{
  "markdown": "<p align=\"center\">\n  <img src=\"https://img.shields.io/badge/Skills-24-brightgreen\" alt=\"24 Skills\">\n  <img src=\"https://img.shields.io/badge/License-MIT-blue\" alt=\"MIT License\">\n  <img src=\"https://img.shields.io/badge/PRs-Welcome-orange\" alt=\"PRs Welcome\">\n</p>\n\n<h1 align=\"center\">Supabase Pentest Skills</h1>\n\n<p align=\"center\">\n  <strong>24 AI Agent Skills for professional security auditing of Supabase applications.</strong><br>\n  Detection, key extraction, RLS testing, IDOR detection, storage audit, evidence collection, comprehensive reporting.\n</p>\n\n<p align=\"center\">\n  <a href=\"#quick-install\">Install</a> •\n  <a href=\"#all-24-skills\">Skills</a> •\n  <a href=\"#example-usage\">Usage</a> •\n  <a href=\"#contributing\">Contribute</a>\n</p>\n\n---\n\n## Quick Install\n\n```bash\nnpx skills add yoanbernabeu/supabase-pentest-skills\n```\n\n**That's it.** Works with Claude Code, Cursor, Codex, OpenCode, Windsurf, and 30+ AI agents.\n\n### One-Liners\n\n```bash\n# Install everything (24 skills)\nnpx skills add yoanbernabeu/supabase-pentest-skills\n\n# Install only detection skills\nnpx skills add yoanbernabeu/supabase-pentest-skills --skill supabase-detect\n\n# Install globally (available in all projects)\nnpx skills add yoanbernabeu/supabase-pentest-skills -g\n\n# List all available skills\nnpx skills add yoanbernabeu/supabase-pentest-skills --list\n\n# Non-interactive (CI/CD friendly)\nnpx skills add yoanbernabeu/supabase-pentest-skills --all -y\n```\n\n---\n\n## Recommended Setup (New Audit)\n\n> **Note**: This setup is optimized for [Claude Code](https://docs.anthropic.com/en/docs/claude-code) users. The CLAUDE.md template provides specific instructions for Claude Code's agent capabilities.\n\nFor professional audits with complete logging and evidence collection, follow this setup:\n\n### Step 1: Install the Skills\n\n```bash\nnpx skills add yoanbernabeu/supabase-pentest-skills\n```\n\n### Step 2: Create a Fresh Audit Directory\n\n```bash\nmkdir my-security-audit\ncd my-security-audit\n```\n\n### Step 3: Download the CLAUDE.md Template\n\nThis template configures your AI agent for strict logging and systematic execution:\n\n```bash\ncurl -o CLAUDE.md https://raw.githubusercontent.com/yoanbernabeu/supabase-pentest-skills/main/templates/CLAUDE.md\n```\n\n### Step 4: Launch the Audit\n\nOpen your AI agent (Claude Code, Cursor, etc.) in the directory and run:\n\n```\n/supabase-pentest\n```\n\nOr use the detailed prompt for maximum compliance:\n\n```\nI need you to run a complete Supabase security audit on https://myapp.example.com\n\nIMPORTANT INSTRUCTIONS:\n1. Use Plan Mode (EnterPlanMode) before starting\n2. Initialize supabase-evidence skill FIRST\n3. Execute ALL 24 audit skills systematically - NO EXCEPTIONS:\n   - 1 detection skill\n   - 5 extraction skills (url, anon-key, service-key, jwt, db-string)\n   - 4 API audit skills (tables-list, tables-read, rls, rpc)\n   - 3 storage audit skills (buckets-list, buckets-read, buckets-public)\n   - 4 auth audit skills (auth-config, auth-signup, auth-users, authenticated)\n   - 1 realtime audit skill\n   - 1 functions audit skill\n   - 2 reporting skills (report, report-compare if applicable)\n4. After EACH skill: update context, log actions, save evidence\n5. NEVER skip a phase without explicit user confirmation\n6. Generate final report with supabase-report\n\nI confirm I am authorized to test this application.\n```\n\n> **Note**: The CLAUDE.md template includes a checklist of all 24 skills that must be executed. The AI agent will follow this checklist systematically.\n\n### Why Use the CLAUDE.md Template?\n\nThe template enforces:\n\n| Requirement | Benefit |\n|-------------|---------|\n| **Mandatory logging** | Complete audit trail for compliance |\n| **Systematic execution** | No steps skipped, consistent results |\n| **Evidence collection** | Professional-grade proof of findings |\n| **Reproducible commands** | All curl commands saved for verification |\n| **Timestamped timeline** | Chronological record of all discoveries |\n\n### Directory Structure After Audit\n\n```\nmy-security-audit/\n├── CLAUDE.md                    # Agent configuration (from template)\n├── .sb-pentest-context.json     # Shared context between skills\n├── .sb-pentest-audit.log        # Complete action log\n├── .sb-pentest-evidence/        # Professional evidence collection\n│   ├── README.md\n│   ├── curl-commands.sh\n│   ├── timeline.md\n│   ├── 01-detection/\n│   ├── 02-extraction/\n│   ├── 03-api-audit/\n│   ├── 04-storage-audit/\n│   ├── 05-auth-audit/\n│   ├── 06-realtime-audit/\n│   └── 07-functions-audit/\n└── supabase-audit-report.md     # Final report\n```\n\n---\n\n## What is Supabase Pentest Skills?\n\nA comprehensive toolkit for **internal security auditing** of Supabase-based applications. These skills help development teams:\n\n- **Detect** Supabase usage from public URLs\n- **Extract** exposed keys, JWTs, and connection strings\n- **Audit** API access, RLS policies, storage buckets, and auth config\n- **Report** findings with severity levels and remediation guidance\n\n### Important Notice\n\nThese skills are designed for **internal self-assessment by authorized development teams only**. Before running any audit:\n\n1. You must own or have explicit authorization to test the target application\n2. Tests are read-only (no write/delete operations)\n3. All actions are logged for audit trail\n\n---\n\n## Security Model\n\n| Aspect | Implementation |\n|--------|----------------|\n| **Access** | Public URL analysis only (HTML, JS, network) |\n| **Operations** | Read-only (no write/delete) |\n| **Rate Limiting** | Adaptive (slows down if throttled) |\n| **Logging** | Full audit trail in `.sb-pentest-audit.log` |\n| **Context** | Shared via `.sb-pentest-context.json` |\n| **Evidence** | Professional-grade evidence in `.sb-pentest-evidence/` |\n| **Authorization** | Explicit ownership confirmation required |\n\n---\n\n## All 24 Skills\n\n### Orchestration & Help\n| Skill | What It Does |\n|-------|--------------|\n| `supabase-pentest` | Orchestrator: guided step-by-step security audit |\n| `supabase-evidence` | Professional evidence collection management |\n| `supabase-help` | Quick reference and usage examples |\n\n### Detection\n| Skill | What It Does |\n|-------|--------------|\n| `supabase-detect` | Detect if a web application uses Supabase |\n\n### Key Extraction\n| Skill | What It Does |\n|-------|--------------|\n| `supabase-extract-url` | Extract Supabase project URL from client code |\n| `supabase-extract-anon-key` | Extract anon/public API key |\n| `supabase-extract-service-key` | Detect leaked service_role key (critical!) |\n| `supabase-extract-jwt` | Extract and decode Supabase JWTs |\n| `supabase-extract-db-string` | Detect exposed database connection strings |\n\n### API Audit\n| Skill | What It Does |\n|-------|--------------|\n| `supabase-audit-tables-list` | List tables exposed via PostgREST |\n| `supabase-audit-tables-read` | Attempt to read data from exposed tables |\n| `supabase-audit-rls` | Test Row Level Security policies |\n| `supabase-audit-rpc` | List and test exposed RPC functions |\n\n### Storage Audit\n| Skill | What It Does |\n|-------|--------------|\n| `supabase-audit-buckets-list` | List storage buckets |\n| `supabase-audit-buckets-read` | Attempt to read files from buckets |\n| `supabase-audit-buckets-public` | Detect misconfigured public buckets |\n\n### Auth Audit\n| Skill | What It Does |\n|-------|--------------|\n| `supabase-audit-auth-config` | Analyze authentication configuration |\n| `supabase-audit-auth-signup` | Test if signup is open/unrestricted |\n| `supabase-audit-auth-users` | Attempt user enumeration |\n| `supabase-audit-authenticated` | **Create test user to detect IDOR & cross-user access** |\n\n### Realtime & Functions Audit\n| Skill | What It Does |\n|-------|--------------|\n| `supabase-audit-realtime` | Test exposed Realtime channels |\n| `supabase-audit-functions` | List and test Edge Functions |\n\n### Reporting\n| Skill | What It Does |\n|-------|--------------|\n| `supabase-report` | Generate comprehensive Markdown report |\n| `supabase-report-compare` | Compare two reports to track progress |\n\n---\n\n## Skill Packs\n\nInstall skills by category:\n\n| Pack | Skills | Description |\n|------|--------|-------------|\n| `supabase-orchestration` | 3 | Main orchestrator, evidence, and help |\n| `supabase-detection` | 1 | Supabase detection |\n| `supabase-extraction` | 5 | Key and credential extraction |\n| `supabase-audit-api` | 4 | API and RLS testing |\n| `supabase-audit-storage` | 3 | Storage bucket auditing |\n| `supabase-audit-auth` | 4 | Authentication testing + IDOR detection |\n| `supabase-audit-realtime` | 1 | Realtime channel testing |\n| `supabase-audit-functions` | 1 | Edge Functions testing |\n| `supabase-report` | 2 | Report generation |\n| **`supabase-complete`** | **24** | **All skills — complete toolkit** |\n\n---\n\n## Severity Levels\n\n| Level | Description | Examples |\n|-------|-------------|----------|\n| **P0** | Critical data exposure, user data, privilege escalation | Service key leaked, full DB access, user enumeration |\n| **P1** | Sensitive data exposure, security misconfiguration | Weak RLS, unprotected buckets, open signup |\n| **P2** | Minor exposure, best practice violations | Verbose errors, unused endpoints exposed |\n\n---\n\n## Example Usage\n\n### Full Security Audit\n\n```\n\"Run a complete Supabase security audit on https://myapp.com\"\n```\n\n### Targeted Checks\n\n```\n\"Check if https://myapp.com uses Supabase\"\n\n\"Extract all Supabase keys from https://myapp.com\"\n\n\"Test RLS policies on my Supabase app\"\n\n\"Check if any storage buckets are misconfigured\"\n\n\"Generate a security report for my last audit\"\n```\n\n### Compare Progress\n\n```\n\"Compare my current audit with last month's report\"\n```\n\n### Recommended Prompt for Maximum Compliance\n\nFor the most thorough audit with strict adherence to all procedures, use this detailed prompt:\n\n```\nI need you to run a complete Supabase security audit on https://myapp.example.com\n\nIMPORTANT INSTRUCTIONS:\n1. Use Plan Mode (EnterPlanMode) before starting if available\n2. Initialize the supabase-evidence skill FIRST to set up evidence collection\n3. Execute ALL audit skills systematically in order (detection → extraction → API → storage → auth → realtime → functions)\n4. After EACH skill execution, you MUST:\n   - Update .sb-pentest-context.json with findings\n   - Log the action to .sb-pentest-audit.log\n   - Save evidence to .sb-pentest-evidence/\n   - Update timeline.md for any P0/P1/P2 finding\n   - Append curl commands to curl-commands.sh\n5. NEVER skip a phase without explicit confirmation\n6. Generate the final report with supabase-report\n\nI confirm I am authorized to test this application.\n```\n\nThis prompt ensures:\n- ✅ Plan Mode activation for better traceability\n- ✅ Proper evidence collection initialization\n- ✅ Systematic execution of all 24 skills\n- ✅ Progressive file updates (crash-resistant)\n- ✅ Complete audit trail for compliance\n\n---\n\n## Report Format\n\nReports include:\n\n1. **Executive Summary** — 5-10 lines, risk overview, score\n2. **Security Score** — 0-100 with letter grade\n3. **Findings by Severity** — P0, P1, P2 issues\n4. **Detailed Analysis** — Per-component breakdown\n5. **Remediation Guidance** — Fix suggestions + code examples + docs links\n\nExample output:\n\n```markdown\n# Supabase Security Audit Report\n\n## Executive Summary\nSecurity Score: 45/100 (Grade: D)\n- 2 P0 (Critical) issues found\n- 3 P1 (High) issues found\n- 5 P2 (Medium) issues found\n\n## Critical Findings (P0)\n### 1. Service Role Key Exposed\n**Severity:** P0 - Critical\n**Location:** /static/js/main.js:1247\n**Impact:** Full database access without RLS\n**Remediation:**\n- Rotate key immediately in Supabase Dashboard\n- Remove from client code\n- Use Edge Functions for privileged operations\n...\n```\n\n---\n\n## Files Generated\n\n| File/Directory | Purpose |\n|----------------|---------|\n| `.sb-pentest-context.json` | Shared context between skills |\n| `.sb-pentest-audit.log` | Detailed action log |\n| `.sb-pentest-evidence/` | **Professional evidence collection** |\n| `supabase-audit-report.md` | Final report |\n\n---\n\n## Professional Evidence Collection\n\nEvery audit generates a complete evidence directory for professional reports:\n\n```\n.sb-pentest-evidence/\n├── README.md                    # Evidence index and summary\n├── curl-commands.sh             # All reproducible curl commands\n├── timeline.md                  # Chronological findings timeline\n│\n├── 01-detection/                # Detection evidence\n│   └── initial-scan.json\n├── 02-extraction/               # Key extraction evidence\n│   ├── extracted-anon-key.json\n│   └── service-key-exposure/    # P0 findings with proof\n├── 03-api-audit/                # API audit evidence\n│   ├── tables/\n│   ├── data-samples/            # Redacted data samples\n│   ├── rls-tests/\n│   └── rpc-tests/\n├── 04-storage-audit/            # Storage audit evidence\n│   ├── buckets/\n│   └── public-url-tests/\n├── 05-auth-audit/               # Auth audit evidence\n│   ├── signup-tests/\n│   └── enumeration-tests/\n├── 06-realtime-audit/           # Realtime audit evidence\n├── 07-functions-audit/          # Functions audit evidence\n└── screenshots/                 # Optional screenshots\n```\n\n### Evidence Features\n\n- **Reproducible**: All curl commands saved for verification\n- **Timestamped**: Complete timeline of findings\n- **Redacted**: Sensitive data automatically masked\n- **Professional**: Ready for compliance and legal purposes\n\n---\n\n## Contributing\n\nContributions welcome! Please ensure all new skills:\n\n1. Follow the existing SKILL.md format\n2. Include practical examples\n3. Document remediation steps with code\n4. Reference official Supabase documentation\n\n---\n\n## License\n\n[MIT](LICENSE) — For internal security assessment only.\n\n---\n\n<p align=\"center\">\n  <strong>Built for developers who take security seriously.</strong><br><br>\n  <a href=\"https://github.com/yoanbernabeu/supabase-pentest-skills\">Star this repo</a> if it helps secure your apps!\n</p>\n",
  "bytes": 13876,
  "sha": "1844d9974442a801e6e315557412adea31d89628953f45582c864edee6f320c7",
  "repo_slug": "yoanbernabeu/supabase-pentest-skills",
  "fonte": "repo",
  "truncated": false,
  "api": "https://api.agentalog.com/api/listings/skl_yoanbernabeu_supabase_pentest_skills_sup_545f556b/readme"
}