supabase-pentest

Orchestrate a complete security audit of a Supabase application.

62|3|Updated Jan 31, 2026
One-click install
npx skills add https://github.com/yoanbernabeu/supabase-pentest-skills --skill supabase-pentest
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: supabase-pentest
Source: https://github.com/yoanbernabeu/supabase-pentest-skills/tree/main/skills/orchestration/supabase-pentest
Command: npx skills add https://github.com/yoanbernabeu/supabase-pentest-skills --skill supabase-pentest

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill guides teams through a structured, plan-aware Supabase security audit, reducing manual coordination and ensuring progressive evidence capture.

Core Features & Use Cases

  • Step-by-step audit orchestration across detections, extractions, API, storage, auth, and reporting.
  • Progressive context updates and real-time evidence logging for compliant security reviews.
  • Use Case: Run a full audit on https://myapp.example.com with automated phase progression and reporting.

Quick Start

Run the Supabase security audit on https://myapp.example.com

Frequently Asked Questions about supabase-pentest

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a structured security audit on a Supabase application?

To run a Supabase security audit, you orchestrate detection, extraction, API, storage, auth, and reporting phases. This process enforces mandatory logging and file-based evidence management while requiring the target audit URL and explicit authorization.

What is progressive evidence logging in a Supabase security audit?

Progressive evidence logging in a Supabase security audit is the continuous capture of context updates and phase validation results. It ensures compliant security reviews by enforcing mandatory logging and file-based evidence management throughout the multi-phase audit.

Can I use plan-mode to guide multi-phase Supabase security reviews?

Yes, you can use plan-mode to guide multi-phase Supabase security reviews. This approach applies guide-driven orchestration across detection, extraction, API, storage, auth, and reporting phases, enforcing phase validation and progressive context updates.

Do I need explicit authorization to conduct a Supabase security audit?

Yes, explicit authorization is required to conduct a Supabase security audit. The orchestration process mandates providing the target audit URL and explicit authorization before initiating detection, extraction, and reporting phases with evidence management.

What's the best way to manage compliance evidence during Supabase security reviews?

The best way to manage compliance evidence during Supabase security reviews is using file-based evidence management. This enforces mandatory logging and progressive context updates, coordinating extraction, API, storage, and auth phases for professional security audits.