supabase-gen

Fail

Audited by Socket on Feb 18, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
src/index.ts

This module is a helper to generate RLS SQL by sending local source files to the OpenAI Chat Completions API. There is no clear evidence of intentional malicious behavior (no backdoor or obfuscated malware). The primary security concern is inadvertent data exfiltration: raw file contents (which can include secrets) are transmitted to an external service without redaction, confirmation, or validation. Additionally, a coding bug prevents correct concatenation of directory files. Recommend fixing the map-return bug, adding explicit secret scrubbing and size/type checks, requiring user consent for sending sensitive files, and adding robust error handling before using in sensitive environments.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 18, 2026, 01:00 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fsupabase-gen%2F@1367d78c127cf15a001b5b5baa49b7ec55b77f38