Supabase Postgres Best Practices

supabase/supabase-postgres-best-practices

SupabaseBridgedsealed Jul 20, 2026

Grouped by public repo namespace. Bridged from skills.sh / SKILL.md sources. Not submitted or endorsed by those companies.

sha256:c4b115fbf70a
FreeLog entrymintedinspectablecapabilitiesdigest-pinnedbridged

85/ 100 · Strong seal

WIP · 2.0-signals

Skill Score is actively being developed and will get sharper over time.

  • Sealed package20/20

    Minted .skill blob in the registry

  • Digest published15/15

    sha256 pin published on skillerr.com

  • Permissions declared15/15

    Capabilities / permissions declared

  • Source attested10/10

    Namespace, submitter, or source URL (not a vendor endorsement)

  • Transparency log0/15

    Log entry recorded at mint (offline verify pending) · https://search.sigstore.dev/?logIndex=2207397361

  • Release profile15/15

    evaluateReleaseProfile passed

  • Registry signal5/5

    5680 install(s) on registry

  • Not revoked5/5

    No revocation on log

Not a malware scan. Not “safe to run.” Transparent registry signals only. Inclusion is not endorsement.

npx @skillerr/add supabase/supabase-postgres-best-practices

Registry pin: sha256:c4b115fbf70a (shown on TrustView; install by name resolves to this sealed blob)

Sealed install targets

Writes supabase-postgres-best-practices.skill (sealed ZIP) plus optional skillerr.json. Not a bare SKILL.md.

Download supabase-postgres-best-practices.skill

Sealed ZIP with digest + skillerr.json. Not a bare SKILL.md.

Free skills install with npx @skillerr/add. Sign in for account history.

Install and download deliver a digest-pinned open .skill package (docs.skillerr.com). Pasting a SKILL.md from the internet has none of this proof.

  • supabase-postgres-best-practices.skill ZIP

    Open-protocol .skill ZIP (skill.json + workflow), not a public raw SKILL.md URL

  • Registry digest pin

    sha256:c4b115fbf70a…

  • Inspect before run

    TrustView on skillerr.com; SKILL.md is a lossy adapter inside the package

  • Permissions surface

    Capabilities declared for review before install

  • Transparency log

    Public Rekor log entry recorded at mint

  • fsFilesystemelevated

    Read or write files in the workspace

Declarations for humans and agents. Not a runtime sandbox guarantee.

Confirm the digest on this page matches the live registry. This checks identity pins only: not a security scan.

expect sha256:c4b115fbf70acf1b
npx @skillerr/add info supabase/supabase-postgres-best-practices
curl -sS https://skillerr.com/api/v1/skills/supabase/supabase-postgres-best-practices | grep -o '"digest":"[^"]*"'

Postgres and Supabase schema, RLS, and query patterns that scale.

Bridged from Supabase's postgres best-practices skill. Covers RLS policies, indexing, migrations, and query shapes that avoid common production pitfalls. Sealed for teams building on Supabase who want a pinned reference skill in agent sessions.

TrustView preview on skillerr.com. Install and download serve the sealed package: there is no public raw SKILL.md URL.

# Supabase Postgres Best Practices

Design schemas, RLS, and queries the Supabase way.

## Focus areas

- Row Level Security policies that match product auth
- Indexes for real query paths
- Safe migrations and rollback habits
- Avoiding N+1 and unbounded selects

## Install

```bash
npx @skillerr/add @supabase/supabase-postgres-best-practices
```

Source: https://github.com/supabase/agent-skills
Public Ledger
Transparency log entry

Recorded at mint to Sigstore Rekor. Offline verify pending on this host. Inclusion is not endorsement.

published_at
2026-03-20T10:00:00.000Z
version
0.1.0
updated_at
2026-07-04T14:00:00.000Z
license
MIT
minted_at
2026-07-20T20:17:45.704Z
permanence
public Rekor log entry (mint receipt)
digest
sha256:c4b115fbf70acf1b696378c8672ff98599b8855a3f75644c84eb0233d78a641f

Public permanence uses Sigstore Rekor. The ledger link is shown when a real logIndex was recorded at mint. Green Anchored requires an offline inclusion proof verify. Catalog claims alone never paint Anchored. Inclusion is not endorsement.