Combine Skills and MCP to Close the Context Gap — Pedro Rodrigues, Supabase
Skills:
Agent Foundations90%
Agents working with Postgres will confidently create a view over a table with row-level security enabled and silently bypass that security in the process. Not because they can't reason. Because they don't know about the security_invoker flag, and nobody told them. Pedro Rodrigues from Supabase ran this exact test: same agent, same task, MCP alone versus MCP plus a skill. The one without the skill shipped a query that exposed data it shouldn't have.
The talk covers what Supabase learned building their agent skill from scratch: critical security rules go directly in skill.md because agents will reliably skip reference files, skills should point to living documentation rather than duplicate it, and opinionated workflow guidance matters more than comprehensive coverage. Their evals ran across Claude and GPT models in three conditions and the result was unanimous. Skills without MCP underperform. MCP without skills misses environment-specific constraints. Together they close the gap that makes agents unreliable on real production systems.
Speaker info:
- https://x.com/rodriguespn23
- https://www.linkedin.com/in/pedro-neves-rodrigues/
- https://github.com/Rodriguespn
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
More on: Agent Foundations
View skill →Related AI Lessons
⚡
⚡
⚡
⚡
The Context Layer: Why Enterprise AI Agents Fail Without It — and What It Actually Takes to Fix That
Dev.to · Swapnil Chougule
Comparing 6 AI Routers Is a Mistake — Until You Define ‘Survived’
Medium · AI
Comparing 6 AI Routers Is a Mistake — Until You Define ‘Survived’
Medium · Programming
What if an AI continued thinking even after you closed the chat?
Dev.to · Stell
🎓
Tutor Explanation
DeepCamp AI