Supabase

Supabase / PostgREST Row-Level-Security playbook — pull the anon (or leaked service_role) key out of the frontend JS, map tables from the auto-generated OpenAPI spec, test anonymous RLS READ disclosures (PII/secret leaks), and anonymous RLS WRITE abuse (insert/update/delete — e.g. forging "certificate"/verification/entitlement rows the app trusts). Use when the target's frontend talks to *.supabase.co, ships an anon JWT, or you see /rest/v1/, /auth/v1/, /storage/v1/ requests.

pentesterflow 0c2293b 2 files · 12.6 KB Updated

File contents

pentesterflow/agent/tree/main/skills/supabase commit 0c2293bdae

Frequently asked questions

npx skillmds@latest add pentesterflow/supabase