List Storage Buckets
🔴 CRITICAL: PROGRESSIVE FILE UPDATES REQUIRED
You MUST write to context files AS YOU GO, not just at the end.
- Write to
.sb-pentest-context.jsonIMMEDIATELY after each bucket discovered- Log to
.sb-pentest-audit.logBEFORE and AFTER each operation- DO NOT wait until the skill completes to update files
- If the skill crashes or is interrupted, all prior findings must already be saved
This is not optional. Failure to write progressively is a critical error.
This skill discovers all storage buckets configured in a Supabase project.
When to Use This Skill
- To inventory all storage buckets
- Before testing bucket access permissions
- To identify publicly accessible buckets
- As part of storage security audit
Prerequisites
- Supabase URL and anon key available
- Detection completed
Understanding Supabase Storage
Supabase Storage provides:
Buckets can be:
- Public: Files accessible without authentication
- Private: Files require authentication and RLS policies
Storage API Endpoints
Usage
Basic Bucket List
With Configuration Details
Output Format
Bucket Configuration Analysis
Context Output
Security Recommendations
For Public Buckets
For Private Buckets
Fix Public Backup Bucket
Common Issues
❌ Problem: Cannot list buckets ✅ Solution: Storage API may be restricted. This is actually good security. Note as "unable to enumerate."
❌ Problem: Many buckets found ✅ Solution: Large applications may have many. Focus on public buckets first.
❌ Problem: Bucket count doesn't match expected ✅ Solution: Some buckets may be created dynamically. Check application code.
MANDATORY: Progressive Context File Updates
⚠️ This skill MUST update tracking files PROGRESSIVELY during execution, NOT just at the end.
Critical Rule: Write As You Go
DO NOT batch all writes at the end. Instead:
- Before starting bucket enumeration → Log the action to
.sb-pentest-audit.log - After each bucket discovered → Immediately update
.sb-pentest-context.json - After each configuration analyzed → Log the result
This ensures that if the skill is interrupted, crashes, or times out, all findings up to that point are preserved.
Required Actions (Progressive)
-
Update
.sb-pentest-context.jsonwith results: -
Log to
.sb-pentest-audit.log: -
If files don't exist, create them before writing.
FAILURE TO UPDATE CONTEXT FILES IS NOT ACCEPTABLE.
MANDATORY: Evidence Collection
📁 Evidence Directory: .sb-pentest-evidence/04-storage-audit/
Evidence Files to Create
Evidence Format
Add to curl-commands.sh
Related Skills
supabase-audit-buckets-read— Attempt to read filessupabase-audit-buckets-public— Find misconfigured public bucketssupabase-audit-storage-rls— Test storage RLS policies


