pp-supabase

Warn

Audited by Socket on Jun 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s Supabase-focused capabilities mostly match its purpose, but it requires trust in a custom third-party CLI that handles privileged Supabase credentials and can route results to arbitrary webhooks. The main concern is install/provenance trust plus outbound delivery features, not obvious hidden malware behavior.

Confidence: 81%Severity: 68%
Audit Metadata
Analyzed At
Jun 23, 2026, 05:10 AM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-supabase%2F@8ba369e0369832d22fe66c2df02cbf6f6b42de8c82b5e22b0e0b7c46d725d02c
Security Audit — socket — pp-supabase