supabase-detect
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s behavior is mostly aligned with its stated purpose and uses official Supabase endpoint patterns, with no external installer or unverifiable binary. However, it is explicitly part of a pentest/audit chain, encourages follow-on key extraction skills, and includes an example that sends an API key to a discovered/custom endpoint; this is proportionate to the stated purpose but still creates meaningful security risk. The unverified supabase-cdn.com pattern slightly weakens data-flow trust, but there is no clear credential exfiltration to unrelated third parties in this skill alone.
Confidence: 87%Severity: 58%
Audit Metadata