backend-development

Fail

Audited by Socket on Feb 23, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The document is a legitimate Supabase backend workflow guide but contains high-risk operational guidance: it explicitly instructs developers to persist real secrets in a seed SQL file (risking plaintext credentials in repo/disk) and broadly recommends creating elevated DB constructs (extensions and SECURITY DEFINER functions) without enforcing narrow scoping or audit practices. There is no direct evidence of malware or obfuscated malicious code in the provided text; the primary concerns are insecure secret management and privilege escalation patterns that could be abused if followed carelessly. Recommendations: remove or clearly warn against persisting plaintext secrets in seed files, require use of environment/CI secret stores or encrypted Vault-only flows, mandate code review and least-privilege for SECURITY DEFINER functions, and audit any provided shell scripts before execution.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 23, 2026, 06:03 AM
Package URL
pkg:socket/skills-sh/tomaspozo%2Fskills%2Fbackend-development%2F@40f1a19049ed69c9c9420106d108f9ca2585fcbd