supabase-detect

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s behavior is mostly aligned with its stated purpose and uses official Supabase endpoint patterns, with no external installer or unverifiable binary. However, it is explicitly part of a pentest/audit chain, encourages follow-on key extraction skills, and includes an example that sends an API key to a discovered/custom endpoint; this is proportionate to the stated purpose but still creates meaningful security risk. The unverified supabase-cdn.com pattern slightly weakens data-flow trust, but there is no clear credential exfiltration to unrelated third parties in this skill alone.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Sep 14, 2026, 06:43 PM
Package URL
pkg:socket/skills-sh/yoanbernabeu%2Fsupabase-pentest-skills%2Fsupabase-detect%2F@58fa4bc78b0f03df7f3f1877ee3d6e3bb82997bc5ab84fbd6734fd0efe12bd8e
Security Audit — socket — supabase-detect