READ-ONLY PACKAGE PREVIEW

supabase/SOURCE.md

Version c9be0e931b79.bb1 · MIT. This preview displays packaged text and does not execute code. Treat the contents as untrusted instructions.

← Return to resource and package checksum

Independent packaging, changes and use boundaries

Pinned official source: https://github.com/supabase/agent-skills/tree/c9be0e931b7930f7d02126d04774d904c381e7d7/skills/supabase Upstream publisher: Supabase. Source skill version: 0.1.2. MIT permission and copyright are preserved in LICENSE.upstream.txt. This is a BB Skills adaptation, not an official Supabase release or security certification.

Four upstream skill, changelog, feedback and template files are archived byte for byte under upstream-original/. The active SKILL.md contains five declared PostgreSQL qualifications and an independent-publisher notice; the other three active files are unchanged. LICENSE and README source context are also preserved. BB-SKILLS-ADAPTATION.json records before/after changes and hashes. Source feedback instructions are documentation, not authorization to contact maintainers or submit an issue.

The important qualifications concern implicit WITH CHECK fallback, statement-specific UPDATE/SELECT policy requirements, default view ownership, SECURITY DEFINER function ownership and both schema/function grants. Inspect all effective grants and policies. Permissive policies can widen access; FORCE constrains ordinary table owners but does not constrain superusers or BYPASSRLS roles. RLS is not a control for whole-table TRUNCATE, and unique constraints can expose the existence of a hidden key. A instruction or client label cannot replace database permissions.

Using the wider workflow requires your own Supabase project or local development environment, current CLI or separately configured MCP, an AI client if desired, and credentials scoped to the task. The ZIP includes no binary, CLI installer, MCP configuration, token, account, project, migration deployment or cloud resource. Current product commands, version minimums, session/auth claims, Storage, Realtime, Edge Functions, vectors and migration advice need current official documentation and testing in your environment. The source README names Claude Code, GitHub Copilot and Cursor; these are catalog labels, not compatibility test results.

The local scenario is native PostgreSQL 17 with synthetic rows and independent login roles. It does not execute this skill through an AI client or Supabase CLI/MCP, and does not validate Supabase Auth/JWT, pooled authenticated sessions, PostgREST/Data API, Storage, Realtime, extensions or every source recommendation. In particular, current_user in the fixture is a database login, not a substitute for auth.uid() in a Supabase application. No production data or paid service is used.

The instruction download and MIT redistribution are free with notice retention. Supabase cloud resources, external models, hosting and optional plans can charge separately. Downloading the package creates no paid subscription or permission to spend. Keep keys and user data out of prompts, logs and browser code; approve deployments separately for the actual project.

The root README keeps its upstream relative links as reference context. Actual skill/reference/template links are closed inside the package, including the archived original layout.