Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
yoanbernabeu avatar

Supabase Audit Auth Signup

  • 309 installs
  • 60 repo stars
  • Updated January 31, 2026
  • yoanbernabeu/supabase-pentest-skills

supabase-audit-auth-signup is a security agent skill that audits Supabase user registration flows for open signup, abuse vectors, and misconfigurations before shipping auth features.

About

supabase-audit-auth-signup is a yoanbernabeu supabase-pentest-skills workflow that tests whether Supabase user signup is open and identifies abuse vectors in the registration process. The skill mandates progressive file updates: writing findings to .sb-pentest-context.json immediately after each test and logging to .sb-pentest-audit.log before and after every test so interrupted runs retain partial results. Developers reach for supabase-audit-auth-signup before shipping apps that expose public registration endpoints on Supabase Auth. The audit focuses on signup flow misconfigurations such as unrestricted account creation paths that enable spam, enumeration, or privilege abuse. It is part of a structured Supabase pentest skill suite designed for agent-driven security reviews rather than manual browser probing alone.

  • Audits Supabase signup/registration flow
  • Identifies auth misconfigurations at registration
  • Progressive file updates ensure findings persist
  • Part of supabase-pentest-skills suite

Supabase Audit Auth Signup by the numbers

  • 309 all-time installs (skills.sh)
  • +13 installs in the week ending Jul 28, 2026 (Skillselion tracking)
  • Ranked #628 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/yoanbernabeu/supabase-pentest-skills --skill supabase-audit-auth-signup

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs309
repo stars60
Last updatedJanuary 31, 2026
Repositoryyoanbernabeu/supabase-pentest-skills

How do you audit Supabase signup for abuse vectors?

Audits the Supabase user registration (signup) flow for security vulnerabilities and misconfigurations before shipping.

Who is it for?

Developers shipping Supabase Auth who need pre-release signup flow pentests with progressive audit logging.

Skip if: Applications not using Supabase Auth or teams needing general OWASP scans unrelated to Supabase registration endpoints.

When should I use this skill?

User asks to audit Supabase signup, test open registration, or find auth abuse vectors before shipping.

What you get

.sb-pentest-context.json findings, .sb-pentest-audit.log entries, and documented signup abuse vectors for Supabase Auth.

  • .sb-pentest-context.json
  • .sb-pentest-audit.log
  • signup audit findings

By the numbers

  • Writes to .sb-pentest-context.json after each completed test
  • Logs to .sb-pentest-audit.log before and after each test

Files

SKILL.mdMarkdownGitHub ↗

Signup Flow Audit

🔴 CRITICAL: PROGRESSIVE FILE UPDATES REQUIRED

>

You MUST write to context files AS YOU GO, not just at the end.
- Write to .sb-pentest-context.json IMMEDIATELY after each test completed
- Log to .sb-pentest-audit.log BEFORE and AFTER each test
- DO NOT wait until the skill completes to update files
- If the skill crashes or is interrupted, all prior findings must already be saved

>

This is not optional. Failure to write progressively is a critical error.

This skill tests the user registration flow for security issues and misconfigurations.

When to Use This Skill

  • To verify if signup is appropriately restricted
  • To test for signup abuse vectors
  • To check rate limiting on registration
  • As part of authentication security audit

Prerequisites

  • Supabase URL and anon key available
  • Auth config audit completed (recommended)

Why Signup Security Matters

Open signup can lead to:

RiskDescription
Spam accountsBots creating fake accounts
Resource abuseFree tier exploitation
Email spamUsing your service to send emails
Data pollutionFake data in your database
Attack surfaceMore accounts = more attack vectors

Tests Performed

TestPurpose
Signup availabilityIs registration open?
Email validationDoes it accept invalid emails?
Rate limitingCan we create many accounts?
Disposable emailsAre temp emails blocked?
Password policyWhat passwords are accepted?
Response informationWhat info is leaked?

Usage

Basic Signup Test

Test signup security on my Supabase project

Check Specific Aspects

Test if disposable emails are blocked for signup

Output Format

═══════════════════════════════════════════════════════════
 SIGNUP FLOW AUDIT
═══════════════════════════════════════════════════════════

 Project: abc123def.supabase.co
 Endpoint: /auth/v1/signup

 ─────────────────────────────────────────────────────────
 Signup Availability
 ─────────────────────────────────────────────────────────

 Status: ✅ OPEN (Anyone can register)

 Test Result:
 POST /auth/v1/signup
 Body: {"email": "test-xxxxx@example.com", "password": "TestPass123!"}
 Response: 200 OK - Account created

 Assessment: Signup is publicly available.
             Review if this is intended.

 ─────────────────────────────────────────────────────────
 Email Validation
 ─────────────────────────────────────────────────────────

 Valid email formats:
 ├── user@domain.com: ✅ Accepted (expected)
 ├── user+tag@domain.com: ✅ Accepted (expected)
 └── user@subdomain.domain.com: ✅ Accepted (expected)

 Invalid email formats:
 ├── user@: ❌ Rejected (good)
 ├── @domain.com: ❌ Rejected (good)
 ├── user@.com: ❌ Rejected (good)
 └── not-an-email: ❌ Rejected (good)

 Disposable Email Test:
 ├── user@mailinator.com: ✅ Accepted ← 🟠 P2
 ├── user@tempmail.com: ✅ Accepted ← 🟠 P2
 └── user@guerrillamail.com: ✅ Accepted ← 🟠 P2

 Finding: Disposable emails are not blocked.
 Risk: Users can create throwaway accounts.

 Recommendation: Consider using an email validation
 service or blocklist in your application logic.

 ─────────────────────────────────────────────────────────
 Password Policy
 ─────────────────────────────────────────────────────────

 Minimum Length Test:
 ├── "12345" (5 chars): ❌ Rejected
 ├── "123456" (6 chars): ✅ Accepted ← P2 Short
 └── "1234567890" (10 chars): ✅ Accepted

 Current Policy: Minimum 6 characters

 Weak Password Test:
 ├── "password": ✅ Accepted ← 🟠 P2
 ├── "123456": ✅ Accepted ← 🟠 P2
 ├── "qwerty123": ✅ Accepted ← 🟠 P2
 └── "letmein": ✅ Accepted ← 🟠 P2

 Finding: Common weak passwords are accepted.

 Recommendation:
 1. Increase minimum length to 8+ characters
 2. Consider password strength requirements
 3. Check against common password lists

 ─────────────────────────────────────────────────────────
 Rate Limiting
 ─────────────────────────────────────────────────────────

 Signup Rate Test (same IP):
 ├── Request 1: ✅ 200 OK
 ├── Request 2: ✅ 200 OK
 ├── Request 3: ✅ 200 OK
 ├── Request 4: ❌ 429 Too Many Requests
 └── Retry-After: 3600 seconds

 Rate Limit: 3 signups/hour per IP
 Assessment: ✅ Rate limiting is active (good)

 ─────────────────────────────────────────────────────────
 Information Disclosure
 ─────────────────────────────────────────────────────────

 Existing Email Test:
 POST /auth/v1/signup (with existing email)
 Response: "User already registered"

 Finding: 🟠 P2 - Response reveals email existence

 This allows:
 ├── Email enumeration attacks
 ├── Knowing if someone has an account
 └── Targeted phishing attempts

 Recommendation: Use generic message like
 "Check your email to continue" for both new
 and existing accounts.

 ─────────────────────────────────────────────────────────
 Email Confirmation
 ─────────────────────────────────────────────────────────

 Status: ❌ NOT REQUIRED (confirmed in auth-config)

 Test: Created account and checked session
 Result: User immediately authenticated without
         email confirmation.

 ─────────────────────────────────────────────────────────
 Summary
 ─────────────────────────────────────────────────────────

 Signup: Open to public
 Rate Limiting: ✅ Active (3/hour)
 Email Confirmation: ❌ Not required

 Findings:
 ├── P1: Email confirmation disabled
 ├── P2: Disposable emails accepted
 ├── P2: Weak passwords accepted
 └── P2: Email enumeration possible

 Security Score: 5/10

 Priority Actions:
 1. Enable email confirmation
 2. Strengthen password policy
 3. Consider disposable email blocking
 4. Use generic error messages

═══════════════════════════════════════════════════════════

Test Details

Disposable Email Detection

Common disposable email domains tested:

  • mailinator.com
  • tempmail.com
  • guerrillamail.com
  • 10minutemail.com
  • throwaway.email

Weak Password List

Common passwords tested:

  • password, password123
  • 123456, 12345678
  • qwerty, qwerty123
  • letmein, welcome
  • admin, administrator

Rate Limit Testing

Attempt 1: 200 OK
Attempt 2: 200 OK
Attempt 3: 200 OK
Attempt 4: 429 Too Many Requests

Context Output

{
  "signup_audit": {
    "timestamp": "2025-01-31T13:00:00Z",
    "signup_open": true,
    "rate_limit": {
      "enabled": true,
      "limit": 3,
      "period": "hour"
    },
    "email_validation": {
      "basic_validation": true,
      "disposable_blocked": false
    },
    "password_policy": {
      "min_length": 6,
      "weak_passwords_blocked": false
    },
    "information_disclosure": {
      "email_enumeration": true
    },
    "findings": [
      {
        "severity": "P1",
        "issue": "Email confirmation disabled"
      },
      {
        "severity": "P2",
        "issue": "Disposable emails accepted"
      },
      {
        "severity": "P2",
        "issue": "Weak passwords accepted"
      },
      {
        "severity": "P2",
        "issue": "Email enumeration possible"
      }
    ]
  }
}

Remediation Examples

Block Disposable Emails

// In your signup handler or Edge Function
import { isDisposable } from 'email-validator-package';

if (isDisposable(email)) {
  throw new Error('Please use a permanent email address');
}

Strengthen Password Requirements

// Custom password validation
function validatePassword(password: string): boolean {
  if (password.length < 8) return false;
  if (!/[A-Z]/.test(password)) return false;
  if (!/[a-z]/.test(password)) return false;
  if (!/[0-9]/.test(password)) return false;
  return true;
}

Prevent Email Enumeration

// Always return same message
async function signup(email, password) {
  try {
    await supabase.auth.signUp({ email, password });
  } catch (error) {
    // Don't reveal if email exists
  }
  return { message: 'Check your email to continue' };
}

Restrict Signup

If signup should be invite-only:

// Use admin API to invite users
const { data, error } = await supabaseAdmin.auth.admin.inviteUserByEmail(
  'user@example.com'
);

// Or disable signup in dashboard and use:
const { data, error } = await supabaseAdmin.auth.admin.createUser({
  email: 'user@example.com',
  email_confirm: true
});

MANDATORY: Progressive Context File Updates

⚠️ This skill MUST update tracking files PROGRESSIVELY during execution, NOT just at the end.

Critical Rule: Write As You Go

DO NOT batch all writes at the end. Instead:

1. Before each signup test → Log the action to .sb-pentest-audit.log 2. After each vulnerability found → Immediately update .sb-pentest-context.json 3. After rate limit tests → Log the results immediately

This ensures that if the skill is interrupted, crashes, or times out, all findings up to that point are preserved.

Required Actions (Progressive)

1. Update `.sb-pentest-context.json` with results:

   {
     "signup_audit": {
       "timestamp": "...",
       "signup_open": true,
       "rate_limit": { ... },
       "findings": [ ... ]
     }
   }

2. Log to `.sb-pentest-audit.log`:

   [TIMESTAMP] [supabase-audit-auth-signup] [START] Testing signup security
   [TIMESTAMP] [supabase-audit-auth-signup] [FINDING] P2: Weak passwords accepted
   [TIMESTAMP] [supabase-audit-auth-signup] [CONTEXT_UPDATED] .sb-pentest-context.json updated

3. If files don't exist, create them before writing.

FAILURE TO UPDATE CONTEXT FILES IS NOT ACCEPTABLE.

MANDATORY: Evidence Collection

📁 Evidence Directory: .sb-pentest-evidence/05-auth-audit/signup-tests/

Evidence Files to Create

FileContent
signup-tests/open-signup.jsonSignup availability test
signup-tests/weak-password.jsonWeak password acceptance test
signup-tests/disposable-email.jsonDisposable email test
signup-tests/rate-limit.jsonRate limiting test

Evidence Format

{
  "evidence_id": "AUTH-SIGNUP-001",
  "timestamp": "2025-01-31T10:55:00Z",
  "category": "auth-audit",
  "type": "signup_test",

  "tests": [
    {
      "test_name": "weak_password_acceptance",
      "severity": "P2",
      "request": {
        "method": "POST",
        "url": "https://abc123def.supabase.co/auth/v1/signup",
        "body": {"email": "test@example.com", "password": "123456"},
        "curl_command": "curl -X POST '$URL/auth/v1/signup' -H 'apikey: $ANON_KEY' -H 'Content-Type: application/json' -d '{\"email\": \"test@example.com\", \"password\": \"123456\"}'"
      },
      "response": {
        "status": 200,
        "message": "User created"
      },
      "result": "VULNERABLE",
      "impact": "Weak passwords (6 chars) accepted"
    },
    {
      "test_name": "disposable_email",
      "severity": "P2",
      "request": {
        "body": {"email": "test@mailinator.com", "password": "Test123456!"}
      },
      "response": {
        "status": 200,
        "message": "User created"
      },
      "result": "VULNERABLE",
      "impact": "Disposable emails not blocked"
    }
  ]
}

Related Skills

  • supabase-audit-auth-config — Full auth configuration
  • supabase-audit-auth-users — User enumeration testing
  • supabase-audit-rls — Protect user data with RLS

Related skills

How it compares

Use supabase-audit-auth-signup for targeted Supabase registration pentests; use general security scanners for non-Supabase auth stacks.

FAQ

What files does supabase-audit-auth-signup write during tests?

supabase-audit-auth-signup writes findings to .sb-pentest-context.json immediately after each completed test and logs to .sb-pentest-audit.log before and after every test. Progressive updates ensure partial results survive interruptions.

What does supabase-audit-auth-signup test on Supabase?

supabase-audit-auth-signup tests whether user signup is open and identifies potential abuse vectors in the Supabase registration process. The skill README describes signup flow audit as its primary focus.

Securityauditappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.