supabase-audit-auth-config
Analyze Supabase authentication configuration for security weaknesses and misconfigurations.
What this skill does
# Authentication Configuration Audit
> ๐ด **CRITICAL: PROGRESSIVE FILE UPDATES REQUIRED**
>
> You MUST write to context files **AS YOU GO**, not just at the end.
> - Write to `.sb-pentest-context.json` **IMMEDIATELY after each setting analyzed**
> - Log to `.sb-pentest-audit.log` **BEFORE and AFTER each test**
> - **DO NOT** wait until the skill completes to update files
> - If the skill crashes or is interrupted, all prior findings must already be saved
>
> **This is not optional. Failure to write progressively is a critical error.**
This skill analyzes the authentication configuration of a Supabase project.
## When to Use This Skill
- To review authentication security settings
- Before production deployment
- When auditing auth-related vulnerabilities
- As part of comprehensive security review
## Prerequisites
- Supabase URL and anon key available
- Detection completed
## Auth Endpoints
Supabase Auth (GoTrue) exposes:
```
https://[project].supabase.co/auth/v1/
```
| Endpoint | Purpose |
|----------|---------|
| `/auth/v1/settings` | Public settings (limited) |
| `/auth/v1/signup` | User registration |
| `/auth/v1/token` | Authentication |
| `/auth/v1/user` | Current user info |
| `/auth/v1/recover` | Password recovery |
## What Can Be Detected
From the public API, we can detect:
| Setting | Detection Method |
|---------|------------------|
| Email auth enabled | Attempt signup |
| Phone auth enabled | Check settings |
| OAuth providers | Check settings |
| Signup disabled | Attempt signup |
| Email confirmation | Signup response |
| Password requirements | Error messages |
## Usage
### Basic Auth Audit
```
Audit authentication configuration
```
### Check Specific Features
```
Check if signup is open and what providers are enabled
```
## Output Format
```
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
AUTHENTICATION CONFIGURATION AUDIT
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Project: abc123def.supabase.co
Auth Endpoint: https://abc123def.supabase.co/auth/v1/
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Authentication Methods
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Email/Password: โ
Enabled
โโโ Signup: โ
Open (anyone can register)
โโโ Email Confirmation: โ NOT REQUIRED โ P1 Issue
โโโ Password Min Length: 6 characters โ P2 Consider longer
โโโ Secure Password Check: Unknown
Phone/SMS: โ
Enabled
โโโ Provider: Twilio
Magic Link: โ
Enabled
โโโ OTP Expiry: 300 seconds (5 min)
OAuth Providers Detected: 3
โโโ Google: โ
Enabled
โโโ GitHub: โ
Enabled
โโโ Discord: โ
Enabled
Anonymous Auth: โ
Enabled โ Review if intended
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Security Settings
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Rate Limiting:
โโโ Signup: 3/hour per IP (good)
โโโ Token: 30/hour per IP (good)
โโโ Recovery: 3/hour per IP (good)
Session Configuration:
โโโ JWT Expiry: 3600 seconds (1 hour)
โโโ Refresh Token Rotation: Unknown
โโโ Inactivity Timeout: Unknown
Security Headers:
โโโ CORS: Configured
โโโ Allowed Origins: * (wildcard) โ P2 Consider restricting
โโโ Credentials: Allowed
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Findings
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
๐ P1: Email Confirmation Disabled
Issue: Users can signup and immediately access the app
without verifying their email address.
Risks:
โโโ Fake accounts with invalid emails
โโโ Typosquatting ([email protected])
โโโ No verified communication channel
โโโ Potential for abuse
Recommendation:
Supabase Dashboard โ Authentication โ Email Templates
โ Enable "Confirm email"
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
๐ก P2: Short Minimum Password Length
Issue: Minimum password length is 6 characters.
Recommendation: Increase to 8-12 characters minimum.
Supabase Dashboard โ Authentication โ Settings
โ Minimum password length
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
๐ก P2: Wildcard CORS Origin
Issue: CORS allows requests from any origin (*).
Recommendation: Restrict to your domains only.
Supabase Dashboard โ Authentication โ URL Configuration
โ Site URL and Redirect URLs
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โน๏ธ INFO: Anonymous Auth Enabled
Note: Anonymous authentication is enabled.
This is fine if intentional (guest access).
Review if you expect all users to be authenticated.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Summary
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Auth Methods: 5 enabled
OAuth Providers: 3
Findings:
โโโ P1 (High): 1 - Email confirmation disabled
โโโ P2 (Medium): 2 - Password length, CORS
โโโ Info: 1 - Anonymous auth enabled
Recommended Actions:
1. Enable email confirmation
2. Increase minimum password length
3. Restrict CORS to specific domains
4. Review if anonymous auth is needed
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
## Security Checklist
### Email Authentication
| Setting | Recommended | Risk if Wrong |
|---------|-------------|---------------|
| Email Confirmation | โ
Required | Fake accounts |
| Password Length | โฅ8 chars | Weak passwords |
| Password Complexity | Enable | Easy to guess |
| Rate Limiting | Enable | Brute force |
### OAuth Configuration
| Setting | Recommended | Risk if Wrong |
|---------|-------------|---------------|
| Verified providers only | Yes | Account takeover |
| Proper redirect URLs | Specific URLs | OAuth redirect attacks |
| State parameter | Enabled | CSRF attacks |
### Session Security
| Setting | Recommended | Risk if Wrong |
|---------|-------------|---------------|
| Short JWT expiry | 1 hour or less | Token theft |
| Refresh token rotation | Enabled | Token reuse |
| Secure cookie flags | HttpOnly, Secure, SameSite | XSS, CSRF |
## Context Output
```json
{
"auth_config": {
"timestamp": "2025-01-31T12:30:00Z",
"methods": {
"email": {
"enabled": true,
"signup_open": true,
"email_confirmation": false,
"min_password_length": 6
},
"phone": {
"enabled": true,
"provider": "twilio"
},
"magic_link": {
"enabled": true,
"otp_expiry": 300
},
"oauth": {
"enabled": true,
"providers": ["google", "github", "discord"]
},
"anonymous": {
"enabled": true
}
},
"findings": [
{
"severity": "P1",
"issue": "Email confirmation disabled",
"recommendation": "Enable email confirmation in dashboard"
}
]
}
}
```
## Common Auth Vulnerabilities
### 1. No Email Confirmation
```javascript
// User can signup with any email
const { data, error } = await supabase.auth.signUp({
email: '[email protected]', // No verification needed
password: 'password123'
})
// User is immediately authenticated
```
### 2. Weak Password Policy
```javascript
// Weak password accepted
await supabase.auth.signUp({
email: '[email protected]',
password: '123456' // Accepted with min length 6
})
```
### 3. Open Signup When Not Needed
If your app should only have admin-created users:
```sql
-- Disable public signup via dashboard
-- Or use invite-only flow
```
## Remediation Examples
### Enable Email Confirmation
1. Supabase Dashboard โ Authentication โ Email Templates
2. Enable "Confirm email"
3. Customize confirmation email template
4. Handle unconfirmed users in your app
### Strengthen Password Requirements
1. Dashboard โ Authentication โ Settings
2. Set minimum length to 8+
3. Consider enabling password strength checks
### Restrict CORS
1. Dashboard โ Authentication โ URL Configuration
2. Set specific Site URL
3. Add only your domains to Redirect URLs
4. Remove wildcard entries
## MANDATORY: Progressive Context File Updates
โ ๏ธ **This skill MUST update tracking files PROGRESSIVELY during execution, Related in Security
mac-ops
IncludedComprehensive macOS workstation operations โ diagnose kernel panics, identify failing drives, audit launchd startup items, decode wake reasons, triage TCC permission denials, manage APFS snapshots, recover from no-boot. Use for: Mac is slow, slow bootup, won't boot, kernel panic, kernel_task hot, mds_stores CPU, photoanalysisd, cloudd, login loop, gray screen, sleep wake failure, drive failing, IO errors, APFS snapshots eating space, Time Machine local snapshots, Spotlight indexing, launchd, LaunchAgent, LaunchDaemon, login items, TCC permissions, Full Disk Access, Screen Recording denied, Gatekeeper, quarantine, com.apple.quarantine, app is damaged, helper tool, /Library/PrivilegedHelperTools, pmset, wake reasons, dark wake, sysdiagnose, panic.ips, DiagnosticReports, configuration profile, MDM profile, remote diagnostics over SSH.
a11y-audit
IncludedRun accessibility audits on web projects combining automated scanning (axe-core, Lighthouse) with WCAG 2.1 AA compliance mapping, manual check guidance, and structured reporting. Output is configurable: markdown report only, markdown plus machine-readable JSON, or markdown plus issue tracker integration. Use this skill whenever the user mentions "accessibility audit", "a11y audit", "WCAG audit", "accessibility check", "compliance scan", or asks to check a web project for accessibility issues. Also trigger when the user wants to verify WCAG conformance or map findings to a specific standard (CAN-ASC-6.2, EN 301 549, ADA/AODA).
erpclaw
IncludedAI-native ERP system with self-extending OS. Full accounting, invoicing, inventory, purchasing, tax, billing, HR, payroll, advanced accounting (ASC 606/842, intercompany, consolidation), and financial reporting. 413 actions across 14 domains, 43 expansion modules. Constitutional guardrails, adversarial audit, schema migration. Double-entry GL, immutable audit trail, US GAAP.
assess
IncludedAssesses and rates quality 0-10 across multiple dimensions (correctness, maintainability, security, performance, testability, simplicity) with pros/cons analysis. Compares against project conventions and prior decisions from memory. Produces structured evaluation reports with actionable improvement suggestions. Use when evaluating code, designs, architectures, or comparing alternative approaches.
spring-boot-security-jwt
IncludedProvides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
code-hardcode-audit
IncludedDetect hardcoded values, magic numbers, and leaked secrets. TRIGGERS - hardcode audit, magic numbers, PLR2004, secret scanning.