supabase-pentest

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK but not malware. The skill is internally consistent with a Supabase pentest orchestrator and uses local evidence storage plus explicit authorization language, but it equips an AI agent with offensive security capabilities and some state-changing actions against external targets. No malicious exfiltration or suspicious installer path is present in the provided text; the main risk is the pentesting capability itself and reliance on unreviewed companion sub-skills.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Sep 15, 2026, 12:46 PM
Package URL
pkg:socket/skills-sh/yoanbernabeu%2Fsupabase-pentest-skills%2Fsupabase-pentest%2F@413295a0342aafc7061ca1a444605a74ddb796d13d992b842807b5a1e7611f92
Security Audit — socket — supabase-pentest