/journey-rls
Use as the RLS build stage of the Butterbase journey, after journey-schema. Implements the RLS section of 02-plan.md by delegating to debug-rls policy patterns (for proactive creation, not debugging). Calls manage_rls (create_user_isolation, enable, create_policy). Folded into
$ npx -y skills add butterbase-ai/butterbase-skills --skill journey-rls --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/journey-rls
Context preview
The summary Claude sees to decide when to auto-load this skill.
Use as the RLS build stage of the Butterbase journey, after journey-schema. Implements the RLS section of 02-plan.md by delegating to debug-rls policy patterns (for proactive creation, not debugging). Calls manage_rls (create_user_isolation, enable, create_policy). Folded into
SKILL.md
journey-rls.SKILL.mdname: journey-rls
description: Use as the RLS build stage of the Butterbase journey, after journey-schema. Implements the RLS section of 02-plan.md by delegating to debug-rls policy patterns (for proactive creation, not debugging). Calls manage_rls (create_user_isolation, enable, create_policy). Folded into journey-schema when hackathon_mode is true.
Journey: RLS
Stage 3b of the guided journey. Install Row-Level Security policies for user-owned tables.
When to use
- Dispatched by `journey` when `current_stage: rls`.
- Directly via `/butterbase-skills:journey-rls`.
- Folded into `journey-schema` when `hackathon_mode: true` (do not run separately).
Preflight
If `docs/butterbase/03-preflight.md` is missing, older than 24 hours, or `00-state.md` has `app_id: null`, invoke `butterbase-skills:journey-preflight` first. Wait for it to return successfully before proceeding.
Inputs
- `docs/butterbase/02-plan.md` — the RLS section.
- `docs/butterbase/00-state.md` — for `app_id`.
Procedure
0. **Refresh docs.** Call `butterbase_docs` with `topic: "auth"`. For RLS-specific patterns, also WebFetch `https://docs.butterbase.ai/auth/rls`. Skip if cache is fresh.
1. Read the RLS section of `02-plan.md`. Print it back: `"About to install RLS policies: <list>. Proceed?"`. Wait for `yes`. 2. Invoke `butterbase-skills:debug-rls` via the Skill tool with mode `proactive`, passing the RLS plan and `app_id`. For each user-isolation entry, the wrapped skill calls `manage_rls action: create_user_isolation`. For custom policies, `manage_rls action: enable` then `action: create_policy`. 3. After it returns, sanity-check with `manage_rls action: list` and show the user. 4. Append one line to `docs/butterbase/04-build-log.md`: `<ISO timestamp> rls manage_rls ok` 5. Tick `- [x] rls` in `00-state.md`, set `current_stage:` to the next unchecked stage, bump `last_updated`. 6. Return to `journey` orchestrator (or ask `"Continue to the next stage? (yes/no)"`).
Outputs
- Live RLS policies in the Butterbase app.
- One line in `04-build-log.md`.
Anti-patterns
- ❌ Skipping `manage_rls action: list` verification — invisible policy failures are the #1 RLS gotcha.
- ❌ Creating policies on a table where RLS is not enabled — `enable` must come first.
Read more
name: journey-rls description: Use as the RLS build stage of the Butterbase journey, after journey-schema. Implements the RLS section of 02-plan.md by delegating to debug-rls policy patterns (for proactive creation, not debugging). Calls manage_rls (create_user_isolation, enable, create_policy). Folded into journey-schema when hackathon_mode is true.
Journey: RLS
Stage 3b of the guided journey. Install Row-Level Security policies for user-owned tables.
When to use
- Dispatched by `journey` when `current_stage: rls`.
- Directly via `/butterbase-skills:journey-rls`.
- Folded into `journey-schema` when `hackathon_mode: true` (do not run separately).
Preflight
If `docs/butterbase/03-preflight.md` is missing, older than 24 hours, or `00-state.md` has `app_id: null`, invoke `butterbase-skills:journey-preflight` first. Wait for it to return successfully before proceeding.
Inputs
- `docs/butterbase/02-plan.md` — the RLS section.
- `docs/butterbase/00-state.md` — for `app_id`.
Procedure
0. **Refresh docs.** Call `butterbase_docs` with `topic: "auth"`. For RLS-specific patterns, also WebFetch `https://docs.butterbase.ai/auth/rls`. Skip if cache is fresh.
1. Read the RLS section of `02-plan.md`. Print it back: `"About to install RLS policies: <list>. Proceed?"`. Wait for `yes`. 2. Invoke `butterbase-skills:debug-rls` via the Skill tool with mode `proactive`, passing the RLS plan and `app_id`. For each user-isolation entry, the wrapped skill calls `manage_rls action: create_user_isolation`. For custom policies, `manage_rls action: enable` then `action: create_policy`. 3. After it returns, sanity-check with `manage_rls action: list` and show the user. 4. Append one line to `docs/butterbase/04-build-log.md`: `<ISO timestamp> rls manage_rls ok` 5. Tick `- [x] rls` in `00-state.md`, set `current_stage:` to the next unchecked stage, bump `last_updated`. 6. Return to `journey` orchestrator (or ask `"Continue to the next stage? (yes/no)"`).
Outputs
- Live RLS policies in the Butterbase app.
- One line in `04-build-log.md`.
Anti-patterns
- ❌ Skipping `manage_rls action: list` verification — invisible policy failures are the #1 RLS gotcha.
- ❌ Creating policies on a table where RLS is not enabled — `enable` must come first.
Claude Code plugin for Butterbase — the AI-Native Backend-as-a-Service. This plugin gives Claude deep knowledge of Butterbase's 42+ MCP tools, guides you through common workflows, and auto-configures the MCP server connection.
Repo: butterbase-ai/butterbase-skills
Other skills on butterbase-skills.
- /agents
Use when designing, deploying, or debugging a Butterbase Agent (declarative LLM/tool graph), registering an MCP server for tool use, or wiring access controls and rate limits. Agents are first-class app resources defined by a `graph_spec` and invoked over
Open skill - /ai
Use when calling the app's AI gateway from agent tools — chat completions, embeddings, listing models, configuring defaults or BYOK, reading token/cost usage
Open skill - /auth-setup
Use when configuring OAuth providers (Google/GitHub/Apple/X/etc.), setting up post-login auth hooks, tuning JWT lifetimes, or generating service API keys
Open skill - /build-app
Use when building a new Butterbase app from scratch, creating a full-stack application, or when the user asks to set up a complete backend with database, auth, and deployment
Open skill - /contributing
Use when contributing to the Butterbase codebase, adding new MCP tools, creating API routes, writing migrations, or understanding the monorepo architecture
Open skill - /debug-rls
Use when users report access denied errors, see wrong data, RLS policies are not working, or when troubleshooting Row-Level Security issues in Butterbase
Open skill

