File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:45
Security audit
Security checks across malware telemetry and agentic risk
This is a disclosed Supabase magic-link helper with expected auth-token handling, but it must be installed carefully because it involves login links and a server-only service-role key.
Install this only for a Supabase portal magic-link flow. Keep the service-role key strictly on a trusted backend, protect and rate-limit the link-generation endpoint, audit link requests, and place the redirect/portal snippets before analytics or third-party scripts so auth tokens are handled and removed promptly.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal