Supabase Detection
🔴 CRITICAL: PROGRESSIVE FILE UPDATES REQUIRED
You MUST write to context files AS YOU GO, not just at the end.
- Write to
.sb-pentest-context.jsonIMMEDIATELY after each discovery- Log to
.sb-pentest-audit.logBEFORE and AFTER each action- DO NOT wait until the skill completes to update files
- If the skill crashes or is interrupted, all prior findings must already be saved
This is not optional. Failure to write progressively is a critical error.
This skill determines whether a web application uses Supabase as its backend.
When to Use This Skill
- Starting a security audit on an unknown application
- Verifying Supabase usage before running other audit skills
- Quickly checking multiple applications for Supabase presence
Prerequisites
- Target URL must be publicly accessible
- Internet connection to fetch and analyze the target
Detection Methods
The skill uses multiple detection vectors:
1. Domain Pattern Matching
Searches for Supabase-related domains in:
- HTML source code
- JavaScript bundles
- Network requests (via inline scripts)
Patterns detected:
2. JavaScript Client Detection
Looks for Supabase client library signatures:
3. API Endpoint Detection
Checks for characteristic Supabase endpoints:
4. Response Header Analysis
Looks for Supabase-specific headers:
Usage
Basic Detection
Detection with Verbose Output
Output Format
Supabase Detected
Supabase Not Detected
Context Output
When Supabase is detected, the skill saves to .sb-pentest-context.json:
Audit Log Entry
Each detection is logged to .sb-pentest-audit.log:
Confidence Levels
Edge Cases
Custom Domains
Some Supabase projects use custom domains (e.g., api.mycompany.com). In this case:
Self-Hosted Supabase
Self-hosted instances won't have .supabase.co domains. Look for:
- PostgREST patterns (
/rest/v1/) - GoTrue auth patterns (
/auth/v1/) - Supabase client library in code
Single Page Applications
For SPAs with lazy-loaded chunks:
Common Issues
❌ Problem: Detection returns false negative on SPA ✅ Solution: The app may lazy-load Supabase. Try interacting with the app first to load all chunks, or provide known patterns.
❌ Problem: Multiple Supabase projects detected ✅ Solution: This can happen with multi-tenant setups. The skill will list all found projects.
❌ Problem: Detection is slow
✅ Solution: Large JS bundles take time to analyze. Use --quick mode for faster but less thorough detection:
Next Steps
After detection:
- Run
supabase-extract-urlto confirm and extract the project URL - Run
supabase-extract-anon-keyto find the API key - Or use
supabase-pentestfor a full guided audit
MANDATORY: Progressive Context File Updates
⚠️ This skill MUST update tracking files PROGRESSIVELY during execution, NOT just at the end.
Critical Rule: Write As You Go
DO NOT batch all writes at the end. Instead:
- Before starting any action → Log the action to
.sb-pentest-audit.log - After each discovery → Immediately update
.sb-pentest-context.json - After each significant step → Log completion to
.sb-pentest-audit.log
This ensures that if the skill is interrupted, crashes, or times out, all findings up to that point are preserved.
Required Actions (Progressive)
-
Create/Update
.sb-pentest-context.jsonwith results: -
Create/Log to
.sb-pentest-audit.log: -
IMPORTANT: As the first skill in the audit chain, this skill is responsible for creating the context files if they don't exist.
FAILURE TO UPDATE CONTEXT FILES IS NOT ACCEPTABLE.
MANDATORY: Evidence Collection
📁 Evidence Directory: .sb-pentest-evidence/01-detection/
Evidence Files to Create
Evidence Format
Add to curl-commands.sh
Add to timeline.md
Related Skills
supabase-extract-url— Extract project URL from codesupabase-extract-anon-key— Find anon keysupabase-pentest— Full orchestrated audit


