security-supabase

Warn

Audited by Socket on Feb 12, 2026

1 alert found:

Anomaly
AnomalyLOW
references/rls-security-definer.md

This document contains safe, non-obfuscated guidance and intentionally insecure examples to illustrate the dangerous behavior of SECURITY DEFINER functions with respect to RLS. The insecure example demonstrates a real supply-chain-like risk in database code: SECURITY DEFINER functions owned by a superuser can act as hidden backdoors bypassing RLS, enabling data exfiltration or unauthorized modifications. The file itself is not malicious code but documents a high-risk pattern; follow the recommended mitigations (use SECURITY INVOKER by default, restrict EXECUTE, set search_path) and audit existing functions.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Feb 12, 2026, 06:52 PM
Package URL
pkg:socket/skills-sh/elliottrjacobs%2Fbench-skills%2Fsecurity-supabase%2F@df396a6884ea512a0372aca16efe5341012e3775