Skip to main content

yoanbernabeu/supabase-pentest-skills

SkillsMP 已收集 yoanbernabeu/supabase-pentest-skills 中的 24 个 Skill。打开任一 Skill 可查看来源和详情。

最近记录的来源活动
SkillsMP 收录数据更新
已收集 skills
24
GitHub 星标
68
GitHub Forks
3

这个仓库中的 skills

1 个职业分类 · 已分类 100%

已展示 24 / 24 个已收集 Skill。

职业分类
信息安全分析师
描述

Orchestrate a complete Supabase security audit with guided step-by-step execution and ownership confirmation.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Test Row Level Security (RLS) policies for common bypass vulnerabilities and misconfigurations.

原文语言:英语

更新
职业分类
信息安全分析师
描述

List and test exposed PostgreSQL RPC functions for security issues and potential RLS bypass.

原文语言:英语

更新
职业分类
信息安全分析师
描述

List all tables exposed via the Supabase PostgREST API to identify the attack surface.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Attempt to read data from exposed tables to verify actual data exposure and RLS effectiveness.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze Supabase authentication configuration for security weaknesses and misconfigurations.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Test if user signup is open and identify potential abuse vectors in the registration process.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Test for user enumeration vulnerabilities through various authentication endpoints.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Create a test user (with explicit permission) to audit what authenticated users can access vs anonymous users. Detects IDOR, cross-user access, and privilege escalation.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Discover and test Supabase Edge Functions for security vulnerabilities and misconfigurations.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Test Supabase Realtime WebSocket channels for unauthorized subscriptions and data exposure.

原文语言:英语

更新
职业分类
信息安全分析师
描述

List all storage buckets and their configuration to identify the storage attack surface.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Identify storage buckets that are publicly accessible and may contain sensitive data.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Attempt to list and read files from storage buckets to verify access controls.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Detect if a web application uses Supabase by analyzing client-side code, network patterns, and API endpoints.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Initialize and manage the evidence collection directory for professional security audits with documented proof of findings.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Extract the Supabase anon/public API key from client-side code. This key is expected in client apps but important for RLS testing.

原文语言:英语

更新
职业分类
信息安全分析师
描述

CRITICAL - Detect exposed PostgreSQL database connection strings in client-side code. Direct DB access is a P0 issue.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Extract and decode Supabase-related JWTs from client-side code, cookies, and local storage patterns.

原文语言:英语

更新
职业分类
信息安全分析师
描述

CRITICAL - Detect if the Supabase service_role key is leaked in client-side code. This is a P0 severity issue.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Extract the Supabase project URL from client-side JavaScript code, environment variables, and configuration files.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Quick reference for all Supabase security audit skills with usage examples and command overview.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Generate a comprehensive Markdown security audit report with executive summary, findings, and remediation guidance.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Compare two security audit reports to track remediation progress and identify new vulnerabilities.

原文语言:英语

更新
已展示 24 / 24 个已收集 Skill。