CtrlK
BlogDocsLog inGet started
Tessl Logo

supabase-database

Generates Supabase database migrations, writes RLS policies with auth.uid(), configures auth integration, and generates TypeScript types. Use when creating tables, writing migrations, configuring RLS, or implementing Supabase auth.

73

Quality

90%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Excellent content: dense non-obvious Supabase/RLS gotchas, a validation-rich migration workflow with explicit feedback loops, and executable verification/type-generation commands, all in a compact body with clear external pointers. The only improvement space is providing a concrete example migration file and a pointer to the "safe-deploy pipeline" itself.

Suggestions

Include a minimal example migration file (e.g., an ENABLE ROW LEVEL SECURITY + policy pair) to make the RLS gotcha #1 rule directly copy-pasteable.

Name or link the "safe-deploy pipeline" referenced in step 5 so the deployment step is actionable rather than assumed.

DimensionReasoningScore

Conciseness

The body is dense, non-obvious knowledge — "`ENABLE ROW LEVEL SECURITY` with no policy denies everything", "`auth.uid()` is NULL for the `anon` role", "`INSERT` needs `WITH CHECK`, not `USING`" — with no padding and no explanation of concepts Claude already knows. It matches the score-5 anchor: lean, assumes competence, every token earns its place.

5 / 5

Actionability

It provides copy-paste-ready commands (the `pg_tables` verification query and `supabase gen types typescript --project-id <project-id> > src/types/supabase.ts`) plus concrete syntax rules, matching the score-4 anchor (mostly executable, minor gaps). It falls short of 5 because there is no example migration snippet and the "safe-deploy pipeline" is referenced without a concrete command or path.

4 / 5

Workflow Clarity

The 5-step migration workflow has a clear sequence, a destructive-action review step, explicit validation at steps 2 and 4 ("run smoke tests plus per-role RLS checks", "Re-run in CI against a test replica with the full suite"), post-deploy re-verification, and an explicit feedback loop ("On failure: revert, adjust, re-run"). This matches the score-5 anchor, and the destructive/batch validation requirement is fully satisfied — not 4, since checkpoints and error recovery are explicit throughout.

5 / 5

Progressive Disclosure

At ~35 lines with well-organized sections (RLS gotchas, Migration workflow) and one clearly signaled one-level-deep reference ("key files: `.opencastle/stack/supabase-config.md`"), it matches the under-50-lines exception for score 5. No bundle files exist to inline, and no nested references are present.

5 / 5

Total

19

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: four concrete third-person actions followed by an explicit "Use when..." clause with natural trigger phrases. The only weakness is modest synonym coverage (e.g., "row level security", "policies") and slight overlap risk with generic database skills on broad triggers like "creating tables".

Suggestions

Add natural synonyms to the trigger clause, e.g., "creating tables or row level security (RLS) policies".

Tie broad triggers like "creating tables" more tightly to Supabase (e.g., "creating tables in Supabase") to reduce overlap with generic SQL/database skills.

DimensionReasoningScore

Specificity

The description lists four concrete, named actions — "Generates Supabase database migrations, writes RLS policies with auth.uid(), configures auth integration, and generates TypeScript types" — giving comprehensive coverage of the skill's domain. It clearly matches the score-5 anchor (multiple specific concrete actions, comprehensive coverage) rather than 4, since no notable capability gaps remain for this scope.

5 / 5

Completeness

It explicitly answers both "what" (four concrete actions) and "when" ("Use when creating tables, writing migrations, configuring RLS, or implementing Supabase auth") with concrete trigger phrases, exactly matching the score-5 anchor. It uses consistent third-person voice ("Generates", "writes", "configures").

5 / 5

Trigger Term Quality

"Use when creating tables, writing migrations, configuring RLS, or implementing Supabase auth" covers natural phrases users would say, matching the score-4 anchor (good coverage, a few natural terms missing). It falls short of 5 because synonyms like "row level security", "policies", or "schema changes" are absent.

4 / 5

Distinctiveness Conflict Risk

The Supabase-specific vocabulary (RLS, auth.uid(), Supabase auth, TypeScript types) creates a clear niche, but "creating tables" and "writing migrations" could also trigger a generic SQL/database skill, matching the score-4 anchor (mostly distinct, minor overlap risk with closely related skills) better than 5.

4 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
monkilabs/opencastle
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.