sk Skill · PentesterFlow
supabase
Supabase / PostgREST Row-Level-Security playbook — pull the anon (or leaked service_role) key out of the frontend JS, map tables from the auto-generated OpenAPI spec, test anonymous RLS READ disclosures (PII/secret leaks), and anonymous RLS WRITE abuse (insert/update/delete — e.g. forging "certificate"/verification/entitlement rows the app trusts). Use when the target's frontend talks to *.supabase.co, ships an anon…
Open on skills.sh ↗read 2026-09-17
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 9
- Connections
- 7
bashTypeScript
- Host repository
- PentesterFlow/agent
- Allowed tools
- http, shell, web_fetch, grep, file_write, read_payloads, confirm_finding
- Host stars
- 1,360
- Host language
- TypeScript