Skip to main content

nextjs-supabase-auth

Integrates Supabase Auth seamlessly with Next.js App Router, ensuring secure authentication and protected routes for web applications.

Install this skill

or
35/100

Security score

The nextjs-supabase-auth skill was audited on May 12, 2026 and we found 9 security issues across 2 threat categories, including 2 high-severity. Review the findings below before installing.

Categories Tested

Security Issues

high line 131

Template literal with variable interpolation in command context

SourceSKILL.md
131return NextResponse.redirect(`${origin}${next}`)
high line 135

Template literal with variable interpolation in command context

SourceSKILL.md
135return NextResponse.redirect(`${origin}/auth/error`)
medium line 38

Access to .env file

SourceSKILL.md
38process.env.NEXT_PUBLIC_SUPABASE_URL!,
medium line 39

Access to .env file

SourceSKILL.md
39process.env.NEXT_PUBLIC_SUPABASE_ANON_KEY!
medium line 50

Access to .env file

SourceSKILL.md
50process.env.NEXT_PUBLIC_SUPABASE_URL!,
medium line 51

Access to .env file

SourceSKILL.md
51process.env.NEXT_PUBLIC_SUPABASE_ANON_KEY!,
medium line 81

Access to .env file

SourceSKILL.md
81process.env.NEXT_PUBLIC_SUPABASE_URL!,
medium line 82

Access to .env file

SourceSKILL.md
82process.env.NEXT_PUBLIC_SUPABASE_ANON_KEY!,
medium line 237

Access to .env file

SourceSKILL.md
237Fix action: Use window.location.origin or process.env.NEXT_PUBLIC_SITE_URL
Scanned on May 12, 2026
View Security Dashboard
Installation guide →