codex-supabase

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's goal matches Supabase connectivity, but it uses a less-official local MCP package flow and forwards a Supabase API key to external code via command line. This is not clearly malicious, but the install path and credential handling are riskier than necessary for the stated purpose.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 03:36 AM
Package URL
pkg:socket/skills-sh/mathruffian-dot%2Fcodex-lazy-packs%2Fcodex-supabase%2F@f64e7c529bb7a6314f3624574de93398af9ea5fb76367268a77486d6307fb1de
Security Audit — socket — codex-supabase