supabase-automation

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose matches its Supabase admin capabilities, but its trust model is weak: it routes sensitive credentials and high-impact operations through a third-party hosted MCP/Composio layer rather than official direct Supabase tooling. Broad admin scope plus access to live API keys and arbitrary SQL make the overall risk high even without confirmed malicious behavior.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Apr 14, 2026, 07:01 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fsupabase-automation%2F@e29c2be7a8a2dad5ace68b15c343171c59f59361