Back to skill

Security audit

Supabase

Security checks for vulnerabilities and agentic risk

Overview

This Supabase skill is mostly purpose-aligned, but it grants full database authority and has incomplete safeguards around destructive operations and external embedding calls.

Review before installing. Use this only for projects where the agent is allowed full database access, prefer a restricted credential or isolated project when possible, double-check every update/delete/raw SQL request, and avoid vector-search queries containing sensitive text unless sending that text to OpenAI is acceptable.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/supabase.sh:165
Finding

Update and delete safeguards accept non-predicate options

Content
View full analysis
&2 exit 1 fi local url="${REST_URL}/${table}?${filters:1}" api_request PATCH "$url" "$data" | jq . ``` ```bash local filters filters=$(build_filters "$@") if [[ -z "$filters" ]]; then echo "Error: At least one filter required for delete (use --eq)" >&2 exit 1 fi local url="${REST_URL}/${table}?${filters:1}" api_request DELETE "$url" | jq . ``` ### Technical Analysis The update and delete protections only verify that the complete query-string fragment returned by `build_filters` is nonempty. They do not verify that the arguments include an actual row-selection predicate. Non-predicate options such as `--limit` generate a nonempty string and therefore satisfy the safety check. Ordering can also contribute query-string content when combined with applicable options. Consequently, the error message claims that a filter such as `--eq` is required, but the implementation does not enforce that requirement. Because every request is authenticated with `SUPABASE_SERVICE_KEY`, these mutations execute with a service-role credential that normally bypasses Supabase Row Level Security. The failure is therefore more consequential than the same validation flaw under an unprivileged credential. ### Attack Path 1. An attacker influences a natural-language database request, automation input, or arguments passed to ...[truncated 1013 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/supabase.sh:124
Finding

Unencoded URL components allow PostgREST request manipulation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/supabase.sh:15
Finding

Unvalidated Supabase URL can disclose the service-role credential

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill’s declared behavior does not fully match its effective capabilities: it implies storage management that is not present, while also introducing optional external access to OpenAI for embeddings. This mismatch can cause operators or downstream agents to route sensitive data into an undeclared third-party API, creating data exfiltration and trust-boundary risks, especially in a database skill that may handle confidential records.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill exposes shell-based capabilities but does not declare any tool scope or allowed-tools boundaries, making it harder for the agent platform to enforce least privilege. Because the documented commands support arbitrary SQL, table modification, and deletion using a Supabase service role key, undeclared shell access increases the chance of unsafe invocation and privilege misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger conditions are broad enough to match many generic database, vector, embeddings, or Supabase-related requests, which can cause the skill to activate in contexts where high-privilege database operations are unnecessary. In this skill, that matters more because it is configured around a Supabase service key that bypasses RLS and supports raw SQL and destructive actions, increasing the blast radius of accidental or overly eager invocation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The vector-search command transmits the user's query text to OpenAI to generate embeddings, which expands the skill's behavior beyond a Supabase-only integration and introduces third-party data egress. This is risky because database/vector-search queries may contain sensitive business data, secrets, or personal information that users would reasonably expect to stay within Supabase.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

User-supplied vector-search text is sent to OpenAI without any user-facing warning, confirmation, or disclosure in the command behavior. In a database/search skill, users may pass proprietary documents, internal search terms, or personal data, making silent third-party transmission a meaningful privacy and compliance risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script requires and uses an unrelated third-party credential, OPENAI_API_KEY, despite being presented as a Supabase skill. This broadens the credential scope of the skill and increases the chance of unintended cross-service access, data leakage, and operator misunderstanding about what secrets are needed and how they are used.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The hardcoded external endpoint https://api.openai.com/ confirms that vector-search depends on a third-party service outside Supabase. In this skill context, that makes the behavior more dangerous because operators may assume a database connector keeps data within the Supabase environment, while this implementation silently exports query content elsewhere.

Content

Scanner excerpt · scripts/supabase.sh (reported line 362)May include surrounding context.

sh
fi
    
    local embedding
    embedding=$(curl -s https://api.openai.com/v1/embeddings \
        -H "Authorization: Bearer ${OPENAI_API_KEY}" \
        -H "Content-Type: application/json" \
        -d "{\"input\": $(printf '%s' "$query" | jq -Rs .), \"model\": \"text-embedding-ada-002\"}" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The hardcoded external endpoint https://api.openai.com/ confirms that vector-search depends on a third-party service outside Supabase. In this skill context, that makes the behavior more dangerous because operators may assume a database connector keeps data within the Supabase environment, while this implementation silently exports query content elsewhere.

Content

Scanner excerpt · scripts/supabase.sh (reported line 362)May include surrounding context.

sh
fi
    
    local embedding
    embedding=$(curl -s https://api.openai.com/v1/embeddings \
        -H "Authorization: Bearer ${OPENAI_API_KEY}" \
        -H "Content-Type: application/json" \
        -d "{\"input\": $(printf '%s' "$query" | jq -Rs .), \"model\": \"text-embedding-ada-002\"}" \

Static analysis

No suspicious patterns detected.