supabase-extract-url
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). This skill fetches and parses client-side JavaScript/HTML from arbitrary public websites (e.g., "Extract Supabase URL from https://myapp.example.com") and even probes REST API endpoints for validation, meaning it ingests and interprets untrusted third‑party content that could contain injected instructions.
Audit Metadata