All authors
yoanbernabeu avatar

Claude Skills by yoanbernabeu

github.com/yoanbernabeu
25 skillsA× 22B× 30 installs5 views
ReleaseA

Create a new release for grepai. Checks CI, determines version type, updates CHANGELOG and documentation, credits contributors, and creates GitHub release.

developmentgobash
0
1,174
Supabase Audit RlsA

Test Row Level Security (RLS) policies for common bypass vulnerabilities and misconfigurations.

securitygobash
0
26
Supabase Audit RpcA

List and test exposed PostgreSQL RPC functions for security issues and potential RLS bypass.

securitygobash
0
26
Supabase Audit Tables ListA

List all tables exposed via the Supabase PostgREST API to identify the attack surface.

securitygobash
0
26
Supabase Audit Tables ReadA

Attempt to read data from exposed tables to verify actual data exposure and RLS effectiveness.

securitygobash
0
26
Supabase Audit Auth ConfigA

Analyze Supabase authentication configuration for security weaknesses and misconfigurations.

securityjavascriptgo
0
26
Supabase Audit Auth SignupA

Test if user signup is open and identify potential abuse vectors in the registration process.

securitytypescriptgo
0
26
Supabase Audit Auth UsersA

Test for user enumeration vulnerabilities through various authentication endpoints.

securitytypescriptpython
0
26
Supabase Audit AuthenticatedA

Create a test user (with explicit permission) to audit what authenticated users can access vs anonymous users. Detects IDOR, cross-user access, and privilege escalation.

securityjavascriptgo
0
26
Supabase Audit FunctionsA

Discover and test Supabase Edge Functions for security vulnerabilities and misconfigurations.

securityjavascripttypescript
0
26
Supabase Audit RealtimeA

Test Supabase Realtime WebSocket channels for unauthorized subscriptions and data exposure.

securityjavascriptgo
0
26
Supabase Audit Buckets ListA

List all storage buckets and their configuration to identify the storage attack surface.

securitygobash
0
26
Supabase Audit Buckets PublicB

Identify storage buckets that are publicly accessible and may contain sensitive data.

securitytypescriptgo
0
26
Supabase Audit Buckets ReadB

Attempt to list and read files from storage buckets to verify access controls.

securitygobash
0
26
Supabase DetectA

Detect if a web application uses Supabase by analyzing client-side code, network patterns, and API endpoints.

securityjavascriptgo
0
26
Supabase EvidenceA

Initialize and manage the evidence collection directory for professional security audits with documented proof of findings.

securitygobash
0
26
Supabase Extract Anon KeyA

Extract the Supabase anon/public API key from client-side code. This key is expected in client apps but important for RLS testing.

securityjavascriptgo
0
26
Supabase Extract Db StringA

CRITICAL - Detect exposed PostgreSQL database connection strings in client-side code. Direct DB access is a P0 issue.

securityjavascripttypescript
0
25
Supabase Extract JwtA

Extract and decode Supabase-related JWTs from client-side code, cookies, and local storage patterns.

securityjavascriptgo
0
25
Supabase Extract Service KeyA

CRITICAL - Detect if the Supabase service_role key is leaked in client-side code. This is a P0 severity issue.

securityjavascripttypescript
0
25
Supabase Extract UrlA

Extract the Supabase project URL from client-side JavaScript code, environment variables, and configuration files.

securityjavascriptgo
0
25
Supabase HelpA

Quick reference for all Supabase security audit skills with usage examples and command overview.

documentationbashgit
0
25
Supabase PentestA

Orchestrate a complete Supabase security audit with guided step-by-step execution and ownership confirmation.

securitygoaws
0
25
Supabase Report CompareA

Compare two security audit reports to track remediation progress and identify new vulnerabilities.

securitygogit
0
25
Supabase ReportB

Generate a comprehensive Markdown security audit report with executive summary, findings, and remediation guidance.

documentationjavascripttypescript
0
25