Agent skill
workspace-isolation-audit
Use when asked to audit or fix Supabase queries to ensure every query filters by workspace_id and workspace access is validated.
Install this agent skill to your Project
npx add-skill https://github.com/majiayu000/claude-skill-registry/tree/main/skills/other/workspace-isolation-audit
SKILL.md
Goal: ensure multi-tenant isolation by enforcing workspace_id filtering everywhere it applies.
Workflow:
-
Identify affected scope
- Ask which feature/agent/API route is in scope if unclear.
- Prefer targeted fixes over repo-wide refactors.
-
Find candidate queries
- Search for
.from(usage in the relevant area. - Look for missing
.eq("workspace_id", workspaceId)(or equivalent RLS-safe filter).
- Search for
-
Verify workspace context
- API routes: read
workspaceIdfromreq.nextUrl.searchParams, validate viavalidateUserAndWorkspace. - Agents: use
task.workspace_id(required); do not derive workspace from auth user id. - Server helpers: ensure functions accept
workspaceIdexplicitly rather than importing globals.
- API routes: read
-
Fix and harden
- Add the required filter.
- Add or update targeted tests for the modified behavior.
-
Validate
- Run
npm run typecheck. - Run the most targeted tests that cover the change (Vitest/Playwright depending on area).
- Run
Recommended Agent Skills
Expand your agent's capabilities with these related and highly-rated skills.
agent-ops-spec
Manage specification documents in .agent/specs/. Use when user provides requirements, acceptance criteria, or feature descriptions that need to be tracked and validated against implementation.
agent-ops-state
Maintain .agent state files. Use at session start, after meaningful steps, and before concluding: read/update constitution/memory/focus/issues/baseline consistently.
agent-ops-spec
Manage specification documents in .agent/specs/. Use when user provides requirements, acceptance criteria, or feature descriptions that need to be tracked and validated against implementation.
agent-ops-testing
Test strategy, execution, and coverage analysis. Use when designing tests, running test suites, or analyzing test results beyond baseline checks.
agent-ops-testing
Test strategy, execution, and coverage analysis. Use when designing tests, running test suites, or analyzing test results beyond baseline checks.
agent-ops-state
Maintain .agent state files. Use at session start, after meaningful steps, and before concluding: read/update constitution/memory/focus/issues/baseline consistently.
Didn't find tool you were looking for?