supabase-automation

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly match its stated Supabase automation purpose, and the MCP endpoint appears to be an official Composio/Rube service rather than a random installer. However, it routes sensitive Supabase administration through a third-party intermediary, includes high-privilege actions like arbitrary SQL and API key retrieval, and its setup claim understates the real auth/trust model. This is not confirmed malware, but it carries meaningful security risk and should be treated as a high-trust admin integration.

Confidence: 85%Severity: 61%
Audit Metadata
Analyzed At
Mar 17, 2026, 05:58 AM
Package URL
pkg:socket/skills-sh/diegosouzapw%2Fawesome-omni-skill%2Fsupabase-automation%2F@aa7dbe5efb361de25951c34c1929764387b4d061