SupabaseBLOCK
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server that provides programmatic access to the Supabase Management API. This server allows AI models and other clients to manage Supabase projects and organizations through a standardized interface.
Features
Project Management
- List all projects
- Get project details
- Create new projects
- Delete projects
- Retrieve project API keys
Organization Management
- List all organizations
- Get organization details
- Create new organizations
Installation
Add the following to your Claude Config JSON file
{
"mcpServers": {
"supabase": {
"command": "npx",
"args": [
"y",
"@joshuarileydev/supabase-mcp-server"
],
"env": {
"SUPABASE_API_KEY": "API_KEY_HERE"
}
}
}
}cd9faeb0b56cOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add supabase-mcp-server --env SUPABASE_API_KEY=${SUPABASE_API_KEY} -- npx -y @joshuarileydev/[email protected]{
"mcpServers": {
"supabase-mcp-server": {
"command": "npx",
"args": [
"-y",
"@joshuarileydev/[email protected]"
],
"env": {
"SUPABASE_API_KEY": "${SUPABASE_API_KEY}"
}
}
}
}Exposed tools (8)
5 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
create_organization | write | Create a new organization |
create_project | write | Create a new Supabase project |
delete_project | destructive | Delete a Supabase project |
get_organization | read | Get details of a specific organization |
get_project | read | Get details of a specific Supabase project |
get_project_api_keys | read | Get API keys for a specific Supabase project |
list_organizations | read | List all organizations |
list_projects | read | List all Supabase projects |
Trust audit
BLOCKgrade F · trust 35/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (10 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
exec(sql: string): void;
var deprecatedfn = new Function('fn', 'log', 'deprecate', 'message', 'site','return function (' + args + ') {' +bound = Function('binder', 'return function (' + joiny(boundArgs, ',') + '){ return binder.apply(this,arguments); }')(binder);if (options.unix === false) { // this branch is for exec()request ~ requests
request ~ requests
node_modules/.bin/resolve
node_modules/.bin/shjs
node_modules/.bin/shx
node_modules/.bin/tsc
node_modules/.bin/tsserver
* console.log(myURL.password);
| "beacon"
"chars": "€پ‚ƒ„...†‡ˆ‰ٹ‹Œچژڈگ‘’“”•–—کTMڑ›œں ،¢£¤¥¦§ ̈©ھ«¬® ̄°±23 ́μ¶· ̧1؛»1⁄41⁄23⁄4؟ہءآأؤإئابةتثجحخدذرزسشصض×طظعغـفقكàلâمنهوçèéêëىيîïًٌٍَôُِ÷ّùْûüے"
"chars": "«»...“”�•‘’� กขฃคฅฆงจฉชซฌญฎฏฐฑฒณดตถทธนบปผฝพฟภมยรฤลฦวศษสหฬอฮฯะัาําิีึืฺุู–—฿เแโใไๅๆ็่้๊๋์ํTM๏๐๑๒๓๔๕๖๗๘๙®©����"
delete_project
.package-lock.json
.travis.yml
.nycrc
.nycrc
.nycrc
var expected = path.join(__dirname, '../../node_modules/jquery/dist/jquery.js');
assert.equal(resolve.sync('../../node_modules/jquery', { basedir: basedir, preserveSymlinks: false }), expected);assert.equal(resolve.sync('../../../../../node_modules/jquery', { basedir: basedir, preserveSymlinks: true }), expected);Gates applied: no_behavioural_pass.
cd9faeb0b56cfull audit observations/trust-audit/mcp-server/joshuarileydev__supabase.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | cd9faeb0b56c | BLOCK | F | 35 | first audit |
Questions
What tools does Supabase expose?
8 in total: 5 read-only, 2 that write, and 1 that can delete or overwrite (delete_project). Every one is listed on this page with its risk.
Is Supabase safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (35/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Supabase need?
It reads SUPABASE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Supabase run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as @joshuarileydev/supabase-mcp-server at 0.0.2.
How current is this page?
The grade is for one exact copy of the source (cd9faeb0b56c), read on 2026-10-08. The repository is watched and re-audited when it changes.