BigHugger
sk Skill · PentesterFlow

supabase

Supabase / PostgREST Row-Level-Security playbook — pull the anon (or leaked service_role) key out of the frontend JS, map tables from the auto-generated OpenAPI spec, test anonymous RLS READ disclosures (PII/secret leaks), and anonymous RLS WRITE abuse (insert/update/delete — e.g. forging "certificate"/verification/entitlement rows the app trusts). Use when the target's frontend talks to *.supabase.co, ships an anon…

installs 8w
0
30-day movement
starts with the next reading
Related entries
9
Connections
7
bashTypeScript
Host repository
PentesterFlow/agent
Allowed tools
http, shell, web_fetch, grep, file_write, read_payloads, confirm_finding
Host stars
1,360
Host language
TypeScript