supabase-extract-service-key

Community

Detect Supabase service key leaks.

Authormarvinbiss
Version1.0.0
Installs0

System Documentation

What problem does it solve?

This Skill prevents critical security breaches by detecting if the highly sensitive Supabase service_role key is accidentally exposed in client-side code, which bypasses all security policies.

Core Features & Use Cases

  • Critical Security Audit: Identifies the presence of the service_role key in client-side JavaScript bundles, inline scripts, or source maps.
  • Detailed Impact Analysis: Explains the severe consequences of exposure, including full database access, RLS bypass, and user impersonation.
  • Use Case: During a routine security audit of a web application using Supabase, this skill is run to ensure the service_role key is not present in any publicly accessible client-side code, preventing a P0 severity vulnerability.

Quick Start

Check for service key leaks on https://myapp.example.com.

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: supabase-extract-service-key
Download link: https://github.com/marvinbiss/servicesartisans/archive/main.zip#supabase-extract-service-key

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.