Agent skill

Blueprint Supabase Security

by receptron in receptron/mulmoterminal

Review the built app against OWASP Top 10:2025 as an attacker would, fix what is exploitable, prove it on the local stack, and write the report.

MITAuto-check: notesSecurity

Install Blueprint Supabase Security

skills CLI
$ npx skills add receptron/mulmoterminal --skill blueprint-supabase-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install receptron/mulmoterminal blueprint-supabase-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/receptron/mulmoterminal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/blueprints/supabase/skills/security .claude/skills/blueprint-supabase-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
blueprint-supabase-security
GitHub stars
237
Token cost
~1.5k tokens
SKILL.md length
879 words
Files
1
Skills in repo
31
Repo updated
First seen
Licence
MIT

At a glance

Review the built app against OWASP Top 10:2025 as an attacker would, fix what is exploitable, prove it on the local stack, and write the report.

  • Works in 4 steps: Context. Read .blueprint/spec.md (above… → Audit, category by category (the list… → Fix every HIGH and MEDIUM finding, and… → …
  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers Method, What to look at in this app…, What the check does, and must… and The report, plus 1 more section
  • Calls yarn and git

What it does

Blueprint Supabase Security is an agent skill from receptron/mulmoterminal. Review the built app against OWASP Top 10:2025 as an attacker would, fix what is exploitable, prove it on the local stack, and write the report.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities. It works with Supabase. The repository describes itself as: Run multiple Claude Code and Codex sessions in parallel — a browser terminal grid that shows which agent needs you. Local, tmux-backed, MIT. The licence is MIT.

When your agent uses it

  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/blueprint-supabase-security”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Context. Read .blueprint/spec.md (above all "必ず詰める点" and the four columns per table), then
  2. Audit, category by category (the list below). Anything the screen checks, assume an attacker skips: they call
  3. Fix every HIGH and MEDIUM finding, and add a test to test/security.test.ts that fails without the fix.
  4. Report in .blueprint/security-review.md (format below).

What it can do on your machine

Read from SKILL.md and the folder at commit b3f6ff0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • yarn
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use yarn and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Blueprint Supabase Security loads about 1.5k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 879 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:36
    build and any `VITE_` value; `.env*.local` files are in `.gitignore`.
  • NoteMentions a .env fileSKILL.md:61
    _role key anywhere in `dist/` or in any `.env` file.
  • NoteMentions a .env fileSKILL.md:62
    - `.env` and `.env*.local` files, if present, ignored by `.gitignore`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from receptron/mulmoterminal at commit b3f6ff0, republished under its MIT licence (© receptron). 879 words, ~1,489 tokens.

Download SKILL.mdSave it as .claude/skills/blueprint-supabase-security/SKILL.md (or your agent's skills folder).
name
blueprint-supabase-security
description
Review the built app against OWASP Top 10:2025 as an attacker would, fix what is exploitable, prove it on the local stack, and write the report.

Security review

The app is built and runs. Before it is published, review it the way an attacker would read it, fix what is exploitable, and leave a report the person can read. The check does not take your word for it: it resets the local database to your migrations and seed, runs Supabase's own security linter, and tries every table as a stranger.

Method

  1. Context. Read .blueprint/spec.md (above all "必ず詰める点" and the four columns per table), then supabase/migrations/, supabase/seed.sql, supabase/config.toml, src/client/, vite.config.ts and package.json. Note who may do what, and where each rule is enforced.
  2. Audit, category by category (the list below). Anything the screen checks, assume an attacker skips: they call the API with the publishable key from the page.
  3. Fix every HIGH and MEDIUM finding, and add a test to test/security.test.ts that fails without the fix.
  4. Report in .blueprint/security-review.md (format below).

Severity: HIGH is directly exploitable (read or change someone's data, bypass sign-in, run code). MEDIUM needs a specific condition but the impact is real. LOW is defence in depth. Report a finding only when you can state how it is exploited and you are at least 70% sure. Do not report denial of service, rate limits, or missing validation on a field that cannot cause harm.

What to look at in this app (OWASP Top 10:2025)

  • A01 Broken Access Control — every table in public has row level security and a policy per allowed operation; ownership is checked in with check as well as using, so a row cannot be added or moved into someone else's name; a role comes from a table the user cannot write for themselves.
  • A02 Security Misconfiguration — _headers on every page, with the CSP's connect-src naming only this build's Supabase; sign-up open only as far as the spec says; nothing but public exposed through the API.
  • A03 Software Supply Chain Failures — yarn audit --groups dependencies has no high or critical.
  • A04 Cryptographic Failures — the page gets the publishable key only; the secret key stays out of src/, the build and any VITE_ value; .env*.local files are in .gitignore.
  • A05 Injection — no SQL built from strings in functions (format() with %L/%I, or parameters); the screen never renders input as HTML.
  • A06 Insecure Design — every rule the spec states is enforced in Postgres (policy, constraint or function), not only on the screen.
  • A07 Authentication Failures — Supabase Auth only; no password kept anywhere else; sign-out ends the session.
  • A08 Software or Data Integrity Failures — a security definer function checks its caller and pins search_path; an uploaded file is checked for type and size by a Storage policy.
  • A09 Security Logging and Alerting Failures — say where sign-in failures and data changes can be seen (the Supabase dashboard's logs) and what is not logged.
  • A10 Mishandling of Exceptional Conditions — a failed call is shown in words, and a refusal refuses: no policy or function lets a row through when a lookup fails or returns NULL.
Show full SKILL.md (387 more words)Show less

What the check does, and must see

  • Supabase's security linter (yarn supabase db advisors --local --type security) reports nothing.
  • Every table in public, starting from the seed: a signed-out visitor and a freshly signed-up user who owns nothing each try to read a seeded row, add a row (empty, and a copy of the seeded row's values), add that copy in the seeded row's owner's name in each user column (a foreign key to auth.users, a default of auth.uid(), or a column whose seeded value is a user's id), change a seeded row to its own values, move it into their own name (every user column set to them; declared only as update-owner, never covered by update), and delete it. Whatever gets through must be listed in .blueprint/public-access.json for that operation and that kind of user. What it cannot try, test/security.test.ts proves: an owner moving their OWN row into someone else's name (the strangers own nothing), and a policy that opens only for a value the seed does not hold.
  • The served page has a Content-Security-Policy with frame-ancestors 'none', X-Content-Type-Options: nosniff, no X-Powered-By, and no secret key or service_role key anywhere in dist/ or in any .env file.
  • .env and .env*.local files, if present, ignored by .gitignore.

The report

.blueprint/security-review.md, in the spec's language. One section per category, its heading naming the id (## A01 … through ## A10 …), every finding on a line of its own:

- HIGH fixed: <what was wrong, how it could be exploited> — <what changed, which test proves it>
- LOW accepted: <what, and why it is acceptable for this app>

The state is fixed, open or accepted; a HIGH or MEDIUM may be neither open nor accepted. A category with nothing to report says what was checked and "指摘なし".

Done when the check passes: the report covers A01–A10 with nothing HIGH or MEDIUM left open, the tests pass, the audit is clean, the linter reports nothing, the strangers get only what is declared, and the page sends the headers and no secret.

Always

  • Read .blueprint/spec.md first. It is the agreed specification; do not widen it.
  • When you need a decision, ask it through the blueprint question tool and stop. Do not guess.
  • Do not run git init: a new repository loses the folder's trust and the next unattended step stops at Claude Code's trust prompt. The user adds git themselves after the build if they want it.
  • Say you are done by stopping; the executor runs the check. Do not claim success yourself.

© receptron, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in blueprints/supabase/skills/security of receptron/mulmoterminal.

Open the folder on GitHubat commit b3f6ff0

Compare with similar skills

Blueprint Supabase Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Blueprint Supabase Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Blueprint Supabase Security this skillreceptron/mulmoterminal237—~1.5kAutomated safety check: NotesMIT
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
Vibe Checkbenavlabs/vibe-check118—~1.1kAutomated safety check: NotesMIT
Security Reviewaffaan-m/ECC276k3 repos~2.5kAutomated safety check: NotesMIT
Security Reviewaffaan-m/ECC276k2 repos~2.5kAutomated safety check: NotesMIT
Security Reviewaffaan-m/ECC276k2 repos~2.7kAutomated safety check: NotesMIT

Similar skills

  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • Vibe Check

    benavlabs/vibe-check

    Security audit for web apps, especially AI-built ("vibe coded") ones.

    118 GitHub stars~1.1k tokensUpdated 21 days ago
    SecurityAuto-check: notes
  • Security Review

    affaan-m/ECC

    在添加身份验证、处理用户输入、处理机密信息、创建API端点或实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。

    276k GitHub starsUsed in 3 repos~2.5k tokens
    SecurityAuto-check: notes
  • Security Review

    affaan-m/ECC

    認証の追加、ユーザー入力の処理、シークレットの操作、APIエンドポイントの作成、支払い/機密機能の実装時にこのスキルを使用します。包括的なセキュリティチェックリストとパターンを提供します。

    276k GitHub starsUsed in 2 repos~2.5k tokens
    SecurityAuto-check: notes
  • Security Review

    affaan-m/ECC

    인증 추가, 사용자 입력 처리, 시크릿 관리, API 엔드포인트 생성, 결제/민감한 기능 구현 시 이 스킬을 사용하세요.

    276k GitHub starsUsed in 2 repos~2.7k tokens
    SecurityAuto-check: notes
  • Security Review

    affaan-m/ECC

    Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın.

    276k GitHub starsUsed in 1 repo~3.2k tokens
    SecurityAuto-check: notes

More from receptron/mulmoterminal

All 31 skills in this repo
  • Mulmoterminal Bug Report

    receptron/mulmoterminal

    Help desk for "MulmoTerminal is broken". An agent skill from receptron/mulmoterminal.

    237 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Mulmoterminal Decisions

    receptron/mulmoterminal

    Check what this project's humans have already been asked, and how they answered, before asking them something similar.

    237 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Mulmoterminal Help

    receptron/mulmoterminal

    Help desk for questions about MulmoTerminal itself — what it can do, how a feature or a part of the screen works, how to set something up, what is new in this version or in the latest one.

    237 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Mulmoterminal Notify

    receptron/mulmoterminal

    Decide which moments MulmoTerminal beeps or pushes for, and what each one plays — soundKinds, sounds and pushKinds in ~/.mulmoterminal/config.json, plus a per-project sound / sounds in…

    237 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Mulmoterminal Theme

    receptron/mulmoterminal

    Build a colour scheme of your own for MulmoTerminal — one that joins Midnight, Nord, Daylight and Solarized in Settings' theme picker and can then be pinned per project.

    237 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Blueprint Ask Answer

    receptron/mulmoterminal

    Answer each question from the named documents only, quoting where the answer is written, or saying plainly that the documents do not say — changing nothing yet.

    237 GitHub stars~780 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Blueprint Supabase Security

What does Blueprint Supabase Security do?

Review the built app against OWASP Top 10:2025 as an attacker would, fix what is exploitable, prove it on the local stack, and write the report. Blueprint Supabase Security is an agent skill from receptron/mulmoterminal. Review the built app against OWASP Top 10:2025 as an attacker would, fix what is exploitable, prove it on the local stack, and write the report.

When should I use Blueprint Supabase Security?

Blueprint Supabase Security fits situations like: tasks that involve Web application vulnerabilities.

How do I install Blueprint Supabase Security in Claude Code?

Run `npx skills add receptron/mulmoterminal --skill blueprint-supabase-security -a claude-code`. Or copy the skill folder (blueprints/supabase/skills/security in receptron/mulmoterminal) into .claude/skills/blueprint-supabase-security in your project. Claude Code loads it when a task matches its description.

How do I install Blueprint Supabase Security in Codex?

Run `npx skills add receptron/mulmoterminal --skill blueprint-supabase-security -a codex`. Or copy the skill folder (blueprints/supabase/skills/security in receptron/mulmoterminal) into .agents/skills/blueprint-supabase-security in your project. Codex loads it when a task matches its description.

Can I use Blueprint Supabase Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add receptron/mulmoterminal --skill blueprint-supabase-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/blueprint-supabase-security, .gemini/skills/blueprint-supabase-security, .github/skills/blueprint-supabase-security and .opencode/skills/blueprint-supabase-security in your project.

What does Blueprint Supabase Security need to run?

Going by SKILL.md and its folder, Blueprint Supabase Security needs the command-line tools its instructions call (yarn and git).

Does Blueprint Supabase Security access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Blueprint Supabase Security safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Blueprint Supabase Security use?

Blueprint Supabase Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Blueprint Supabase Security use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Blueprint Supabase Security?

Skills that share tags, products or a category with Blueprint Supabase Security: Security Review (jewbetcha/opentrace, 116 stars), Vibe Check (benavlabs/vibe-check, 118 stars), Security Review (affaan-m/ECC, 276k stars) and Security Review (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Blueprint Supabase Security?

receptron (a GitHub organization) maintains it in receptron/mulmoterminal, which has 237 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 10, 2026.

Source: receptron/mulmoterminal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.