CtrlK
BlogDocsLog inGet started
Tessl Logo

supabase-api

Supabase JavaScript client API and REST API usage. Use when integrating Supabase, setting up clients, or using REST endpoints directly.

60

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/supabase-api/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, lean reference — nearly every line is executable copy-paste code with no concept padding. Its structural weaknesses are the missing validate/retry guidance around destructive database operations and the inlining of ~350 lines of API detail in SKILL.md when the bundle already demonstrates a references/ pattern that could carry it.

Suggestions

Add a validation pattern to destructive operations: show checking the returned row via 'Prefer: return=representation' on DELETE/PATCH to confirm the targeted row actually existed, or a verify-then-retry loop alongside the existing error-codes table.

Move the Auth, Storage, Realtime, and TypeScript sections out of SKILL.md into references/ files (e.g. references/auth.md, references/storage.md) and keep a one-line well-signaled pointer per section in the body, mirroring the existing client-patterns.md link.

Drop one of the two pagination demonstrations (query params vs Range header) or note when each is preferable, to remove the duplicated coverage.

DimensionReasoningScore

Conciseness

The body is almost entirely executable code blocks and tables with no concept explanations — it assumes Claude's competence and never pads with prose like 'Supabase is a platform that...'. Minor trims are possible (pagination is demonstrated twice via query params and the Range header, and the JS quick reference partially re-covers ground Claude already knows), which keeps it at anchor 4 rather than the 'every token earns its place' anchor 5.

4 / 5

Actionability

Everything is copy-paste ready: install command, four complete createClient variants, curl commands with exact headers for every REST CRUD operation, executable auth/storage/realtime/edge-function snippets, a filter-operator table with concrete query examples, and an error-codes table. This matches 'Fully executable; copy-paste ready code or commands; specific examples cover the common cases'.

5 / 5

Workflow Clarity

This is a reference skill with no multi-step workflows, and an Error Handling section with an `if (error)` pattern and a codes table gives some recovery guidance. However, the destructive and database operations (DELETE, upsert with merge-duplicates, PATCH) include no validation or verify-then-retry loop — no guidance to check the row exists, use return=representation to confirm the affected row, or handle partial failures — so per the rubric's cap for database operations without feedback loops, workflow clarity cannot exceed 3.

3 / 5

Progressive Disclosure

The one bundle file (references/client-patterns.md, verified present) is real, one level deep, and clearly signaled via a '## References' section with a descriptive label. But the body itself is 352 lines of inlined API reference — auth, storage, realtime, filter operators, and type helpers are detail that belongs in reference files while SKILL.md stays an overview. This matches 'content that should be separate is inline' at anchor 3; the good section headers keep it from scoring 2.

3 / 5

Total

15

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid, third-person description with an explicit 'Use when' trigger clause and excellent distinctiveness from the named product. Its main weakness is a generic what-clause ('API usage') that under-specifies the concrete capabilities and omits natural keywords like database, queries, auth, and storage.

Suggestions

Replace the generic 'API and REST API usage' what-clause with concrete actions, e.g. 'Initialize Supabase clients, run database queries and upserts, manage auth, upload storage files, and subscribe to realtime changes, via the JavaScript client or the REST API directly.'

Add natural trigger synonyms users would actually say — 'Supabase database', 'query Supabase', 'Supabase auth', 'Postgres REST endpoints' — to the 'Use when' clause.

Mention the specific sub-services (auth, storage, realtime, edge functions) so the description surfaces the full scope of the skill body.

DimensionReasoningScore

Specificity

The description names the domain ('Supabase JavaScript client API and REST API usage') and a couple of semi-concrete actions ('setting up clients', 'using REST endpoints directly'), but the what-clause is a generic noun phrase ('API usage') rather than a list of concrete capabilities. It matches the anchor 'Names domain and 1-2 concrete actions, but not comprehensive' — it lacks the enumerated actions (querying tables, auth, storage, realtime) that would justify a 4.

3 / 5

Completeness

Both what and when are present, and the 'Use when integrating Supabase, setting up clients, or using REST endpoints directly' clause is explicit with concrete triggers. It falls just short of anchor 5 because the what-clause ('API and REST API usage') is noticeably less action-concrete than the anchor-5 exemplar, which lists specific actions before the 'Use when' clause.

4 / 5

Trigger Term Quality

The core natural term 'Supabase' is present and reinforced by 'client' and 'REST endpoints', but common variations a user would actually say are missing — database, queries, auth, storage, realtime, Postgres. This fits 'Some relevant keywords but missing common variations or synonyms' rather than the good-coverage anchor 4.

3 / 5

Distinctiveness Conflict Risk

'Supabase' is a distinct named product and the description carves a clear niche (JS client + REST API usage) with product-specific triggers; virtually no other skill would fire on these terms. This matches the anchor 'Clear niche with distinct triggers; minimal conflict risk'.

5 / 5

Total

15

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
fernandezbaptiste/Skrillz
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.