supabase-pentest-skills
24 AI Agent Skills for professional security auditing of Supabase applications. Detection, key extraction, RLS testing, storage audit, IDOR detection, and comprehensive reporting. Works with Claude Code, Cursor, Windsurf, and 30+ AI agents.
220
安装命令
npx skhub add --skillset @yoanbernabeu/supabase-pentest-skills包含的技能
Identify storage buckets that are publicly accessible and may contain sensitive data.
00
Attempt to list and read files from storage buckets to verify access controls.
00
Discover and test Supabase Edge Functions for security vulnerabilities and misconfigurations.
00
Test Supabase Realtime WebSocket channels for unauthorized subscriptions and data exposure.
00
Test Row Level Security (RLS) policies for common bypass vulnerabilities and misconfigurations.
00
List and test exposed PostgreSQL RPC functions for security issues and potential RLS bypass.
00
List all tables exposed via the Supabase PostgREST API to identify the attack surface.
00
Attempt to read data from exposed tables to verify actual data exposure and RLS effectiveness.
00
Detect if a web application uses Supabase by analyzing client-side code, network patterns, and API endpoints.
00
Extract the Supabase anon/public API key from client-side code. This key is expected in client apps but important for RLS testing.
00
CRITICAL - Detect exposed PostgreSQL database connection strings in client-side code. Direct DB access is a P0 issue.
00
Extract and decode Supabase-related JWTs from client-side code, cookies, and local storage patterns.
00
CRITICAL - Detect if the Supabase service_role key is leaked in client-side code. This is a P0 severity issue.
00
Extract the Supabase project URL from client-side JavaScript code, environment variables, and configuration files.
00
Quick reference for all Supabase security audit skills with usage examples and command overview.
00
Orchestrate a complete Supabase security audit with guided step-by-step execution and ownership confirmation.
00
Generate a comprehensive Markdown security audit report with executive summary, findings, and remediation guidance.
00
Compare two security audit reports to track remediation progress and identify new vulnerabilities.
00
Analyze Supabase authentication configuration for security weaknesses and misconfigurations.
00
Test if user signup is open and identify potential abuse vectors in the registration process.
00
Test for user enumeration vulnerabilities through various authentication endpoints.
00
List all storage buckets and their configuration to identify the storage attack surface.
00