Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/luxvil/ai-coding-rules/65-stack-supabasegit clone --depth 1 https://github.com/Luxvil/ai-coding-rulesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00934 |
| Opus 5 | $0.00000 | $0.00467 |
| Sonnet 5 | $0.00000 | $0.00187 |
| Haiku 4.5 | $0.00000 | $0.00093 |
Grade A, and why
65-stack-supabase scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to 65-stack-supabase — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 163 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Supabase Stack Rules
Row-Level Security (RLS)
Mandatory Practices
- Enable RLS on ALL tables (no exceptions)
- Use
(SELECT auth.uid())pattern for performance (17x faster) - Index all columns used in RLS policies
- Always guard against null auth state
Performance Patterns
Function Caching (CRITICAL)
-- ❌ BAD: O(N × f(C)) — function per row
auth.uid() = user_id
-- ✅ GOOD: O(N + f(C)) — function once
(SELECT auth.uid()) = user_id
Join Optimization
-- ❌ BAD: Subquery per row
user_id IN (SELECT id FROM team_members WHERE team_id = ...)
-- ✅ GOOD: Array comparison
user_id = ANY(ARRAY(SELECT id FROM team_members WHERE team_id = ...))
Null Guards
-- ✅ Always include
auth.uid() IS NOT NULL AND (SELECT auth.uid()) = user_id
Policy Types
- Use permissive policies by default
- Use restrictive only for complex multi-condition scenarios
- Combine policies with OR logic (permissive) or AND logic (restrictive)
Authentication
Client-Side
- Never trust client-side auth state for sensitive operations
- Always verify session server-side before mutations
- Use
supabase.auth.getUser()NOTgetSession()for security
Server-Side
// ✅ Secure: Validates JWT with Supabase
const { data: { user }, error } = await supabase.auth.getUser();
// ❌ Insecure: Can be spoofed
const { data: { session } } = await supabase.auth.getSession();
Token Handling
- Never log full tokens
- Use short-lived access tokens
- Implement token refresh logic
Edge Functions
Structure
import { serve } from 'https://deno.land/[email protected]/http/server.ts';
serve(async (req) => {
// CORS handling
if (req.method === 'OPTIONS') {
return new Response('ok', { headers: corsHeaders });
}
try {
// Function logic
return new Response(JSON.stringify({ data }), {
headers: { ...corsHeaders, 'Content-Type': 'application/json' },
status: 200,
});
} catch (error) {
return new Response(JSON.stringify({ error: error.message }), {
headers: { ...corsHeaders, 'Content-Type': 'application/json' },
status: 400,
});
}
});
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 163 lines · 0 tokens per session scan A a70541923785
65-stack-supabase is a cursor rule published in the GitHub repository Luxvil/ai-coding-rules (3 stars, last pushed 2d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 934 tokens. A static security scan graded it A with 0 findings. It is 100% identical to 65-stack-supabase, differing in 0 lines, and is treated as a copy.
Other cursor rules, from other repositories
exam-answer-format
Guidelines for writing exam-style answers in a practical, conversational style with definitions first followed by real-world examples.
lecture-reference-linking
Guidelines for including course materials lists and inline references when writing exam answers or documentation that references course materials.
short-answer-version
Guidelines for creating short/concise versions of detailed answers.
documentation-formatting
Guidelines for formatting markdown documentation to improve readability and scannability.
mermaid-diagrams
Guidelines for adding Mermaid diagrams to exam answers and documentation with automatic SVG generation support.
human-writing-style
Rules for writing naturally and authentically - avoid robotic AI tone in documentation, code comments, error messages, and explanations. Write like a human colleague, not a customer service bot.