Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问许可证需确认审计异常

supabase-helpSupabase help 搜索

Agent Skill

supabase-help 用于查找、检索和筛选相关信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

4,093

周安装

164

GitHub Stars

37

下载量

1,325
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:supabase-help(Supabase help 搜索)
来源仓库:https://github.com/yoanbernabeu/supabase-pentest-skills
仓库路径:skills/supabase-help
安装命令:
npx skills add https://github.com/yoanbernabeu/supabase-pentest-skills --skill supabase-help
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/yoanbernabeu/supabase-pentest-skills --skill supabase-help

简介

用于搜索 Supabase 相关的帮助文档和常见问题。

  • 适合开发者在遇到问题时快速查找解决方案。
  • 基于关键词检索,返回相关资源链接。适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。
  • 结果仅供参考,需结合实际环境验证。
  • supabase-help 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Supabase Pentest Skills Help

Quick reference for all 24 security audit skills.

When to Use This Skill

  • Need a quick overview of available skills
  • Looking for the right skill for a specific task
  • Want usage examples for a particular skill

Quick Start

# Full guided audit
/supabase-pentest https://myapp.example.com

# Check if app uses Supabase
/supabase-detect https://myapp.example.com

# Generate report from previous audit
/supabase-report

All Skills Reference

Orchestration

SkillCommandPurpose
supabase-pentest/supabase-pentest <url>Full guided security audit
supabase-evidence/supabase-evidenceInitialize evidence collection
supabase-help/supabase-helpThis help reference

Detection

SkillCommandPurpose
supabase-detect/supabase-detect <url>Detect Supabase usage

Extraction

SkillCommandPurpose
supabase-extract-url/supabase-extract-url <url>Find Supabase project URL
supabase-extract-anon-key/supabase-extract-anon-keyExtract anon API key
supabase-extract-service-key/supabase-extract-service-keyFind leaked service key
supabase-extract-jwt/supabase-extract-jwtExtract JWTs from code
supabase-extract-db-string/supabase-extract-db-stringFind DB connection strings

API Audit

SkillCommandPurpose
supabase-audit-tables-list/supabase-audit-tables-listList exposed tables
supabase-audit-tables-read/supabase-audit-tables-readRead table data
supabase-audit-rls/supabase-audit-rlsTest RLS policies
supabase-audit-rpc/supabase-audit-rpcTest RPC functions

Storage Audit

SkillCommandPurpose
supabase-audit-buckets-list/supabase-audit-buckets-listList storage buckets
supabase-audit-buckets-read/supabase-audit-buckets-readRead bucket files
supabase-audit-buckets-public/supabase-audit-buckets-publicFind public buckets

Auth Audit

SkillCommandPurpose
supabase-audit-auth-config/supabase-audit-auth-configCheck auth settings
supabase-audit-auth-signup/supabase-audit-auth-signupTest signup access
supabase-audit-auth-users/supabase-audit-auth-usersTest user enumeration
supabase-audit-authenticated/supabase-audit-authenticatedCreate test user to detect IDOR

Realtime & Functions

SkillCommandPurpose
supabase-audit-realtime/supabase-audit-realtimeTest Realtime channels
supabase-audit-functions/supabase-audit-functionsTest Edge Functions

Reporting

SkillCommandPurpose
supabase-report/supabase-reportGenerate Markdown report
supabase-report-compare/supabase-report-compare <old> <new>Compare two reports

Severity Levels

LevelColorDescription
P0🔴Critical: data exposure, user data, privilege escalation
P1🟠High: sensitive data, security misconfiguration
P2🟡Medium: minor exposure, best practice violations

Common Workflows

Quick Security Check

1. /supabase-detect https://myapp.com
2. /supabase-extract-anon-key
3. /supabase-audit-rls
4. /supabase-report

Full Audit

1. /supabase-pentest https://myapp.com
   (Follow guided prompts through all phases)

Storage-Only Audit

1. /supabase-detect https://myapp.com
2. /supabase-audit-buckets-list
3. /supabase-audit-buckets-public
4. /supabase-report

Compare After Fixes

1. Copy previous report to reports/audit-v1.md
2. Run new audit: /supabase-pentest https://myapp.com
3. /supabase-report-compare reports/audit-v1.md supabase-audit-report.md

Files and Directories Created

File/DirectoryDescription
.sb-pentest-context.jsonShared context between skills
.sb-pentest-audit.logAction log with timestamps
.sb-pentest-evidence/Evidence directory for professional audits
supabase-audit-report.mdFinal security report

Evidence Directory Structure

.sb-pentest-evidence/
├── README.md                 # Evidence index
├── curl-commands.sh          # Reproducible commands
├── timeline.md               # Chronological findings
├── 01-detection/             # Detection evidence
├── 02-extraction/            # Key extraction evidence
├── 03-api-audit/             # API audit evidence
├── 04-storage-audit/         # Storage audit evidence
├── 05-auth-audit/            # Auth audit evidence
├── 06-realtime-audit/        # Realtime audit evidence
├── 07-functions-audit/       # Functions audit evidence
└── screenshots/              # Optional screenshots

Tips

  1. Always run detection first — Most skills auto-invoke it, but it's faster to run explicitly
  2. Check the context file — If a skill behaves unexpectedly, the context may have stale data
  3. Use the orchestrator for full audits — It handles dependencies automatically
  4. Save reports with dates — Rename supabase-audit-report.md to include the date for history

Need More Help?

  • Each skill has detailed documentation — run /supabase-<skill-name> for specifics
  • Check the README at the repository root
  • Open an issue on GitHub for bugs or feature requests

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

34.07%
按下载量换算451

Claude

32.76%
按下载量换算434

Cursor

20.57%
按下载量换算273

Gemini CLI

10.43%
按下载量换算138

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

未通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills