Orchestrate a complete Supabase security audit with guided step-by-step execution and ownership confirmation.
原文语言:英语
菜单
SkillsMP 已收集 yoanbernabeu/supabase-pentest-skills 中的 24 个 Skill。打开任一 Skill 可查看来源和详情。
已展示 24 / 24 个已收集 Skill。
Orchestrate a complete Supabase security audit with guided step-by-step execution and ownership confirmation.
原文语言:英语
Test Row Level Security (RLS) policies for common bypass vulnerabilities and misconfigurations.
原文语言:英语
List and test exposed PostgreSQL RPC functions for security issues and potential RLS bypass.
原文语言:英语
List all tables exposed via the Supabase PostgREST API to identify the attack surface.
原文语言:英语
Attempt to read data from exposed tables to verify actual data exposure and RLS effectiveness.
原文语言:英语
Analyze Supabase authentication configuration for security weaknesses and misconfigurations.
原文语言:英语
Test if user signup is open and identify potential abuse vectors in the registration process.
原文语言:英语
Test for user enumeration vulnerabilities through various authentication endpoints.
原文语言:英语
Create a test user (with explicit permission) to audit what authenticated users can access vs anonymous users. Detects IDOR, cross-user access, and privilege escalation.
原文语言:英语
Discover and test Supabase Edge Functions for security vulnerabilities and misconfigurations.
原文语言:英语
Test Supabase Realtime WebSocket channels for unauthorized subscriptions and data exposure.
原文语言:英语
List all storage buckets and their configuration to identify the storage attack surface.
原文语言:英语
Identify storage buckets that are publicly accessible and may contain sensitive data.
原文语言:英语
Attempt to list and read files from storage buckets to verify access controls.
原文语言:英语
Detect if a web application uses Supabase by analyzing client-side code, network patterns, and API endpoints.
原文语言:英语
Initialize and manage the evidence collection directory for professional security audits with documented proof of findings.
原文语言:英语
Extract the Supabase anon/public API key from client-side code. This key is expected in client apps but important for RLS testing.
原文语言:英语
CRITICAL - Detect exposed PostgreSQL database connection strings in client-side code. Direct DB access is a P0 issue.
原文语言:英语
Extract and decode Supabase-related JWTs from client-side code, cookies, and local storage patterns.
原文语言:英语
CRITICAL - Detect if the Supabase service_role key is leaked in client-side code. This is a P0 severity issue.
原文语言:英语
Extract the Supabase project URL from client-side JavaScript code, environment variables, and configuration files.
原文语言:英语
Quick reference for all Supabase security audit skills with usage examples and command overview.
原文语言:英语
Generate a comprehensive Markdown security audit report with executive summary, findings, and remediation guidance.
原文语言:英语
Compare two security audit reports to track remediation progress and identify new vulnerabilities.
原文语言:英语