Supabase MCP Server for Database and Project Management

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated Supabase purpose is plausible, but the actual distribution path is a third-party skill installer and registry rather than an official Supabase channel. The main issue is supply-chain and transitive-install trust mismatch, not confirmed malware or explicit exfiltration in this snippet.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Mar 29, 2026, 04:37 AM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Fsupabase-mcp-server-for-database-and-project-management%2F@f70a1fd6d3431ceace02c16b6e8a8c613ac125ea