supabase-workflow

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the core Supabase CLI usage is coherent and mostly benign, but the skill expands its footprint with project-specific SQL wrappers and instructs disabling JWT verification for edge functions. The main risk is not malware-like behavior; it is weakened security controls plus direct remote database/function actions without explicit approval boundaries.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 09:08 PM
Package URL
pkg:socket/skills-sh/sourman%2Fskills%2Fsupabase-workflow%2F@7d601462ee56c0c589b67458b6a7489c379d500d