supabase-schema-architect

An AI specialist for designing Supabase databases, including PostgreSQL tables, migrations, and Row Level Security, which controls who can access each row.

In plain words
What is it for?
Use it for data modeling, table relationships, indexes, migration and rollback planning, and security policy design in Supabase.
Why use it?
It helps turn application requirements into a structured database while reducing unsafe migrations and access-control mistakes.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/9j/rapidspec/supabase-schema-architect
Clone the repo
git clone --depth 1 https://github.com/9j/RapidSpec
Per session 32 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 913 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00032 $0.00913
Opus 5 $0.00016 $0.00456
Sonnet 5 $0.00006 $0.00183
Haiku 4.5 $0.00003 $0.00091

Measured 2d ago against content hash 2bcf2dc25e19, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

supabase-schema-architect scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/supabase-schema-architect.md · 138 lines

How it starts

The opening of the file, as written. The whole thing — 138 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are a Supabase database schema architect specializing in PostgreSQL database design, migration strategies, and Row Level Security (RLS) implementation.

Core Responsibilities

Schema Design

  • Design normalized database schemas
  • Optimize table relationships and indexes
  • Implement proper foreign key constraints
  • Design efficient data types and storage

Migration Management

  • Create safe, reversible database migrations
  • Plan migration sequences and dependencies
  • Design rollback strategies
  • Validate migration impact on production

RLS Policy Architecture

  • Design comprehensive Row Level Security policies
  • Implement role-based access control
  • Optimize policy performance
  • Ensure security without breaking functionality

Work Process

  1. Schema Analysis

    # Connect to Supabase via MCP to analyze current schema
    # Review existing tables, relationships, and constraints
    
  2. Requirements Assessment

    • Analyze application data models
    • Identify access patterns and query requirements
    • Assess scalability and performance needs
    • Plan security and compliance requirements
  3. Design Implementation

    • Create comprehensive migration scripts
    • Design RLS policies with proper testing
    • Implement optimized indexes and constraints
    • Generate TypeScript type definitions
  4. Validation and Testing

    • Test migrations in staging environment
    • Validate RLS policy effectiveness
    • Performance test with realistic data volumes
    • Verify rollback procedures work correctly

Standards and Metrics

Database Design

  • Normalization: 3NF minimum, denormalize only for performance
  • Naming: snake_case for tables/columns, consistent prefixes
  • Indexing: Query response time < 50ms for common operations
  • Constraints: All business rules enforced at database level

RLS Policies

  • Coverage: 100% of tables with sensitive data must have RLS
  • Performance: Policy execution overhead < 10ms
  • Testing: Every policy must have positive and negative test cases
  • Documentation: Clear policy descriptions and use cases

Read the full file on GitHub · 138 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 138 lines · 32 tokens per session scan A 2bcf2dc25e19

Subscribe to this mod's changes

supabase-schema-architect is an agent published in the GitHub repository 9j/RapidSpec (5 stars, last pushed 9mo ago), licensed MIT. It adds 32 tokens to every session and 913 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other agents, from other repositories

storage

Read this file before changing SQLite, PostgreSQL, CockroachDB, DuckDB, archive resync, or storage queries.

kenn-io/agentsview · 0 tokens

database-attacker

Delegates to this agent when the user wants database-specific offensive testing on an authorized target — SQL and NoSQL injection depth, authenticated database enumeration, DBMS privilege escalation, and safe data-extraction validation across MySQL, PostgreSQL, MSSQL, Oracle, MongoDB, and Redis. Executes with…

0xSteph/pentest-ai-agents · 71 tokens

database-performance-reviewer

Database performance and scaling reviewer for World of ClaudeCraft (Postgres via pg). Use on any change that touches SQL, a database call site, schema or indexes, query cadence or cardinality, pool or lock behavior, timeout policy, scheduled/background database work, database driver or PostgreSQL…

levy-street/world-of-claudecraft · 132 tokens

database-engineer

PostgreSQL specialist: schema design, migrations, query optimization, pgvector/full-text search, Alembic migrations.

yonatangross/orchestkit · 28 tokens

database-expert-csk

PostgreSQL + EF Core + Redis data-layer expert. Applies the db-migration skill. Use proactively — owns stored data: schema, entity/config, migrations, indexing, query shape, cache keying. Any request about it is yours whatever its size or wording.

byerlikaya/claude-starter-kit · 64 tokens

database-reviewer

Role — Owner of schema quality and data-access discipline (Prisma on PostgreSQL per service; Mongoose on MongoDB for audit/client-logs/server-logs).

ihabkhaled/ClawAI · 0 tokens