Orchestrate a complete Supabase security audit with guided step-by-step execution and ownership confirmation.
لغة النص الأصلي: الإنجليزية
القائمة
جمع SkillsMP عدد ٢٤ من skills من yoanbernabeu/supabase-pentest-skills. افتح أي skill لمراجعة مصدره وتفاصيله.
عرض ٢٤ من أصل ٢٤ skills مجمعة.
Orchestrate a complete Supabase security audit with guided step-by-step execution and ownership confirmation.
لغة النص الأصلي: الإنجليزية
Test Row Level Security (RLS) policies for common bypass vulnerabilities and misconfigurations.
لغة النص الأصلي: الإنجليزية
List and test exposed PostgreSQL RPC functions for security issues and potential RLS bypass.
لغة النص الأصلي: الإنجليزية
List all tables exposed via the Supabase PostgREST API to identify the attack surface.
لغة النص الأصلي: الإنجليزية
Attempt to read data from exposed tables to verify actual data exposure and RLS effectiveness.
لغة النص الأصلي: الإنجليزية
Analyze Supabase authentication configuration for security weaknesses and misconfigurations.
لغة النص الأصلي: الإنجليزية
Test if user signup is open and identify potential abuse vectors in the registration process.
لغة النص الأصلي: الإنجليزية
Test for user enumeration vulnerabilities through various authentication endpoints.
لغة النص الأصلي: الإنجليزية
Create a test user (with explicit permission) to audit what authenticated users can access vs anonymous users. Detects IDOR, cross-user access, and privilege escalation.
لغة النص الأصلي: الإنجليزية
Discover and test Supabase Edge Functions for security vulnerabilities and misconfigurations.
لغة النص الأصلي: الإنجليزية
Test Supabase Realtime WebSocket channels for unauthorized subscriptions and data exposure.
لغة النص الأصلي: الإنجليزية
List all storage buckets and their configuration to identify the storage attack surface.
لغة النص الأصلي: الإنجليزية
Identify storage buckets that are publicly accessible and may contain sensitive data.
لغة النص الأصلي: الإنجليزية
Attempt to list and read files from storage buckets to verify access controls.
لغة النص الأصلي: الإنجليزية
Detect if a web application uses Supabase by analyzing client-side code, network patterns, and API endpoints.
لغة النص الأصلي: الإنجليزية
Initialize and manage the evidence collection directory for professional security audits with documented proof of findings.
لغة النص الأصلي: الإنجليزية
Extract the Supabase anon/public API key from client-side code. This key is expected in client apps but important for RLS testing.
لغة النص الأصلي: الإنجليزية
CRITICAL - Detect exposed PostgreSQL database connection strings in client-side code. Direct DB access is a P0 issue.
لغة النص الأصلي: الإنجليزية
Extract and decode Supabase-related JWTs from client-side code, cookies, and local storage patterns.
لغة النص الأصلي: الإنجليزية
CRITICAL - Detect if the Supabase service_role key is leaked in client-side code. This is a P0 severity issue.
لغة النص الأصلي: الإنجليزية
Extract the Supabase project URL from client-side JavaScript code, environment variables, and configuration files.
لغة النص الأصلي: الإنجليزية
Quick reference for all Supabase security audit skills with usage examples and command overview.
لغة النص الأصلي: الإنجليزية
Generate a comprehensive Markdown security audit report with executive summary, findings, and remediation guidance.
لغة النص الأصلي: الإنجليزية
Compare two security audit reports to track remediation progress and identify new vulnerabilities.
لغة النص الأصلي: الإنجليزية