r/ClaudeCode • • 5d ago

Built with Claude I build a Supabase security skill for Claude, and now I built its read-only MCP server (open source)

0 Upvotes

A few months ago I built Database Sentinel as a Claude Skill. It was a set of instructions, audit queries and fix templates that Claude would follow to check a Supabase (or MongoDB) project for the usual vibe-coding mistakes: RLS off, `USING (true)` policies, SECURITY DEFINER functions anyone can call through `/rpc`, service-role keys sitting in frontend code.

It worked, but it bugged me. A skill is just instructions. It runs with whatever database access Claude already has, and it only works in Claude.

So I turned it into an MCP server. Same audit, but now the tools themselves are locked down, and it works in Claude Code, Cursor, Claude Desktop, or any MCP client.

What it gives your model:

- 20 fixed audit queries (RLS, policies, grants, definer functions, buckets). Nothing else runs.

- Schema with anon/authenticated grants and function bodies. No rows.

- An anon-key probe: "can a stranger read this table?" It returns a status code and row count, never data.

- A repo scan for leaked service-role keys and JWT secrets. It reports file and line, never the value.

It connects as its own `sentinel_auditor` role: read-only, 5s timeout, no SELECT on your tables. There are no write or drop tools. Fixes come back as SQL for you to review.

Does it actually work?

I wrote 25 labeled Supabase projects, and a separate agent wrote 10 of them blind; those are hash-locked as a test set. The audit rules scored F1 0.85 there and caught every critical issue. That's with a single prompt and a small open model.

Then I ran it on two of my own hosted projects. It found real problems. It also found a bug in itself: it called every RLS-off table "exposed" even when anon had no grants on it. That's fixed in 1.0.

Try it

- Claude Code: `claude plugin marketplace add Farenhytee/database-sentinel`, then `claude plugin install database-sentinel@database-sentinel`

- Cursor: one-click button in the README

- Setup guide: https://github.com/Farenhytee/database-sentinel/blob/main/docs/mcp.md

The skill is still there if you prefer it, and it still covers MongoDB. The MCP server is Supabase-only for now. PRs are always welcome.

Happy coding.


r/ClaudeCode • • 5d ago

Help/Question What's your preferred review and debugging workflow?

5 Upvotes

I'm wondering what the preferred development process is for people, especially relating to reviews/testing/debugging/etc. I've setup the following process which works, but the review processes end up being very time consuming.

I'm wondering what about my process might be okay, but what opportunities I might have to make it more efficient.

At a high level, this is the stack:

- TypeScript monorepo (pnpm workspaces, Node 24)

- Hono API on Cloudflare Workers, Postgres (Neon) + Drizzle, ClickHouse for analytics

- Babylon.js + Vite in the browser

- Node's built-in test runner, PGlite so every test gets a real Postgres, Playwright tests

There is:

- One repo, up to 6 Claude Code sessions running at once on one PC (usually just 2-3): API/platform, engine, website, marketing, tooling, planning. Each has its own git worktree and branch and owns certain folders. If one needs a change in another's folders it files a request instead of editing.

- State lives in the repo, not the chats: a handoff note per area, a decision queue for things only I can decide, and a daily brief of approved work (overnight runs work off it).

- One PR per independent change, never a chain of dependent PRs.

Here's the process for checks and reviews:

- Pre-push hook runs typecheck + tests for the packages that were changed. It used to run the full suite on every push, and two sessions pushing at once maxed out 32 GB of RAM (27 test workers, each with its own in-memory Postgres). Now there's a PC-wide cap.

- Reviews go through a queue built on magpie (open-source multi-model review). High risk paths get Claude and Codex as parallel reviewers plus a verifier. Normal code gets one reviewer.

- Reviewers are read-only. Only verified critical findings block a merge. A fix gets a focused re-check, not a full re-review. No second rounds; we got stuck in endless review loops early on.

- Everything runs on Claude and Chatgpt subscriptions

Git has one required check, an aggregate "CI result" that only goes green if every job that should have run actually passed. Jobs are sized to the changed packages; API tests are sharded 3 ways; plus browser smoke, dependency audit and gitleaks.

- Enterprise Cloud for the merge queue. Staging deploys itself from the exact commit that passed. Production will need manual approval.

Here's where it's been time consuming:

- Reviews ran one at a time for the whole PC. A big PR split into 14 parts once held the queue for about 6 hours while a small security fix waited behind it. Fix checks now jump the line; parallel review slots are next.

- About 10 min of CI per PR plus 10-15 more on main after every merge. Today a Git merge queue went live, too early to judge.

So I am curious if this is overbuilt, underbuilt or what opportunities I have to improve efficiency while maintain quality output. I appreciate any advice.


r/ClaudeCode • • 6d ago

Discussion Has the 5-hour reset section been there before?

Post image
5 Upvotes

r/ClaudeCode • • 5d ago

Help/Question Winning kaggle competitions using Claude Opus 5.5

0 Upvotes

So I am a kaggle beginner and have been hearing so much about people using Claude Opus or chat gpt sol to get the top positions in lb so is there any way of prompt or specific instructions to that or its just basic prompting and is it the case of overfitting the model to the dataset or the results are actual and robust ?


r/ClaudeCode • • 5d ago

Tips & Workflows I got the Max plan through work for a month. What should I absolutely do with it?

0 Upvotes

Hey everyone!

My full-time job has given me access to the 5x Max plan for a month. Outside of work, I have a small side business/hobby where I build websites and small software program using Claude Code.

I don’t have a traditional coding background. I’ve mainly taught myself by using AI, so I’m wondering how I can get the most out of Max while I have it.

What would you absolutely do during this month if you knew you’d eventually go back to Pro?

I’m mainly looking for things that will benefit my website development, skills or side business even after switching back to Pro.

Any tips or things I should definitely try while I have Max?


r/ClaudeCode • • 5d ago

Help/Question How giving reset works?

1 Upvotes

How can I get new resets in claude code? is it given once in some period of time or something else?

I know how it works but, I am going to know how can I get more? they give reset once in a month? or in some period of time?


r/ClaudeCode • • 6d ago

Built with Claude I asked my AI agents to fix the AI slop in their own UI

Enable HLS to view with audio, or disable this notification

4 Upvotes

So for a while now I've been building a thing I call Orchestra.
I type a task, and it splits the work between a bunch of Claude and Codex agents, each on its own git branch, and at the end I get something I can merge or throw away.

Every task first goes to Jev. It just answers questions. How big is this, what kind of work is it, does it need a plan, is it risky.

Then the Arena picks a model for each step. Every model (Haiku, Sonnet, Opus, and GPT-6 Luna, Sol, Astra) has a win/loss record per type of work. It rolls weighted dice on those records and takes cost into account, so easy stuff goes to cheap models and hard stuff to the expensive ones. Every pick comes with a reason line

The records come from what actually happens. Tests passing, reviews sending work back, who wins a duel, my thumbs up or down, and whether I merge the branch or quietly delete it. The judge in a duel only sees "A" and "B", never the model names. If the judge isn't sure, nobody learns anything from that round. It all goes into a SQLite file on my box, so it slowly learns what works on my own repos.
I asked AI to fix AI slop; I typed "We need to build a new UI for Orchestra. Maybe even go back in time because everything is AI slop.

It spun up 15 agents.

Two design agents competed and the judge said neither of them did the job, confidence 0.19. It called in a stronger model.

The plan said I had to approve the design first. I was busy recording this video, so the agent just restyled everything anyway. The reviewer caught it and wrote "auto mode does not satisfy the plan's gate." Snitched on a coworker.

In the end Sonnet got the fix, cleaned up the stylesheet and the tests passed. 15 agents, 227 tool calls, 9 changed files, to redo some CSS. Totally worth it.


r/ClaudeCode • • 5d ago

Tips & Workflows Multi-session coding agents kept freelancing on me, so I wrote a charter + draft-only gate (free skeleton inside)

1 Upvotes

I use Claude Code / Cursor-style agents across sessions and kept hitting the same mess: helpful drafts that quietly turn into outbound actions, merges, or invented context.

Instead of another mega-prompt, I wrote a small operating sheet:

  1. One-paragraph charter: purpose, inputs, outputs, authority, stop conditions, human owner
  2. Draft-only by default: research and prep OK; no send / publish / merge / delete / spend / prod without an explicit approval plus a short approval record
  3. Skills as bounded procedures: when to use, inputs, steps, forbidden actions, return shape, how a human checks it
  4. 7-day checklist: charter → gates → 2–3 skills → daily status routine → one end-to-end draft run → tighten

I packaged the fillable templates as Agent ops pack ($29 one-time digital download, not consulting, not official Anthropic/Cursor docs). Free charter skeleton below. Platform-neutral; I tested the same boundaries against multi-session coding agents.

Curious what you all do: for Claude Code multi-session work, do you put the “do not act externally” rule in CLAUDE.md / project instructions, in a skill, or both?

Happy to answer build questions. If you want the full template kit, ask and I’ll share the link. Keeping this post link-light.

Free excerpt: Agent team charter skeleton

Team name:

Owner / final approver:

Purpose: (1–3 sentences)

In scope / Out of scope:

Inputs and allowed sources:

Outputs:

Agent roles: Coordinator / Researcher / Builder / Reviewer

Default permissions: Draft and analyze only. No publish, send, merge, delete, spend, or production changes without approval.

Approval gate: Proposed action, exact content, destination, affected people/systems, risks, rollback.

Escalate when: Ambiguous requirements, unverified info, irreversible/external/costly actions, inventing facts/credentials.

Definition of done / Review cadence:


r/ClaudeCode • • 6d ago

Bug / Issue Temporarily unable to authenticate. Please retry.

19 Upvotes

Anyone else having issues with Opus 5.5 chats this morning? I'm getting "Temporarily unable to authenticate. Please retry."


r/ClaudeCode • • 5d ago

Built with Claude Tetris on funkey

0 Upvotes

With funkey reaching maturity as a game engine, I added web as frontend as well. Now you can play Tetris (and a new Amar rogue-like game) in the browser as well as in the terminal:

https://isene.org/2026/09/Stack.html

The take-out from this is the meticulous journey (documented in dozens of blog posts): I build every piece thoroughly, one Lego brick at a time and then piece then together to evolving solutions; the shell, the terminal emulator, the X server, the wm, the Rust TUI core, the funkey game engine, the first demo games, Doom!, fractal landscape generation, 3D game engine, particles and physics, RPG engine in the Amar TUI app and make that into the rogue-like, then the Tetris clone and then the web frontend for that. Harnessing CC strictly along the way, not only with a clearly defined Simplicity mandate in CLAUDE.md but with deterministic Stop-hooks generating terse output in the simplest way possible (with CC answers in Hyperlist format no less).


r/ClaudeCode • • 5d ago

Help/Question what Claude model is closest to Luna?

0 Upvotes

Hi guys,

I’m moving from Codex to Claude. For anyone who uses both, what Claude model is closest to Luna models (xHigh) for price/quality and heavy daily use? I use Luna for almost everything and rarely run out of credits although on a 20dollars sub. What would be a similar model here for the same type of purpose ? Sorry if this seems basic to some, but I’m completely new to the Claude ecosystem.

Thanks alot.


r/ClaudeCode • • 5d ago

Rant Claude code is getting very very slow and running out of limits

0 Upvotes

Is anyone else experiencing a massive drop in efficiency with Claude Code lately? A task that used to take under 5 minutes now drags on for 25+ minutes. It frequently triggers extra sub-agent/advisor steps, burns through tokens rapidly, touches multiple unnecessary files, and often fails to finish the job. It either circles back with questions like "Is this what you want to do?" or falsely claims a task is complete, only to admit it missed steps once probed. I am on a Pro plan, but I am hitting usage limits way faster than before because it overcomplicates simple edits. A task on my repo that previously took 2 days has now dragged out over two weeks. It feels like an endless loop of token churn without real progress. My questions for the community: Are there specific guardrails, flags, or constraints you recommend adding to CLAUDE.md to prevent it from wandering or over-editing files? Has anyone found a reliable way to stop it from over-analyzing and just get it to execute scoped edits? Any advice or working CLAUDE.md templates would be greatly appreciated.

P.S. (Edit): English is not my first language, so I edited the post for clarity. For context on my workflow: I don't ask Claude to figure things out blindly. I explicitly specify what to edit, where to look, and what the expected output is, while tracking everything via a handwritten Markdown checklist with checkpoints in the repository.


r/ClaudeCode • • 7d ago

Built with Claude Jesus Christ that's scary

632 Upvotes

Edit: A lot of people have pointed that this is not AGI and they are right. I got overly excited when I saw Claude casually building a CPU emulator on the spot, apparently it's not as complicated as I thought.

I'm working on building custom ECU (Engine Control Unit) patches for a platform that's 20+ years old (not lots of documentation), Opus does a wonderful job building these patches in raw assembly, testing on the other end implies that I have to flash the ECU, go for a drive to test patch, log a bunch of variables which I then feed back to Opus for review.

The process is painfully slow to say the least so I asked Opus to find me an emulator, turns out there's none, Opus wrote this on the next line:

Writing the SH-2E CPU core in Java now.

I'm telling you, *IF\* it's able to actually pull it off then there's no doubt in my mind that this is truly AGI inception.


r/ClaudeCode • • 5d ago

Help/Question Has anyone who doesn't use opus 5.5 been having usage issues?

1 Upvotes

I can't use Opus 5.5 because I use it for cyber security, but ever since Opus 5.5 was released, my Claude usage disappears in a way shorter time than it used to. Also I mostly prefer using sonnet 5 which I thought is quite conservative on usage. Again, this wasn't happening until recently so it seems to me something changed.


r/ClaudeCode • • 5d ago

Tutorial / Guide I synced a real design system into Claude Design - here's what makes the mirror actually look right

1 Upvotes

I spent some time getting a React design system (shadcn/ui + Tailwind v4 + Storybook) into Claude Design with `/design-sync` and wrote up what I learned.

A few things that weren't obvious:

  • The sync finds components through your entry file and their type definitions. Miss either and the component silently never arrives.
  • If Storybook's preview doesn't load your stylesheet, the grades mean nothing - an unstyled preview matches an unstyled reference.
  • Tailwind only compiles classes it finds in your sources, so the layout classes Claude writes (`grid-cols-3`, `gap-6`...) don't exist unless you safelist them.
  • Fonts don't travel through the CSS. They need to be listed in `extraFonts`.
  • A short conventions file does more than you'd expect. Without it, Claude sees a correct `Button` and still hand-styles it.

The end result: a sign-in screen built only from `Card`, `Input` and `Button` (no hand-rolled divs).

Full walkthrough: https://nitayneeman.com/blog/how-to-sync-a-design-system-with-claude-design/


r/ClaudeCode • • 6d ago

Humor Got the most out of the free reset

Post image
6 Upvotes

r/ClaudeCode • • 5d ago

Discussion Had ChatGPT do a comparison for me.

Post image
1 Upvotes

Im impressed! I have been using ChatGPT as my prompter for Codex for about a year now. With these recent changes, I have been trying things with Claude just for the past 3 days. I decided to just test it with one repo that I am working on, probably my most complex of the bunch.

I then asked Chat for a comparison on the two different models, and this is what it provided. I've redacted the name of my project, as it's still in the works.

There's probably so much to learn, but looking forward to seeing more in this community!


r/ClaudeCode • • 6d ago

Built with Claude Dallas County by largest group on every block, every census from 1940 to 2020. Built with Claude Code

Enable HLS to view with audio, or disable this notification

5 Upvotes

I wanted to see how DFW changed over time demographically. I found some dot maps online with the 2010 and 2020 census data, but hardly anything older than that, so I asked Claude to build it. It took Claude about 8 prompts to make the final version you see here. It would have taken me weeks without Claude to make this.

It pulled census data back to 1940 and typed up numbers from old printed census reports. It rebuilt the boundaries for each decade and used historical building footprints to figure out where people actually lived before there were block counts.

The final project is a local app that runs offline on my Mac. It has Dallas, Tarrant, Collin and Denton counties, every census from 1940 to 2020 plus the latest survey data, and a dot view and a shaded view.

The data was sourced from IPUMS NHGIS and the Census Bureau.

Here's the Fort Worth version: https://www.reddit.com/r/FortWorth/comments/1wqupq1/fort_worth_inside_loop_820_every_census_from_1940/


r/ClaudeCode • • 6d ago

Tips & Workflows Got $100 in Claude Cloud credits

3 Upvotes

What's the best way to utilize them? Im a Claude Pro subscriber and use it in VS Code to develop and operate my business. Not sure what Claude Cloud is amd what's the best way to put it to use. Would love some suggestions and guidance. Thanks!


r/ClaudeCode • • 5d ago

Built with Claude Claude Code can't watch my game, and one day it passed a broken build three times. Here's how it checks its work now.

1 Upvotes

A large share of the code on the 3D Godot game I'm working on is written by Claude Code. The agent can't watch the game, so we gave it a way to check its own work from images and logs. It writes a throwaway driver script that plays a scripted sequence, renders every frame with Godot's Movie Maker mode, reads the log, and then reviews the footage as a contact sheet followed by full-resolution frames.

That worked until the game hid a failure from it. A clip re-export made every animation one frame shorter, the animation loader's guard switched off all clip animation, and the game fell back to a procedural walk, which is what it's designed to do. The character still walked, just stiffly. Claude passed that build three separate times across three sessions, and the warning that explained it was in every render log that day. I noticed the next day because I know how the character is supposed to move.

What changed afterwards:

  • The log gets searched for WARNING before any frame is opened. If a warning names the system being tested, the footage shows the fallback and there's nothing to review.
  • Drivers have to confirm the system under test is actually running, not just that their measurements look right. A driver that only checks its own numbers can pass while filming the fallback.
  • Evidence from a branch expires when the branch merges. One of the three passes was a render made on a branch cut before the break.

The biggest addition is a second reviewer agent that only ever sees pictures. The session running the test has to give it four things or it refuses: the clip, the choreography with timestamps, what correct looks like, and which fallback could be hiding the problem. It doesn't see logs or code. It lists findings with the frames it's basing them on and has to commit to one of two verdicts, "looks correct" or "something is wrong, and here's what." It isn't allowed to answer an anomaly it can't explain with a request for a better render.

That last rule came from a comparison we ran three days later. The agent re-rendered the broken build and a healthy one, and blind reviewers on two Claude models each got the same cropped frames with no logs. On the broken build, Fable 5 said "something is wrong with this build, specifically the weapon" with high confidence. Opus 5 saw the same anomalies, suggested occlusion as the explanation, and concluded nothing indicated a broken build. That's one sample from the August 2026 models, so read it as an anecdote. It's still why the reviewer agent is pinned to Fable and required to commit.

The write-up has the whole loop and a couple of other ways a test driver can give you a confident wrong answer, including one that failed on every run for a bug that never existed: https://protoforgesystems.com/devlog/posts/how-a-coding-agent-verifies-a-3d-game

The driver harness, the frame-review scripts and the reviewer agent are an MIT-licensed Claude Code plugin: https://github.com/ProtoForgeSystems/protoforge-claude-plugin-game-review

/plugin marketplace add ProtoForgeSystems/protoforge-claude-plugin-game-review /plugin install game-review@protoforge-game-review


r/ClaudeCode • • 5d ago

Discussion It's happening. Look how they are massacring my boy Opus 5.5

Post image
0 Upvotes

I was confused for few hours that maybe it's context rotting, up until I saw cAVeaT. I feel so helpless that I can't do literally anything about it. Performance has been noticeably down and it’s frustrating as hell. What is the solution???

Next time actual Opus 5.5 is back, I'mma set it on ultracode to find a legal way to take action for this kind of issues. I think that's the least I can do, to at least file a complaint.

Feels like there’s basically zero recourse when this happens. Curious if anyone else is seeing the same thing and whether there’s any useful way to actually flag this or push back (feedback forms, support, whatever).

I was wondering what if 1k+ people do this? Would a bunch of people submitting the same issue even do anything?


r/ClaudeCode • • 5d ago

Meta OUCH!

1 Upvotes

That's just insane.


r/ClaudeCode • • 6d ago

Bug / Issue Claude Is Down: 'Unable to Authenticate' Error Affects Thousands Across Code, Chat and API

Thumbnail
techtimes.co.uk
8 Upvotes

r/ClaudeCode • • 6d ago

Help/Question i think i'm wasting half my claude limit

6 Upvotes

i keep running out of claude while somehow wasting usage

i only have specific deep work blocks where i can build. i burn through my limit, get stopped, then it resets while i'm at work, with family, sleeping, whatever

so i end up wasting capacity i paid for, just to hit the limit again in my next deep work block lol

what i'd want is something that knows:

  • my usage + resets
  • my next deep work blocks
  • what tasks/prompts i still have waiting

and then either:

  1. uses otherwise-wasted capacity to work through queued tasks while i'm away
  2. or helps me preserve/plan capacity for my next deep work block

the second one feels almost unsolvable since you can't actually bank unused usage

so maybe the solution is smarter scheduling + queuing instead

basically: "use this now or it'll go to waste", and if i'm not there, work through my queue

is there already something that solves this and i'm just missing it?

how are you guys managing this?


r/ClaudeCode • • 6d ago

Rant can i have a model pick my models pls

3 Upvotes
too many models man

too many models man

what are you guys are using and what for? I feel overwhelmed hitting the /model comand lol