Supabase MCP Server

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is plausible and Supabase-aligned, but the trust chain is inconsistent. The skill claims a Supabase source while distribution occurs through a third-party skill marketplace/repo and a transitive installer, so users may forward Supabase credentials to code not clearly published by Supabase. No direct malicious behavior is shown, but install provenance and credential trust are not fully coherent.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Mar 29, 2026, 04:36 AM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Fsupabase-mcp-server%2F@9089288f5e32e5fdac160e908d21c31e2e0dd2a5