supabase
Handles the full Supabase workflow from schema changes to deployment, with built-in security guardrails that catch common traps like RLS...
<objective> Perform comprehensive security and quality audit of code, architecture, infrastructure, or sprint implementations. Generate prioritized findings with actionable remediation at the appropriate output path based on audit type. </objective>
Full skill instructions
<zone_constraints>
This skill operates under Managed Scaffolding:
| Zone | Permission | Notes |
|---|---|---|
.claude/ | NONE | System zone - never suggest edits |
loa-grimoire/, .beads/ | Read/Write | State zone - project memory |
src/, lib/, app/ | Read-only | App zone - requires user confirmation |
NEVER suggest modifications to .claude/. Direct users to .claude/overrides/ or .loa.config.yaml.
</zone_constraints>
<integrity_precheck>
Before ANY operation, verify System Zone integrity:
yq eval '.integrity_enforcement' .loa.config.yamlstrict and drift detected -> HALT and reportwarn -> Log warning and proceed with caution
</integrity_precheck><factual_grounding>
Before ANY synthesis, planning, or recommendation:
"[exact quote]" (file.md:L45)[ASSUMPTION]Grounded Example:
The SDD specifies "PostgreSQL 15 with pgvector extension" (sdd.md:L123)
Ungrounded Example:
[ASSUMPTION] The database likely needs connection pooling
</factual_grounding>
<structured_memory_protocol>
loa-grimoire/NOTES.md<tool_result_clearing>
After tool-heavy operations (grep, cat, tree, API calls):
Example:
# Raw grep: 500 tokens -> After decay: 30 tokens
"Found 47 AuthService refs across 12 files. Key locations in NOTES.md."
</tool_result_clearing>
<trajectory_logging>
Log each significant step to loa-grimoire/a2a/trajectory/{agent}-{date}.jsonl:
{"timestamp": "...", "agent": "...", "action": "...", "reasoning": "...", "grounding": {...}}
</trajectory_logging>
<kernel_framework>
Perform comprehensive security and quality audit. Generate reports at:
SECURITY-AUDIT-REPORT.md + loa-grimoire/audits/YYYY-MM-DD/loa-grimoire/a2a/deployment-feedback.mdloa-grimoire/a2a/sprint-N/auditor-sprint-feedback.mdloa-grimoire/audits/YYYY-MM-DD/Success = Comprehensive report with:
Verdicts:
<uncertainty_protocol>
<grounding_requirements> Before auditing:
<citation_requirements>
Assess codebase size to determine parallel splitting:
find . -name "*.ts" -o -name "*.js" -o -name "*.tf" -o -name "*.py" | xargs wc -l 2>/dev/null | tail -1
Thresholds:
| Size | Lines | Strategy |
|---|---|---|
| SMALL | <2,000 | Sequential (all 5 categories) |
| MEDIUM | 2,000-5,000 | Consider category splitting |
| LARGE | >5,000 | MUST split into parallel |
If MEDIUM/LARGE: See <parallel_execution> section below.
For Sprint Audit:
loa-grimoire/a2a/sprint-N/engineer-feedback.md (senior lead approval required)For Deployment Audit:
loa-grimoire/deployment/ existsdeployment-report.md for context if existsFor Codebase Audit:
Execute audit by category (sequential or parallel per Phase -1):
Security Audit - See resources/REFERENCE.md §Security
Architecture Audit - See resources/REFERENCE.md §Architecture
Code Quality Audit - See resources/REFERENCE.md §CodeQuality
DevOps Audit - See resources/REFERENCE.md §DevOps
Blockchain/Crypto Audit - See resources/REFERENCE.md §Blockchain (if applicable)
Use template from resources/templates/audit-report.md.
File Organization:
SECURITY-AUDIT-REPORT.md at rootloa-grimoire/audits/YYYY-MM-DD/Sprint/Deployment Audit:
Codebase Audit:
<parallel_execution>
Spawn 5 parallel Explore agents:
Focus ONLY on: Secrets, Auth, Input Validation, Data Privacy,
Supply Chain, API Security, Infrastructure Security
Files: [auth/, api/, middleware/, config/]
Return: Findings with severity, file:line, PoC, remediation
Focus ONLY on: Threat Model, SPOFs, Complexity, Scalability, Decentralization
Files: [src/, infrastructure/]
Return: Findings with severity, file:line, remediation
Focus ONLY on: Error Handling, Type Safety, Code Smells, Testing, Docs
Files: [src/, tests/]
Return: Findings with severity, file:line, remediation
Focus ONLY on: Deployment Security, Monitoring, Backup, Access Control
Files: [Dockerfile, terraform/, .github/workflows/, scripts/]
Return: Findings with severity, file:line, remediation
Focus ONLY on: Key Management, Transaction Security, Contract Interactions
Files: [contracts/, wallet/, web3/]
Return: Findings OR "N/A - No blockchain code"
<output_format>
See resources/templates/audit-report.md for full structure.
Key sections:
<success_criteria>
<communication_style> Be direct and blunt:
Be specific with evidence:
Be uncompromising on security:
Be practical but paranoid:
Red Flags (immediate CRITICAL):
Handles the full Supabase workflow from schema changes to deployment, with built-in security guardrails that catch common traps like RLS...
Comprehensive guides and best practices for Neon Serverless Postgres, covering setup, connection methods, authentication, and platform APIs.
Guide for setting up and using Firebase Authentication. Use this skill when the user's app requires user sign-in, user management, or secure data access using auth rules.
A skill to evaluate how secure Firestore security rules are. Use this when Firestore security rules are updated to ensure that the generated rules are extremely secure and robust.
Official skill for integrating Firebase AI Logic (Gemini API) into web applications. Covers setup, multimodal inference, structured output, and security.
Complete Better Auth server and client setup with database adapters, session management, plugins, and security configuration.
Deploy and manage projects on Vercel using token-based authentication. Use when working with Vercel CLI using access tokens rather than interactive login — e.g. "deploy to vercel", "set up vercel", "add environment variables to vercel".
Complete Cloudflare platform integration with decision trees for compute, storage, AI, networking, security, and infrastructure-as-code.
Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.
Send, read, and manage Gmail messages, drafts, labels, and account settings.
Comprehensive website auditing across 230+ rules in 21 categories including SEO, performance, security, and accessibility.
Shared authentication, CLI syntax, and output formatting patterns for gws Google Workspace commands.
Discover your celebrity doppelgänger with StarByFace!
GeoSpy: Pricing, Features, FAQs, and Alternatives for AI Teams
Detect AI-generated voices to protect against audio fraud.
Ensure Your Content's Originality with AI Plagiarism Checker
Upscale images by 400% without quality loss
Protect your social media from copyright disputes
Accurately Detect AI-Generated Content with TheChecker.AI
Chrome extension that detects and flags AI-generated content