Back to skill

Security audit

database

Security checks for vulnerabilities and agentic risk

Overview

This Supabase skill does what it says, but it uses very powerful database credentials and has safety gaps that could expose credentials or allow broad data changes.

Install only if you are comfortable giving the skill a Supabase service-role key and using it for admin-level database changes. Verify SUPABASE_URL carefully, avoid production service-role credentials where possible, treat vector-search queries as shared with the embedding provider, and manually review any update, delete, upsert, RPC, or raw SQL command before running it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/supabase.sh:15
Finding

Unvalidated Supabase URL Can Disclose the Service-Role Credential

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/supabase.sh:126
Finding

Non-Predicate Options Bypass Update and Delete Safety Checks

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill exposes shell-based database operations but does not declare any tool scope or allowed-tools restrictions. In an agent environment, this increases the chance the skill is invoked with overly broad execution capability, enabling high-impact actions such as arbitrary SQL execution, schema changes, and data deletion through the shell wrapper.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger description is broad enough to match generic requests involving databases, vector stores, or embeddings, not just explicit Supabase tasks. This can cause the skill to activate in contexts where users did not intend direct database access, increasing the likelihood of unnecessary exposure of privileged operations and accidental execution of sensitive actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation presents update and delete operations as normal quick commands without any warning about irreversibility, confirmation requirements, or production-safety considerations. Because the skill is configured around a Supabase service role key that bypasses RLS, accidental or induced use of these commands could modify or remove large amounts of sensitive data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The raw SQL section includes unrestricted SQL execution and even schema-changing examples like CREATE TABLE without cautions about privilege level, environment targeting, rollback, or change management. In this skill’s context, raw SQL is especially dangerous because it can be used for destructive DDL/DML and may run under a highly privileged service role.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script executes write and delete operations against Supabase tables, including irreversible data changes, but offers no explicit safety warning or confirmation at execution time. The help text lists the commands, yet it does not clearly warn users that these commands modify or delete remote database records.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The vector-search command sends the user's raw query text to a third-party service at api.heybossai.com to generate embeddings, but this external transmission is not inherent to Supabase itself and is not disclosed in the skill metadata. Users may reasonably expect queries to stay within Supabase, so sensitive search text could be exposed to an unrelated external provider.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This skill is presented as a Supabase integration but also requires SKILLBOSS_API_KEY and calls an unrelated external API for embeddings. That expands the trust boundary and data exposure surface beyond the declared purpose of the skill, creating privacy and supply-chain risk if users are unaware of the dependency.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The hardcoded external endpoint indicates the skill depends on and transmits data to a non-Supabase service for normal operation of vector search. In a database/vector-store skill, that is more dangerous because users may submit internal documents or sensitive retrieval queries under the assumption they remain within their database environment.

Content

Scanner excerpt · scripts/supabase.sh (reported line 362)May include surrounding context.

sh
fi

    local embedding
    embedding=$(curl -s https://api.heybossai.com/v1/pilot \
        -H "Authorization: Bearer ${SKILLBOSS_API_KEY}" \
        -H "Content-Type: application/json" \
        -d "{\"type\": \"embedding\", \"inputs\": {\"input\": $(printf '%s' "$query" | jq -Rs .)}}" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The hardcoded external endpoint indicates the skill depends on and transmits data to a non-Supabase service for normal operation of vector search. In a database/vector-store skill, that is more dangerous because users may submit internal documents or sensitive retrieval queries under the assumption they remain within their database environment.

Content

Scanner excerpt · scripts/supabase.sh (reported line 362)May include surrounding context.

sh
fi

    local embedding
    embedding=$(curl -s https://api.heybossai.com/v1/pilot \
        -H "Authorization: Bearer ${SKILLBOSS_API_KEY}" \
        -H "Content-Type: application/json" \
        -d "{\"type\": \"embedding\", \"inputs\": {\"input\": $(printf '%s' "$query" | jq -Rs .)}}" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code transmits user-supplied search text to an external embedding API without any warning, consent flow, or masking. Search queries often contain proprietary, personal, or security-sensitive text, so silently forwarding them to a third party can cause confidentiality and compliance issues.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.