CtrlK
BlogDocsLog inGet started
Tessl Logo

supabase-storage

Supabase Storage for file uploads, downloads, buckets, and signed URLs. Use when uploading files, managing storage buckets, generating signed URLs, or handling images.

64

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

The canonical home for this skill is supabase-storage in fernandezbaptiste/Skrillz

SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is a highly actionable, executable reference with lean code-first sections, but it stumbles on workflow safety and structure: destructive/batch operations (multi-file remove, bucket creation, RLS policies) have no validation or feedback loops, and its progressive disclosure is undermined by a broken reference link and policy content inlined that duplicates the existing reference file.

Suggestions

Add validation checkpoints around destructive/batch operations: before `remove([...])` list files to confirm targets, check the returned error, and verify deletion afterward; similarly show verifying a bucket exists before INSERT and checking policy application with a test query.

Fix the References section: either create references/upload-patterns.md or remove the link, since the file is missing from the bundle.

Move the full 'Storage RLS Policies' SQL examples into the existing references/storage-policies.md and keep only one or two exemplar policies inline, trimming the near-duplicate 'Download as Blob'/'Download to Browser' pair to one section.

DimensionReasoningScore

Conciseness

The body is almost entirely lean, executable snippets with one-line annotations ("upsert: true // Replace if exists", "// data is a Blob") and no padding explaining concepts Claude already knows, matching the 'efficient; minor instances that could be trimmed' anchor — e.g., 'Download as Blob' and 'Download to Browser' largely repeat each other, and the 'Enable RLS' section is only an empty SQL comment.

4 / 5

Actionability

Every section provides copy-paste-ready executable JavaScript/SQL/TOML covering the common cases — uploads (basic, options, browser, base64), downloads, public/signed URLs, list with search, single/multiple delete, move/copy, transforms, RLS policies, plus concrete error-message branching ("The resource already exists", 'exceeded', 'mime type') — matching the 'fully executable; covers common cases' anchor.

5 / 5

Workflow Clarity

The skill is reference-style with clearly organized task sections, but the destructive and batch operations lack validation or verification checkpoints: `remove([...])` deletes multiple files with no pre-check or post-verification, bucket creation and RLS policies apply with no confirm/rollback guidance, and error handling is shown only for uploads. Per the rubric cap, destructive/batch operations without validation cannot score above 3; the missing checkpoints for delete/policy operations keep it at the 'sequence present but checkpoints missing' anchor.

3 / 5

Progressive Disclosure

Section structure is clear and the References section signals one-level-deep files, but one of the two referenced files (references/upload-patterns.md) does not exist in the bundle, breaking navigation, and ~60 lines of RLS policy SQL are inlined in the body that duplicate content in the existing references/storage-policies.md — content that belongs in the separate file sits inline and a listed reference is dead, matching the 'could be better organized; references present but not clearly signaled' anchor.

3 / 5

Total

15

/

20

Passed

Description

83%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, well-formed description: it names a specific domain, lists several concrete capabilities, and includes an explicit third-person 'Use when...' trigger clause with natural phrases. Its only weaknesses are minor — some covered capabilities and trigger variations (downloads, deletes, file extensions) are absent from the description.

Suggestions

Add the remaining covered capabilities to the 'what' clause (e.g., listing, deleting, moving/copying files and image transformations) to close the coverage gap.

Include trigger variations for the other common tasks, e.g., 'downloading or deleting files, listing bucket contents, or transforming/serving images'.

Tie the generic triggers ('uploading files', 'handling images') explicitly to Supabase (e.g., 'Use when working with Supabase projects and the user needs to upload files...') to reduce overlap with generic file-upload skills.

DimensionReasoningScore

Specificity

"Supabase Storage for file uploads, downloads, buckets, and signed URLs" names the domain plus several concrete actions (upload, download, bucket management, signed URLs), but omits other capabilities the skill itself covers (delete, move/copy, list, image transformations, RLS policies), matching the 'several specific actions; minor gaps' anchor rather than comprehensive coverage.

4 / 5

Completeness

It explicitly answers both questions with concrete trigger phrases: the 'what' ("Supabase Storage for file uploads, downloads, buckets, and signed URLs") and the 'when' ("Use when uploading files, managing storage buckets, generating signed URLs, or handling images"), mirroring the anchor-5 example structure; voice is third person, not first/second.

5 / 5

Trigger Term Quality

The 'Use when' clause lists natural phrases users would say — "uploading files", "managing storage buckets", "generating signed URLs", "handling images" — giving good keyword coverage, but misses common variations like downloading/deleting files and lacks synonyms or file-type terms (e.g., images are named but no extensions), so it falls short of the comprehensive-synonyms anchor.

4 / 5

Distinctiveness Conflict Risk

"Supabase Storage" carves a clear niche and "generating signed URLs" / "storage buckets" are Supabase-distinct triggers, but "uploading files" and "handling images" are generic phrases that could also fire for non-Supabase upload/image skills — minor overlap risk, matching the 'mostly distinct' anchor.

4 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 1 missing

Warning

referenced_paths_exist

Referenced path issues: 1 missing

Warning

Total

14

/

16

Passed

Repository
fernandezbaptiste/Skrillz
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.