Atlas / MCP servers / joshuarileydev / Supabase

SupabaseBLOCK

mcp/joshuarileydev/supabase
Verdict
BLOCK
Grade
F
Trust score
35 /100
Exposed tools
8 5r · 2w · 1d
Transport
sse · stdio
License
—
Stars
52
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server that provides programmatic access to the Supabase Management API. This server allows AI models and other clients to manage Supabase projects and organizations through a standardized interface.

Features

Project Management

  • List all projects
  • Get project details
  • Create new projects
  • Delete projects
  • Retrieve project API keys

Organization Management

  • List all organizations
  • Get organization details
  • Create new organizations

Installation

Add the following to your Claude Config JSON file

{
"mcpServers": {
"supabase": {
"command": "npx",
"args": [
"y",
"@joshuarileydev/supabase-mcp-server"
],
"env": {
"SUPABASE_API_KEY": "API_KEY_HERE"
}
}
}
}
Read from source at commit cd9faeb0b56cOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add supabase-mcp-server --env SUPABASE_API_KEY=${SUPABASE_API_KEY} -- npx -y @joshuarileydev/[email protected]
claude-desktop
{
  "mcpServers": {
    "supabase-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@joshuarileydev/[email protected]"
      ],
      "env": {
        "SUPABASE_API_KEY": "${SUPABASE_API_KEY}"
      }
    }
  }
}
03

Exposed tools (8)

5 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
create_organizationwriteCreate a new organization
create_projectwriteCreate a new Supabase project
delete_projectdestructiveDelete a Supabase project
get_organizationreadGet details of a specific organization
get_projectreadGet details of a specific Supabase project
get_project_api_keysreadGet API keys for a specific Supabase project
list_organizationsreadList all organizations
list_projectsreadList all Supabase projects
04

Trust audit

BLOCKgrade F · trust 35/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (6 observation(s))
Shell
declared (10 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
node_modules/@types/node/sqlite.d.ts:81
exec(sql: string): void;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
node_modules/depd/index.js:425
var deprecatedfn = new Function('fn', 'log', 'deprecate', 'message', 'site',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
node_modules/depd/index.js:427
'return function (' + args + ') {' +
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
node_modules/function-bind/implementation.js:74
bound = Function('binder', 'return function (' + joiny(boundArgs, ',') + '){ return binder.apply(this,arguments); }')(binder);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
node_modules/shelljs/src/common.js:334
if (options.unix === false) { // this branch is for exec()
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHSupply chain · supply.typosquat · CWE-829, CWE-1357
node_modules/form-data/package.json
request ~ requests
Why it matters. dependency name one edit from a popular package
Fix. verify the package; likely typosquat
HIGHSupply chain · supply.typosquat · CWE-829, CWE-1357
node_modules/iconv-lite/package.json
request ~ requests
Why it matters. dependency name one edit from a popular package
Fix. verify the package; likely typosquat
MEDIUMInventory / provenance · inv.symlink · CWE-1104
node_modules/.bin/resolve
node_modules/.bin/resolve
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
node_modules/.bin/shjs
node_modules/.bin/shjs
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
node_modules/.bin/shx
node_modules/.bin/shx
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
node_modules/.bin/tsc
node_modules/.bin/tsc
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
node_modules/.bin/tsserver
node_modules/.bin/tsserver
Why it matters. link not followed
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
node_modules/@types/node/url.d.ts:560
* console.log(myURL.password);
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
node_modules/@types/node-fetch/index.d.ts:50
| "beacon"
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
node_modules/iconv-lite/encodings/sbcs-data-generated.js:100
"chars": "€پ‚ƒ„...†‡ˆ‰ٹ‹Œچژڈگ‘’“”•–—کTMڑ›œں ،¢£¤¥¦§ ̈©ھ«¬® ̄°±23 ́μ¶· ̧1؛»1⁄41⁄23⁄4؟ہءآأؤإئابةتثجحخدذرزسشصض×طظعغـفقكàلâمنهوçèéêëىيîïًٌٍَôُِ÷ّùْûüے"
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
node_modules/iconv-lite/encodings/sbcs-data-generated.js:373
"chars": "«»...“”�•‘’� กขฃคฅฆงจฉชซฌญฎฏฐฑฒณดตถทธนบปผฝพฟภมยรฤลฦวศษสหฬอฮฯะัาําิีึืฺุู–—฿เแโใไๅๆ็่้๊๋์ํTM๏๐๑๒๓๔๕๖๗๘๙®©����"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_project
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
node_modules/.package-lock.json
.package-lock.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
node_modules/concat-map/.travis.yml
.travis.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
node_modules/function-bind/.nycrc
.nycrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
node_modules/hasown/.nycrc
.nycrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
node_modules/is-core-module/.nycrc
.nycrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
node_modules/resolve/test/resolver/multirepo/packages/package-a/index.js:9
var expected = path.join(__dirname, '../../node_modules/jquery/dist/jquery.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
node_modules/resolve/test/resolver/multirepo/packages/package-a/index.js:19
assert.equal(resolve.sync('../../node_modules/jquery', { basedir: basedir, preserveSymlinks: false }), expected);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
node_modules/resolve/test/resolver/multirepo/packages/package-a/index.js:33
assert.equal(resolve.sync('../../../../../node_modules/jquery', { basedir: basedir, preserveSymlinks: true }), expected);

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha cd9faeb0b56cfull audit observations/trust-audit/mcp-server/joshuarileydev__supabase.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08cd9faeb0b56cBLOCKF35first audit
06

Questions

What tools does Supabase expose?

8 in total: 5 read-only, 2 that write, and 1 that can delete or overwrite (delete_project). Every one is listed on this page with its risk.

Is Supabase safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (35/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Supabase need?

It reads SUPABASE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Supabase run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as @joshuarileydev/supabase-mcp-server at 0.0.2.

How current is this page?

The grade is for one exact copy of the source (cd9faeb0b56c), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement