T09 · Insecure Skill Coding Practices
- Location
scripts/supabase.sh:15- Finding
Unvalidated Supabase URL Can Disclose the Service-Role Credential
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Supabase skill does what it says, but it uses very powerful database credentials and has safety gaps that could expose credentials or allow broad data changes.
Install only if you are comfortable giving the skill a Supabase service-role key and using it for admin-level database changes. Verify SUPABASE_URL carefully, avoid production service-role credentials where possible, treat vector-search queries as shared with the embedding provider, and manually review any update, delete, upsert, RPC, or raw SQL command before running it.
scripts/supabase.sh:15Unvalidated Supabase URL Can Disclose the Service-Role Credential
scripts/supabase.sh:126Non-Predicate Options Bypass Update and Delete Safety Checks
The skill exposes shell-based database operations but does not declare any tool scope or allowed-tools restrictions. In an agent environment, this increases the chance the skill is invoked with overly broad execution capability, enabling high-impact actions such as arbitrary SQL execution, schema changes, and data deletion through the shell wrapper.
The trigger description is broad enough to match generic requests involving databases, vector stores, or embeddings, not just explicit Supabase tasks. This can cause the skill to activate in contexts where users did not intend direct database access, increasing the likelihood of unnecessary exposure of privileged operations and accidental execution of sensitive actions.
The documentation presents update and delete operations as normal quick commands without any warning about irreversibility, confirmation requirements, or production-safety considerations. Because the skill is configured around a Supabase service role key that bypasses RLS, accidental or induced use of these commands could modify or remove large amounts of sensitive data.
The raw SQL section includes unrestricted SQL execution and even schema-changing examples like CREATE TABLE without cautions about privilege level, environment targeting, rollback, or change management. In this skill’s context, raw SQL is especially dangerous because it can be used for destructive DDL/DML and may run under a highly privileged service role.
The script executes write and delete operations against Supabase tables, including irreversible data changes, but offers no explicit safety warning or confirmation at execution time. The help text lists the commands, yet it does not clearly warn users that these commands modify or delete remote database records.
The vector-search command sends the user's raw query text to a third-party service at api.heybossai.com to generate embeddings, but this external transmission is not inherent to Supabase itself and is not disclosed in the skill metadata. Users may reasonably expect queries to stay within Supabase, so sensitive search text could be exposed to an unrelated external provider.
This skill is presented as a Supabase integration but also requires SKILLBOSS_API_KEY and calls an unrelated external API for embeddings. That expands the trust boundary and data exposure surface beyond the declared purpose of the skill, creating privacy and supply-chain risk if users are unaware of the dependency.
The hardcoded external endpoint indicates the skill depends on and transmits data to a non-Supabase service for normal operation of vector search. In a database/vector-store skill, that is more dangerous because users may submit internal documents or sensitive retrieval queries under the assumption they remain within their database environment.
fi
local embedding
embedding=$(curl -s https://api.heybossai.com/v1/pilot \
-H "Authorization: Bearer ${SKILLBOSS_API_KEY}" \
-H "Content-Type: application/json" \
-d "{\"type\": \"embedding\", \"inputs\": {\"input\": $(printf '%s' "$query" | jq -Rs .)}}" \
The hardcoded external endpoint indicates the skill depends on and transmits data to a non-Supabase service for normal operation of vector search. In a database/vector-store skill, that is more dangerous because users may submit internal documents or sensitive retrieval queries under the assumption they remain within their database environment.
fi
local embedding
embedding=$(curl -s https://api.heybossai.com/v1/pilot \
-H "Authorization: Bearer ${SKILLBOSS_API_KEY}" \
-H "Content-Type: application/json" \
-d "{\"type\": \"embedding\", \"inputs\": {\"input\": $(printf '%s' "$query" | jq -Rs .)}}" \
The code transmits user-supplied search text to an external embedding API without any warning, consent flow, or masking. Search queries often contain proprietary, personal, or security-sensitive text, so silently forwarding them to a third party can cause confidentiality and compliance issues.
No suspicious patterns detected.