEX statements, and demonstrated EXPLAIN output showing query time reduced from 1800ms to 32ms.
Audit RLS policies for authorization vulnerabilities
Review this RLS policy for authorization flaws:
create policy "users_see_own_profile" on profiles for select using (auth.uid() = user_id);
Does this cover UPDATE? Could users reassign another user's profile?
The skill detected the missing WITH CHECK clause on UPDATE, which would allow user_id reassignment exploits, and provided the corrected policy with both USING and WITH CHECK to prevent privilege escalation.
Resolve connection pool exhaustion
My Supabase app keeps getting 'too many connections' errors. How do I configure pgbouncer for session-mode pooling? Show me the configuration steps.
The skill provided pgbouncer session-mode configuration, identified unclosed connections in the Node.js application code, and reduced peak connections from 120 to 8 for serverless functions.
What's Included
- Query Performance Rules: 8 prioritized rules covering indexes, query plans, partial indexes, join optimization, and performance metrics with SQL examples
- Security and RLS Reference: Policy patterns, authorization validation, BOLA/IDOR prevention, and Supabase security checklist (JWT, API keys, SECURITY DEFINER risks)
- Schema Design Principles: Column type selection, constraint best practices, naming conventions, and migration strategies for production Postgres
- Connection Management Guide: pgbouncer configuration examples, session vs transaction pooling modes, and serverless function optimization patterns
- Supabase Integration Documentation: Auth patterns (JWT, session lifecycle), Edge Functions setup, Storage permissions, RLS in exposed schemas, and data API configuration
- Performance Monitoring Toolkit: EXPLAIN analysis templates, slow query identification procedures, and diagnostic scripts for production troubleshooting
Who It's For
- Backend Engineers
- DevOps and Infrastructure Engineers
- Security Engineers
- Full-Stack Developers
- Database Administrators
Best For
- Postgres query optimization
- Row-Level Security implementation
- Schema design and migrations
- Performance troubleshooting
- Supabase project setup
