supabase
What this skill does
The skill provides a CLI tool for interacting with the Supabase Management API and includes a local SQLite cache for cross-project queries. It is designed for developers to manage Supabase resources a
github/mvanhorn - Tool Misuse - 1.9k stars
Threat analysis
Skill info
pkg:github/mvanhorn/printing-press-library@5a78746?skill=supabaseAssessments (1)
Tool Misuse
Tool Misuse via local-llm-review
README.md
The README.md file contains a line that suggests using `rm -rf bin/` in the Makefile. This could be a risk if the Makefile is not properly secured and could be manipulated to delete important files.Badge
Add the Anomity scan badge for supabase to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of supabase? Report an issue or request a rescan.




