## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Bug fix (build resilience)
## What is the current behavior?
`apps/www/scripts/fetchAgentSkills.mjs` runs as part of `content:build`
and fails the whole `www` build (and `pnpm dev:www`) whenever the GitHub
API call fails. #50106 added `AGENT_SKILLS_GITHUB_TOKEN` to mitigate
rate limits on Vercel, but that does not cover local runs or builds
where the env var is not available (e.g. fork PRs).
Example from a local `pnpm dev:www` hitting the unauthenticated rate
limit:
```
www:dev: Error: GET https://api.github.com/repos/supabase/agent-skills/releases/latest → 403
www:dev: at fetchJson (file:///.../apps/www/scripts/fetchAgentSkills.mjs:38:22)
www:dev: at process.processTicksAndRejections (node:internal/process/task_queues:105:5)
www:dev: at async main (file:///.../apps/www/scripts/fetchAgentSkills.mjs:53:19)
```
## What is the new behavior?
`public/.well-known/agent-skills/index.json` is already committed to the
repo, so when the fetch fails and `VERCEL_ENV` is not `production`, the
script logs the error, keeps the committed file, and exits 0:
```
www:dev: Error: GET https://api.github.com/repos/supabase/agent-skills/releases/latest → 403
www:dev: ...
www:dev: Fetch failed — keeping committed public/.well-known/agent-skills/index.json
```
Production builds still fail loudly so a stale skills list is never
silently shipped.
Verified locally by forcing a 401 with a bad token:
- `VERCEL_ENV=preview` exits 0 and keeps the committed `index.json`
- `VERCEL_ENV=production` exits 1
## Additional context
Follow-up to #50106.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Bug Fixes**
* Improved handling of skill data fetch failures outside production.
* Preserves previously available skill data when a fetch fails and a
committed fallback is available.
* Continues to report failures when no fallback data exists.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Context
As per PR title - just a nice to have as our `www` preview builds
occasionally fail, likely due to rate limits on the GH API
Env var `AGENT_SKILLS_GITHUB_TOKEN` has been added to the `www` app on
Vercel
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Chores**
* Added optional GitHub authentication support for retrieving agent
skills.
* Preserved existing request behavior when no authentication token is
provided.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Summary
- Adds `apps/www/scripts/fetchAgentSkills.mjs` — at build time (`pnpm
content:build`) fetches the latest `index.json` from
`supabase/agent-skills` release assets and writes it verbatim to
`public/.well-known/agent-skills/index.json`
- Skill URLs are absolute GitHub Release asset URLs, embedded by the
agent-skills repo at release time (supabase/agent-skills#87) — no URL
rewriting needed on this side
## How it works
1. Fetches latest release from `supabase/agent-skills` via GitHub API
2. Downloads `index.json` from the release assets
3. Writes it verbatim to `public/.well-known/agent-skills/index.json`
Clients discover and install skills from
`supabase.com/.well-known/agent-skills/index.json` and fetch tarballs
directly from GitHub Release assets.
## Dependency
Requires supabase/agent-skills#87 to be merged and released so the
published `index.json` contains absolute URLs.
---------
Co-authored-by: Pedro Rodrigues <44656907+Rodriguespn@users.noreply.github.com>
Co-authored-by: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Pedro Rodrigues <pedro.rodrigues@supabase.io>