supabase-workflow

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This is an operations/workflow document for Supabase tasks that does not contain obvious malware or obfuscated code. The primary security concerns are operational misconfigurations and information exposure: a blanket recommendation to disable JWT verification for edge functions (high-risk), inclusion of a Supabase project ref (information leak), and use of local wrappers whose behavior is not shown (unknown risk). Recommend removing/justifying insecure defaults, auditing local wrappers, and adding cautious guidance for destructive commands and migration repair usage.

Confidence: 75%Severity: 55%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:25 PM
Package URL
pkg:socket/skills-sh/sourman%2Fskills%2Fsupabase-workflow%2F@7d601462ee56c0c589b67458b6a7489c379d500d