Supabase Postgres best practices

Schema, indexing and row-level security as Supabase recommends them.

Installation

$ npx skills add supabase/agent-skills

The CLI's unit is the repository, so this installs everything in supabase/agent-skills, not supabase-postgres-best-practices alone. It writes into whichever agent directories it finds — Claude Code, Codex, Cursor, Copilot, Windsurf, Zed.

Summary

Schema, indexing and row-level security as Supabase recommends them.

  • Reach for it when anything touching RLS policies — the place where a plausible-looking generated policy is a data leak.
  • Spans Implement and Secure, so it is usually worth loading for the whole piece of work rather than at one moment in it.
  • Assumes sql.
  • Published by Supabase, who ship the thing it is about — a stronger claim than a well-regarded engineer having written something good.
  • Installing pulls the whole supabase/agent-skills repository, which is the CLI's unit — not this file alone.

Where it sits in delivery

ImplementWriting the change: framework-specific conventions, and the discipline that keeps a long agent run on the rails.Everything in Build
SecureThreat modelling, scanning, supply chain, and finding the other five copies of the bug you just found.Everything in Secure

The skill itself

The full text lives with its publisher and changes when they change it. Read it there rather than here — a mirrored copy of somebody else's procedure goes stale silently, and this page would have no way of telling you.

Related

More in Implement