Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/zoxknez/ai-coding-rules/65-stack-supabasegit clone --depth 1 https://github.com/zoxknez/ai-coding-rulesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00934 |
| Opus 5 | $0.00000 | $0.00467 |
| Sonnet 5 | $0.00000 | $0.00187 |
| Haiku 4.5 | $0.00000 | $0.00093 |
Grade A, and why
65-stack-supabase scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- 65-stack-supabase — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 163 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Supabase Stack Rules
Row-Level Security (RLS)
Mandatory Practices
- Enable RLS on ALL tables (no exceptions)
- Use
(SELECT auth.uid())pattern for performance (17x faster) - Index all columns used in RLS policies
- Always guard against null auth state
Performance Patterns
Function Caching (CRITICAL)
-- ❌ BAD: O(N × f(C)) — function per row
auth.uid() = user_id
-- ✅ GOOD: O(N + f(C)) — function once
(SELECT auth.uid()) = user_id
Join Optimization
-- ❌ BAD: Subquery per row
user_id IN (SELECT id FROM team_members WHERE team_id = ...)
-- ✅ GOOD: Array comparison
user_id = ANY(ARRAY(SELECT id FROM team_members WHERE team_id = ...))
Null Guards
-- ✅ Always include
auth.uid() IS NOT NULL AND (SELECT auth.uid()) = user_id
Policy Types
- Use permissive policies by default
- Use restrictive only for complex multi-condition scenarios
- Combine policies with OR logic (permissive) or AND logic (restrictive)
Authentication
Client-Side
- Never trust client-side auth state for sensitive operations
- Always verify session server-side before mutations
- Use
supabase.auth.getUser()NOTgetSession()for security
Server-Side
// ✅ Secure: Validates JWT with Supabase
const { data: { user }, error } = await supabase.auth.getUser();
// ❌ Insecure: Can be spoofed
const { data: { session } } = await supabase.auth.getSession();
Token Handling
- Never log full tokens
- Use short-lived access tokens
- Implement token refresh logic
Edge Functions
Structure
import { serve } from 'https://deno.land/[email protected]/http/server.ts';
serve(async (req) => {
// CORS handling
if (req.method === 'OPTIONS') {
return new Response('ok', { headers: corsHeaders });
}
try {
// Function logic
return new Response(JSON.stringify({ data }), {
headers: { ...corsHeaders, 'Content-Type': 'application/json' },
status: 200,
});
} catch (error) {
return new Response(JSON.stringify({ error: error.message }), {
headers: { ...corsHeaders, 'Content-Type': 'application/json' },
status: 400,
});
}
});
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 163 lines · 0 tokens per session scan A a70541923785
65-stack-supabase is a cursor rule published in the GitHub repository zoxknez/ai-coding-rules (27 stars, last pushed 4mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 934 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other cursor rules, from other repositories
angular-20
This rule provides comprehensive best practices and coding standards for Angular development, focusing on modern TypeScript, standalone components, signals, and performance optimizations.
dev-standard
Apache Superset development standards and guidelines for Cursor IDE.
cli-error-handling
CLI command error handling patterns.
prefer-direct-imports-over-module-mocks
Prefer extracting a testable core over vi.mock / vi.resetModules when unit tests need to reach production logic entangled with config, env, or singletons.
control-plane-descriptors
Control plane descriptor and instance implementation patterns.
family-instance-domain-actions
Family instance domain action implementation patterns.