Security Review
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
Review the built app against OWASP Top 10:2025 as an attacker would, fix what is exploitable, prove it on the local stack, and write the report.
$ npx skills add receptron/mulmoterminal --skill blueprint-supabase-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install receptron/mulmoterminal blueprint-supabase-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/receptron/mulmoterminal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/blueprints/supabase/skills/security .claude/skills/blueprint-supabase-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "blueprint-supabase-security" agent skill from https://github.com/receptron/mulmoterminal/tree/main/blueprints/supabase/skills/security into .claude/skills/blueprint-supabase-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blueprint-supabase-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/receptron/mulmoterminal/tree/main/blueprints/supabase/skills/securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add receptron/mulmoterminal --skill blueprint-supabase-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install receptron/mulmoterminal blueprint-supabase-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/receptron/mulmoterminal.git skills-src && mkdir -p .agents/skills && cp -r skills-src/blueprints/supabase/skills/security .agents/skills/blueprint-supabase-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "blueprint-supabase-security" agent skill from https://github.com/receptron/mulmoterminal/tree/main/blueprints/supabase/skills/security into .agents/skills/blueprint-supabase-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blueprint-supabase-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add receptron/mulmoterminal --skill blueprint-supabase-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install receptron/mulmoterminal blueprint-supabase-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/receptron/mulmoterminal.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/blueprints/supabase/skills/security .cursor/skills/blueprint-supabase-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "blueprint-supabase-security" agent skill from https://github.com/receptron/mulmoterminal/tree/main/blueprints/supabase/skills/security into .cursor/skills/blueprint-supabase-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blueprint-supabase-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/receptron/mulmoterminal.git --path blueprints/supabase/skills/security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add receptron/mulmoterminal --skill blueprint-supabase-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install receptron/mulmoterminal blueprint-supabase-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/receptron/mulmoterminal.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/blueprints/supabase/skills/security .gemini/skills/blueprint-supabase-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "blueprint-supabase-security" agent skill from https://github.com/receptron/mulmoterminal/tree/main/blueprints/supabase/skills/security into .gemini/skills/blueprint-supabase-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blueprint-supabase-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install receptron/mulmoterminal blueprint-supabase-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add receptron/mulmoterminal --skill blueprint-supabase-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/receptron/mulmoterminal.git skills-src && mkdir -p .github/skills && cp -r skills-src/blueprints/supabase/skills/security .github/skills/blueprint-supabase-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "blueprint-supabase-security" agent skill from https://github.com/receptron/mulmoterminal/tree/main/blueprints/supabase/skills/security into .github/skills/blueprint-supabase-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blueprint-supabase-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add receptron/mulmoterminal --skill blueprint-supabase-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install receptron/mulmoterminal blueprint-supabase-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/receptron/mulmoterminal.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/blueprints/supabase/skills/security .opencode/skills/blueprint-supabase-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "blueprint-supabase-security" agent skill from https://github.com/receptron/mulmoterminal/tree/main/blueprints/supabase/skills/security into .opencode/skills/blueprint-supabase-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "blueprint-supabase-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
blueprint-supabase-securityReview the built app against OWASP Top 10:2025 as an attacker would, fix what is exploitable, prove it on the local stack, and write the report.
Blueprint Supabase Security is an agent skill from receptron/mulmoterminal. Review the built app against OWASP Top 10:2025 as an attacker would, fix what is exploitable, prove it on the local stack, and write the report.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Web application vulnerabilities. It works with Supabase. The repository describes itself as: Run multiple Claude Code and Codex sessions in parallel — a browser terminal grid that shows which agent needs you. Local, tmux-backed, MIT. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit b3f6ff0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
yarngitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use yarn and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Blueprint Supabase Security loads about 1.5k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 879 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
build and any `VITE_` value; `.env*.local` files are in `.gitignore`._role key anywhere in `dist/` or in any `.env` file.- `.env` and `.env*.local` files, if present, ignored by `.gitignore`.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from receptron/mulmoterminal at commit b3f6ff0, republished under its MIT licence (© receptron). 879 words, ~1,489 tokens.
.claude/skills/blueprint-supabase-security/SKILL.md (or your agent's skills folder).The app is built and runs. Before it is published, review it the way an attacker would read it, fix what is exploitable, and leave a report the person can read. The check does not take your word for it: it resets the local database to your migrations and seed, runs Supabase's own security linter, and tries every table as a stranger.
.blueprint/spec.md (above all "必ず詰める点" and the four columns per table), then
supabase/migrations/, supabase/seed.sql, supabase/config.toml, src/client/, vite.config.ts and
package.json. Note who may do what, and where each rule is enforced.test/security.test.ts that fails without the fix..blueprint/security-review.md (format below).Severity: HIGH is directly exploitable (read or change someone's data, bypass sign-in, run code). MEDIUM needs a specific condition but the impact is real. LOW is defence in depth. Report a finding only when you can state how it is exploited and you are at least 70% sure. Do not report denial of service, rate limits, or missing validation on a field that cannot cause harm.
public has row level security and a policy per allowed
operation; ownership is checked in with check as well as using, so a row cannot be added or moved into someone
else's name; a role comes from a table the user cannot write for themselves._headers on every page, with the CSP's connect-src naming only this
build's Supabase; sign-up open only as far as the spec says; nothing but public exposed through the API.yarn audit --groups dependencies has no high or critical.src/, the
build and any VITE_ value; .env*.local files are in .gitignore.format() with %L/%I, or parameters); the screen
never renders input as HTML.security definer function checks its caller and pins
search_path; an uploaded file is checked for type and size by a Storage policy.yarn supabase db advisors --local --type security) reports nothing.public, starting from the seed: a signed-out visitor and a freshly signed-up user who owns
nothing each try to read a seeded row, add a row (empty, and a copy of the seeded row's values), add that copy in
the seeded row's owner's name in each user column (a foreign key to auth.users, a default of auth.uid(), or a
column whose seeded value is a user's id),
change a seeded row to its own values, move it into their own name (every user column set to them; declared only
as update-owner, never covered by update), and delete it. Whatever gets through must be listed in .blueprint/public-access.json for that operation and that kind
of user. What it cannot try, test/security.test.ts proves: an owner moving their OWN row into someone else's name
(the strangers own nothing), and a policy that opens only for a value the seed does not hold.frame-ancestors 'none', X-Content-Type-Options: nosniff,
no X-Powered-By, and no secret key or service_role key anywhere in dist/ or in any .env file..env and .env*.local files, if present, ignored by .gitignore..blueprint/security-review.md, in the spec's language. One section per category, its heading naming the id
(## A01 … through ## A10 …), every finding on a line of its own:
- HIGH fixed: <what was wrong, how it could be exploited> — <what changed, which test proves it>
- LOW accepted: <what, and why it is acceptable for this app>The state is fixed, open or accepted; a HIGH or MEDIUM may be neither open nor accepted. A category with
nothing to report says what was checked and "指摘なし".
Done when the check passes: the report covers A01–A10 with nothing HIGH or MEDIUM left open, the tests pass, the audit is clean, the linter reports nothing, the strangers get only what is declared, and the page sends the headers and no secret.
.blueprint/spec.md first. It is the agreed specification; do not widen it.git init: a new repository loses the folder's trust and the next unattended step stops at Claude
Code's trust prompt. The user adds git themselves after the build if they want it.© receptron, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in blueprints/supabase/skills/security of receptron/mulmoterminal.
Open the folder on GitHubat commit b3f6ff0
Blueprint Supabase Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Blueprint Supabase Security this skillreceptron/mulmoterminal | 237 | — | ~1.5k | Automated safety check: Notes | MIT | |
| Security Reviewjewbetcha/opentrace | 116 | 18 repos | ~3.1k | Automated safety check: Notes | MIT | |
| Vibe Checkbenavlabs/vibe-check | 118 | — | ~1.1k | Automated safety check: Notes | MIT | |
| Security Reviewaffaan-m/ECC | 276k | 3 repos | ~2.5k | Automated safety check: Notes | MIT | |
| Security Reviewaffaan-m/ECC | 276k | 2 repos | ~2.5k | Automated safety check: Notes | MIT | |
| Security Reviewaffaan-m/ECC | 276k | 2 repos | ~2.7k | Automated safety check: Notes | MIT |
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
benavlabs/vibe-check
Security audit for web apps, especially AI-built ("vibe coded") ones.
affaan-m/ECC
在添加身份验证、处理用户输入、处理机密信息、创建API端点或实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。
affaan-m/ECC
認証の追加、ユーザー入力の処理、シークレットの操作、APIエンドポイントの作成、支払い/機密機能の実装時にこのスキルを使用します。包括的なセキュリティチェックリストとパターンを提供します。
affaan-m/ECC
인증 추가, 사용자 입력 처리, 시크릿 관리, API 엔드포인트 생성, 결제/민감한 기능 구현 시 이 스킬을 사용하세요.
affaan-m/ECC
Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın.
receptron/mulmoterminal
Help desk for "MulmoTerminal is broken". An agent skill from receptron/mulmoterminal.
receptron/mulmoterminal
Check what this project's humans have already been asked, and how they answered, before asking them something similar.
receptron/mulmoterminal
Help desk for questions about MulmoTerminal itself — what it can do, how a feature or a part of the screen works, how to set something up, what is new in this version or in the latest one.
receptron/mulmoterminal
Decide which moments MulmoTerminal beeps or pushes for, and what each one plays — soundKinds, sounds and pushKinds in ~/.mulmoterminal/config.json, plus a per-project sound / sounds in…
receptron/mulmoterminal
Build a colour scheme of your own for MulmoTerminal — one that joins Midnight, Nord, Daylight and Solarized in Settings' theme picker and can then be pinned per project.
receptron/mulmoterminal
Answer each question from the named documents only, quoting where the answer is written, or saying plainly that the documents do not say — changing nothing yet.
Works with
Categories
Review the built app against OWASP Top 10:2025 as an attacker would, fix what is exploitable, prove it on the local stack, and write the report. Blueprint Supabase Security is an agent skill from receptron/mulmoterminal. Review the built app against OWASP Top 10:2025 as an attacker would, fix what is exploitable, prove it on the local stack, and write the report.
Blueprint Supabase Security fits situations like: tasks that involve Web application vulnerabilities.
Run `npx skills add receptron/mulmoterminal --skill blueprint-supabase-security -a claude-code`. Or copy the skill folder (blueprints/supabase/skills/security in receptron/mulmoterminal) into .claude/skills/blueprint-supabase-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add receptron/mulmoterminal --skill blueprint-supabase-security -a codex`. Or copy the skill folder (blueprints/supabase/skills/security in receptron/mulmoterminal) into .agents/skills/blueprint-supabase-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add receptron/mulmoterminal --skill blueprint-supabase-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/blueprint-supabase-security, .gemini/skills/blueprint-supabase-security, .github/skills/blueprint-supabase-security and .opencode/skills/blueprint-supabase-security in your project.
Going by SKILL.md and its folder, Blueprint Supabase Security needs the command-line tools its instructions call (yarn and git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Blueprint Supabase Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Blueprint Supabase Security: Security Review (jewbetcha/opentrace, 116 stars), Vibe Check (benavlabs/vibe-check, 118 stars), Security Review (affaan-m/ECC, 276k stars) and Security Review (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
receptron (a GitHub organization) maintains it in receptron/mulmoterminal, which has 237 GitHub stars. The repository holds 31 skills in this directory. The repository was last updated on October 10, 2026.
Source: receptron/mulmoterminal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.