result-supabase-reporter

Fail

Audited by Snyk on Mar 1, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). This skill explicitly reads local "capture_results" data and uploads it to an external Supabase instance using a service-role key (ENV: SUPABASE_SERVICE_ROLE_KEY), which is an intentional data-exfiltration capability that can leak sensitive app/device/user data or credentials if misused.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 1, 2026, 11:01 PM