List Exposed Tables
🔴 CRITICAL: PROGRESSIVE FILE UPDATES REQUIRED
You MUST write to context files AS YOU GO, not just at the end.
- Write to
.sb-pentest-context.jsonIMMEDIATELY after each discovery- Log to
.sb-pentest-audit.logBEFORE and AFTER each action- DO NOT wait until the skill completes to update files
- If the skill crashes or is interrupted, all prior findings must already be saved
This is not optional. Failure to write progressively is a critical error.
This skill discovers all database tables exposed through the Supabase PostgREST API.
When to Use This Skill
- To understand the API attack surface
- Before testing RLS policies
- To inventory exposed data models
- As part of a comprehensive security audit
Prerequisites
- Supabase URL extracted (auto-invokes if needed)
- Anon key extracted (auto-invokes if needed)
How It Works
Supabase exposes tables via PostgREST at:
The skill uses the OpenAPI schema endpoint to enumerate tables:
What Gets Exposed
By default, Supabase exposes tables in the public schema. Tables are exposed when:
- They exist in an exposed schema (default:
public) - No explicit
REVOKEhas been done - PostgREST can see them
Usage
Basic Table List
With Schema Information
Output Format
Risk Classification
Tables are classified by likely content:
Context Output
Hidden Tables
Some tables may not appear in the OpenAPI schema:
Schema Analysis
The skill also checks for non-public schemas:
Common Issues
❌ Problem: No tables found ✅ Solution:
- Check if anon key is valid
- Verify project URL is correct
- The API may be disabled in project settings
❌ Problem: Too many tables listed ✅ Solution: This may indicate overly permissive schema exposure. Consider:
❌ Problem: Sensitive tables exposed ✅ Solution: Either remove from public schema or implement strict RLS.
Recommendations by Table Type
User Tables
Order/Payment Tables
Secret Tables
MANDATORY: Progressive Context File Updates
⚠️ This skill MUST update tracking files PROGRESSIVELY during execution, NOT just at the end.
Critical Rule: Write As You Go
DO NOT batch all writes at the end. Instead:
- Before starting any action → Log the action to
.sb-pentest-audit.log - After each table discovered → Immediately update
.sb-pentest-context.json - After each significant step → Log completion to
.sb-pentest-audit.log
This ensures that if the skill is interrupted, crashes, or times out, all findings up to that point are preserved.
Required Actions (Progressive)
-
Update
.sb-pentest-context.jsonwith results: -
Log to
.sb-pentest-audit.log: -
If files don't exist, create them before writing.
FAILURE TO UPDATE CONTEXT FILES IS NOT ACCEPTABLE.
MANDATORY: Evidence Collection
📁 Evidence Directory: .sb-pentest-evidence/03-api-audit/tables/
Evidence Files to Create
Evidence Format
Add to curl-commands.sh
Related Skills
supabase-audit-tables-read— Test actual data accesssupabase-audit-rls— Verify RLS policiessupabase-audit-rpc— Check exposed functions


