Credential Access
- Category
- Privilege Escalation
- Confidence
- 79% confidence
- Finding
The skill requires a high-privilege Supabase access token and performs authenticated remote configuration writes. Even though it documents careful handling, any skill that consumes such a credential and can send network requests to a management API creates a meaningful credential-exposure and misuse surface if the agent runtime, prompts, or surrounding tooling are compromised.
- Content
md | Item | What this skill needs | |---|---| | Credentials | `SUPABASE_ACCESS_TOKEN`: a personal access token (`sbp_…`) from the dashboard, or a fine-grained token with `auth_config_write` + `project_admin_write`. Env var only. The script sends it in a header, in-process: never in argv, never printed, never written to disk. | | Network out | `https://api.supabase.com` only. `--api-base` accepts nothing else except an `http://` loopback address (test servers). | | Writes | **Remote Auth configuration** via `PATCH /v1/projects/<ref>/config/auth`, only with `--apply`. Without it, every write command is a dry run. Nothing else is written, locally or remotely. | | Data persisted | None. `show` prints to stdout with secret-looking string fields (`*secret*`, `smtp_pass`, `*_key`, `*auth_token*`) replaced by `<redacted>`. |
