NYC

supabase-audit-buckets-read

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Functionally, the skill is a legitimate read-only storage auditing tool that effectively identifies exposed files and secrets in Supabase buckets. It does not contain code that exfiltrates data to external third parties or obfuscated malware. The main security concern is operational: the mandatory progressive persistence and encouragement to download full backups and secret files to local disk significantly increase the risk that sensitive data will be retained, leaked, or mishandled on the operator's host. Recommend adding explicit safeguards: require operator confirmation before downloading large or high-severity files, recommend encrypted evidence storage (or ephemeral in-memory sampling and redaction), enforce minimal sampling (not full downloads) unless pre-authorized, include secure deletion guidance, and clearly separate remediation SQL examples from any read-only execution context.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:15 PM
Package URL
pkg:socket/skills-sh/yoanbernabeu%2Fsupabase-pentest-skills%2Fsupabase-audit-buckets-read%2F@8637d32de607c5ec2195dc38cb8e3bfc6399c5cb