Skip to main content

supabase-pentest-skills

Professional AI-assisted security auditing toolkit with 24 skills for detecting, extracting, testing, and reporting Supabase vulnerabilities (RLS, IDOR, storage, auth, API).

Zur Installation springen

Quellinformationen

Repository
reason-machines/security-skills
Letzte Quellaktivität
13. Juni 2026 um 09:40
Erkannte Sprache von SKILL.md
Englisch
Sterne
12
Forks
1

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.

SKILL.md wird angezeigt

SKILL.md
Quellanweisungen · Schreibgeschützte Vorschau
name
supabase-pentest-skills
description
Professional AI-assisted security auditing toolkit with 24 skills for detecting, extracting, testing, and reporting Supabase vulnerabilities (RLS, IDOR, storage, auth, API).
triggers
["audit my supabase application for security issues","run a security pentest on this supabase project","check for supabase vulnerabilities and exposed keys","test row level security policies on my supabase app","detect if this website uses supabase and extract credentials","generate a security report for my supabase application","check for IDOR vulnerabilities in my supabase auth","scan for misconfigured storage buckets in supabase"]
# Supabase Pentest Skills > Skill by [ara.so](https://ara.so) — Security Skills collection. A comprehensive toolkit of 24 AI agent skills for professional security auditing of Supabase applications. Automates detection, credential extraction, Row Level Security (RLS) testing, IDOR detection, storage audits, authentication analysis, and comprehensive reporting. ## What This Project Does Supabase Pentest Skills is a modular security auditing framework designed for **internal self-assessment** by authorized development teams. It provides: - **Detection**: Identify Supabase usage from public URLs - **Extraction**: Discover exposed API keys, JWTs, service keys, and database connection strings - **API Audit**: Test PostgREST endpoints, RLS policies, and RPC functions - **Storage Audit**: Identify misconfigured buckets and unauthorized file access - **Auth Audit**: Test authentication flows, user enumeration, and IDOR vulnerabilities - **Evidence Collection**: Professional-grade logging and proof-of-concept documentation - **Reporting**: Generate detailed Markdown reports with severity ratings and remediation guidance **Important**: These skills are for authorized testing only. You must own or have explicit permission to audit the target application. ## Installation ### Quick Install (All 24 Skills) ```bash npx skills add yoanbernabeu/supabase-pentest-skills ``` ### Install Specific Skill Packs ```bash # Detection only npx skills add yoanbernabeu/supabase-pentest-skills --skill supabase-detect # Key extraction (5 skills) npx skills add yoanbernabeu/supabase-pentest-skills --pack supabase-extraction # API audit (4 skills) npx skills add yoanbernabeu/supabase-pentest-skills --pack supabase-audit-api # Storage audit (3 skills) npx skills add yoanbernabeu/supabase-pentest-skills --pack supabase-audit-storage # Auth + IDOR testing (4 skills) npx skills add yoanbernabeu/supabase-pentest-skills --pack supabase-audit-auth # Global install (all projects) npx skills add yoanbernabeu/supabase-pentest-skills -g ``` ### List Available Skills ```bash npx skills add yoanbernabeu/supabase-pentest-skills --list ``` ## Recommended Professional Setup For complete audit trail and evidence collection: ```bash # 1. Create audit directory mkdir my-security-audit cd my-security-audit # 2. Install skills npx skills add yoanbernabeu/supabase-pentest-skills # 3. Download agent configuration template curl -o CLAUDE.md https://raw.githubusercontent.com/yoanbernabeu/supabase-pentest-skills/main/templates/CLAUDE.md # 4. Launch your AI agent and run # /supabase-pentest ``` ## Core Skills Reference ### Orchestration & Evidence | Skill | Purpose | |-------|---------| | `supabase-pentest` | Main orchestrator — guided step-by-step audit | | `supabase-evidence` | Initialize professional evidence collection | | `supabase-help` | Quick reference guide | ### Detection & Extraction | Skill | Purpose | |-------|---------| | `supabase-detect` | Detect Supabase usage from HTML/JS | | `supabase-extract-url` | Extract project URL | | `supabase-extract-anon-key` | Extract anon/public API key | | `supabase-extract-service-key` | **Critical**: Detect leaked service_role key | | `supabase-extract-jwt` | Extract and decode JWTs | | `supabase-extract-db-string` | Detect exposed database connection strings | ### API & RLS Testing | Skill | Purpose | |-------|---------| | `supabase-audit-tables-list` | List exposed PostgREST tables | | `supabase-audit-tables-read` | Attempt data reads | | `supabase-audit-rls` | Test Row Level Security policies | | `supabase-audit-rpc` | Test exposed RPC functions | ### Storage & Auth | Skill | Purpose | |-------|---------| | `supabase-audit-buckets-list` | List storage buckets | | `supabase-audit-buckets-read` | Test file access | | `supabase-audit-buckets-public` | Detect public bucket misconfigurations | | `supabase-audit-auth-config` | Analyze auth configuration | | `supabase-audit-auth-signup` | Test open signup | | `supabase-audit-auth-users` | Test user enumeration | | `supabase-audit-authenticated` | **Create test user to detect IDOR** | ### Realtime, Functions & Reporting | Skill | Purpose | |-------|---------| | `supabase-audit-realtime` | Test Realtime channels | | `supabase-audit-functions` | Test Edge Functions | | `supabase-report` | Generate comprehensive report | | `supabase-report-compare` | Compare two audit reports | ## Usage Patterns ### Pattern 1: Full Guided Audit ``` I need a complete security audit of https://myapp.example.com IMPORTANT: 1. Initialize supabase-evidence first 2. Execute ALL 24 skills systematically 3. Log every action 4. Save all evidence 5. Generate final report I confirm I am authorized to test this application. ``` The orchestrator will: 1. Initialize evidence collection 2. Run detection and extraction 3. Execute all API, storage, auth audits 4. Generate comprehensive report with severity ratings ### Pattern 2: Targeted Extraction ``` Extract all Supabase credentials from https://example.com ``` This will run: - `supabase-detect` - `supabase-extract-url` - `supabase-extract-anon-key` - `supabase-extract-service-key` (critical check) - `supabase-extract-jwt` - `supabase-extract-db-string` ### Pattern 3: RLS Policy Testing ``` Test Row Level Security policies on my Supabase app at https://example.com ``` This will: 1. Extract credentials 2. List tables (`supabase-audit-tables-list`) 3. Attempt unauthorized reads (`supabase-audit-tables-read`) 4. Test RLS bypass scenarios (`supabase-audit-rls`) ### Pattern 4: IDOR Detection ``` Check for IDOR vulnerabilities in auth on https://example.com ``` This executes `supabase-audit-authenticated`, which: 1. Creates a test user 2. Attempts cross-user data access 3. Tests privilege escalation 4. Documents findings with proof-of-concept ### Pattern 5: Storage Security Audit ``` Audit storage bucket security for my Supabase application ``` Runs: - `supabase-audit-buckets-list` - `supabase-audit-buckets-read` - `supabase-audit-buckets-public` ### Pattern 6: Compare Progress ``` Compare my latest audit with the report from last month ``` Uses `supabase-report-compare` to show: - New vulnerabilities discovered - Issues resolved - Security score changes ## Context & Evidence Files All skills share state through files: ### `.sb-pentest-context.json` ```json { "target_url": "https://myapp.example.com", "supabase_url": "https://abc123.supabase.co", "anon_key": "eyJhbGc...", "service_key_leaked": false, "findings": { "p0": ["Service role key exposed in /static/js/main.js"], "p1": ["RLS policy missing on 'users' table"], "p2": ["Verbose error messages expose table structure"] }, "tables_exposed": ["users", "posts", "comments"], "buckets_public": ["avatars"], "test_user": { "email": "pentest_user_1738329847@example.com", "password": "RANDOM_SECURE_PASSWORD" } } ``` ### `.sb-pentest-audit.log` ``` [2025-01-31T10:45:23Z] supabase-detect - Started detection on https://myapp.example.com [2025-01-31T10:45:25Z] supabase-detect - Found Supabase URL: https://abc123.supabase.co [2025-01-31T10:45:30Z] supabase-extract-anon-key - Extracted anon key from /static/js/app.js [2025-01-31T10:45:35Z] supabase-audit-tables-list - Found 12 exposed tables [2025-01-31T10:45:40Z] supabase-audit-rls - P0: 'users' table has no RLS policy ``` ### `.sb-pentest-evidence/` Directory Structure ``` .sb-pentest-evidence/ ├── README.md # Evidence index ├── curl-commands.sh # Reproducible API calls ├── timeline.md # Chronological findings ├── 01-detection/ │ └── supabase-detected.md ├── 02-extraction/ │ ├── url-extracted.md │ ├── anon-key-extracted.md │ └── service-key-LEAKED.md # P0 finding ├── 03-api-audit/ │ ├── tables-list.json │ ├── rls-bypass-users.md # P0 finding │ └── rpc-functions.json ├── 04-storage-audit/ │ └── public-bucket-avatars.md # P1 finding └── 05-auth-audit/ ├── test-user-created.md └── idor-detected-users.md # P0 finding ``` ### `curl-commands.sh` (Reproducible Tests) ```bash #!/bin/bash # Generated by supabase-pentest-skills # All API calls made during audit # List tables (unauthenticated) curl -X GET 'https://abc123.supabase.co/rest/v1/' \ -H "apikey: eyJhbGc..." \ -H "Authorization: Bearer eyJhbGc..." # Attempt to read users table (RLS bypass test) curl -X GET 'https://abc123.supabase.co/rest/v1/users?select=*' \ -H "apikey: eyJhbGc..." \ -H "Authorization: Bearer eyJhbGc..." # Test public bucket access curl -X GET 'https://abc123.supabase.co/storage/v1/object/public/avatars/user-123.jpg' # IDOR test: User A accessing User B's data curl -X GET 'https://abc123.supabase.co/rest/v1/profiles?user_id=eq.OTHER_USER_ID' \ -H "apikey: eyJhbGc..." \ -H "Authorization: Bearer USER_A_JWT" ``` ## Report Format ### Example Output (`supabase-audit-report.md`) ```markdown # Supabase Security Audit Report **Target**: https://myapp.example.com **Supabase Project**: https://abc123.supabase.co **Date**: 2025-01-31 **Auditor**: AI Agent (supabase-pentest-skills) --- ## Executive Summary **Security Score**: 45/100 (Grade: D) - **2 P0 (Critical)** issues found - **3 P1 (High)** issues found - **5 P2 (Medium)** issues found **Risk Level**: HIGH — Immediate action required ### Key Risks 1. Service role key exposed in client code (full DB access) 2. Row Level Security disabled on `users` table 3. IDOR vulnerability allows cross-user data access --- ## Critical Findings (P0) ### 1. Service Role Key Exposed in Client Code **Severity**: P0 - Critical **Location**: `/static/js/main.js:1247` **Impact**: Full database access bypassing all RLS policies **Evidence**: ```javascript const supabase = createClient( 'https://abc123.supabase.co', 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJyb2xlIjoic2VydmljZV9yb2xlIn0...' // ^ This is a service_role key! ) ``` **Remediation**: 1. Rotate the service_role key immediately in Supabase Dashboard > Settings > API 2. Remove from client code 3. Use anon key in client, service key ONLY in secure backend/Edge Functions **References**: - [Supabase Security Best Practices](https://supabase.com/docs/guides/auth/managing-user-data#security-considerations) - [API Keys Documentation](https://supabase.com/docs/guides/api/api-keys) --- ### 2. Row Level Security Disabled on `users` Table **Severity**: P0 - Critical **Impact**: All user data readable/writable by anyone with anon key **Test Result**: ```bash curl 'https://abc123.supabase.co/rest/v1/users?select=*' \ -H "apikey: ANON_KEY" \ # Returns ALL users including emails, phone numbers, metadata ``` **Remediation**: ```sql -- Enable RLS ALTER TABLE users ENABLE ROW LEVEL SECURITY; -- Policy: Users can only read their own data CREATE POLICY "Users can view own data" ON users FOR SELECT USING (auth.uid() = id); -- Policy: Users can update their own data CREATE POLICY "Users can update own data" ON users FOR UPDATE USING (auth.uid() = id); ``` --- ## High Priority Findings (P1) ### 1. Public Storage Bucket Misconfiguration **Severity**: P1 - High **Bucket**: `avatars` **Impact**: All uploaded avatars accessible without authentication **Test**: ```bash curl 'https://abc123.supabase.co/storage/v1/object/public/avatars/user-456/avatar.jpg' # Returns file without auth ``` **Remediation**: - Make bucket private if files should be protected - Use signed URLs for temporary access - Implement storage policies: ```sql CREATE POLICY "Avatar access policy" ON storage.objects FOR SELECT USING ( bucket_id = 'avatars' AND (storage.foldername(name))[1] = auth.uid()::text ); ``` --- ## Medium Priority Findings (P2)
Auf GitHub ansehen
Diese SKILL.md ist sehr gross, daher zeigt SkillsMP hier nur den ersten Abschnitt. Auf GitHub ansehen