supabase
Handles the full Supabase workflow from schema changes to deployment, with built-in security guardrails that catch common traps like RLS...
Brainstorm a feature idea, then generate PRDs for Ralph autonomous execution.
Full skill instructions
You are helping the user go from a rough idea to executable PRDs for Ralph.
CRITICAL: This command does NOT write code. It produces documentation files only.
| Workflow | Best For |
|---|---|
/idea | Structured brainstorming with guided questions - Claude leads |
Plan mode → save to docs/ideas/ | Free-form exploration - you lead the thinking |
/prd "description" | Quick PRD, no docs artifact needed |
Both /idea and plan mode can produce docs/ideas/*.md files. The difference is who drives the conversation:
/idea asks you structured questions (scope, UX, edge cases, etc.)Use /idea when you want the structured checklist. Use plan mode when you prefer to think through it your way.
$ARGUMENTS
If $ARGUMENTS is empty, ask: "What feature or idea would you like to brainstorm?"
If $ARGUMENTS has content, acknowledge it and proceed.
Say: "Let's brainstorm this idea. I'll help you think it through, then we'll create documentation for Ralph to execute."
Help the user flesh out the idea through conversation:
Scope & UX:
Security (IMPORTANT - ask if feature involves):
Scale (IMPORTANT - ask if feature involves lists/data):
When you have enough information, summarize what you've learned:
Say: "Here's what I understand about the feature:
Problem: [summary] Solution: [summary] Key decisions: [list]
Ready to write this to docs/ideas/{feature-name}.md? Say 'yes' or tell me what to adjust."
STOP and wait for user confirmation before writing any files.
Once the user confirms, write the idea file:
Create the directory if needed:
mkdir -p docs/ideas
Write to docs/ideas/{feature-name}.md with this structure:
# {Feature Name}
## Problem
What problem does this solve?
## Solution
High-level description of the solution.
## User Stories
- As a [user], I want to [action] so that [benefit]
- ...
## Scope
### In Scope
- ...
### Out of Scope
- ...
## Architecture
### Directory Structure
- Where new files should go (be specific: `src/components/forms/`, not just `src/`)
### Patterns to Follow
- Existing components/utilities to reuse
- Naming conventions
### Do NOT Create
- List things that already exist (avoid duplication)
## Security Requirements
- **Authentication**: Who can access? Login required?
- **Password handling**: Must be hashed with bcrypt (cost 10+), never in responses
- **Input validation**: What must be validated/sanitized?
- **Rate limiting**: What should be rate limited?
- **Sensitive data**: What must NEVER appear in logs/responses?
## Scale Requirements
- **Expected volume**: How many users/items/requests?
- **Pagination**: Max items per page (recommend 100)
- **Caching**: What can be cached? For how long?
- **Database**: What indexes are needed?
## UI Mockup (if applicable)
┌─────────────────────────────────┐ │ [ASCII mockup of the UI] │ └─────────────────────────────────┘
## Open Questions
- Any unresolved decisions
Say: "I've written the idea to docs/ideas/{feature-name}.md.
Review it and let me know:
STOP and wait for user response. Do not proceed until they say 'approved' or 'done'.
Only proceed here after user explicitly approves the idea file.
Say: "Now I'll generate the PRD from your idea file."
Use the Skill tool to invoke /prd with the idea file path:
Skill: prd
Args: docs/ideas/{feature-name}.md
This hands off to /prd which handles:
.ralph/prd.jsonDO NOT duplicate the PRD schema or guidelines here - /prd is the single source of truth.
A good idea file has:
If the feature involves UI, include ASCII mockups in the idea file:
┌─────────────────────────────────────┐
│ Dashboard [⚙️] │
├─────────────────────────────────────┤
│ │
│ ┌─────────┐ ┌─────────┐ │
│ │ Card 1 │ │ Card 2 │ │
│ │ $1,234 │ │ 89% │ │
│ └─────────┘ └─────────┘ │
│ │
│ ┌─────────────────────────────┐ │
│ │ Recent Activity │ │
│ │ • Item 1 │ │
│ │ • Item 2 │ │
│ └─────────────────────────────┘ │
└─────────────────────────────────────┘
Ralph will read these from the idea file via story.contextFiles.
Handles the full Supabase workflow from schema changes to deployment, with built-in security guardrails that catch common traps like RLS...
Comprehensive guides and best practices for Neon Serverless Postgres, covering setup, connection methods, authentication, and platform APIs.
Guide for setting up and using Firebase Authentication. Use this skill when the user's app requires user sign-in, user management, or secure data access using auth rules.
A skill to evaluate how secure Firestore security rules are. Use this when Firestore security rules are updated to ensure that the generated rules are extremely secure and robust.
Official skill for integrating Firebase AI Logic (Gemini API) into web applications. Covers setup, multimodal inference, structured output, and security.
Complete Better Auth server and client setup with database adapters, session management, plugins, and security configuration.
Deploy and manage projects on Vercel using token-based authentication. Use when working with Vercel CLI using access tokens rather than interactive login — e.g. "deploy to vercel", "set up vercel", "add environment variables to vercel".
Complete Cloudflare platform integration with decision trees for compute, storage, AI, networking, security, and infrastructure-as-code.
Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.
Send, read, and manage Gmail messages, drafts, labels, and account settings.
Comprehensive website auditing across 230+ rules in 21 categories including SEO, performance, security, and accessibility.
Shared authentication, CLI syntax, and output formatting patterns for gws Google Workspace commands.
Discover your celebrity doppelgänger with StarByFace!
GeoSpy: Pricing, Features, FAQs, and Alternatives for AI Teams
Detect AI-generated voices to protect against audio fraud.
Ensure Your Content's Originality with AI Plagiarism Checker
Upscale images by 400% without quality loss
Protect your social media from copyright disputes
Accurately Detect AI-Generated Content with TheChecker.AI
Chrome extension that detects and flags AI-generated content