supabase

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core behavior is coherent with its stated function, but it is not a direct Supabase integration. It requires users to trust Membrane as an intermediary for authentication, credential handling, and all Supabase API traffic, which is a meaningful scope and data-flow expansion. The npm-based CLI source appears vendor-consistent and not overtly malicious, but the mutable `latest` install and third-party credential/API mediation raise medium security concerns.

Confidence: 86%Severity: 57%
Audit Metadata
Analyzed At
May 1, 2026, 09:24 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsupabase%2F@ccaed35ab9f2247742a64fe0483b709b31dab98b