supabase

Manage Supabase projects from the CLI

$ anc audit supabase --json

workhorse Go supabase/cli
MUST 19 / 28SHOULD 13 / 212 failing17 warningsaudited 2026-06-01 · anc 0.5.0
66pass rate
2/8principles met

Audience signal: mixed

This tool sends mixed signals: some agent-readable affordances are present, others are not. Treat the warnings below as friction points, not defects.

This is an informational signal, not an authoritative verdict — see methodology. The per-audit evidence below is the ground truth.

Eight principles, scored

Behavioral and source checks. Every non-pass row carries a copy-paste remediation prompt.

  1. P1
    Non-Interactive by Default

    15 flag(s) found in --help but no `[env: NAME]` bindings advertised · no default-value annotations found in --help. SHOULD-tier — agents reading help text need to see what value a flag falls back to when omitted (`[default: <value>]` per clap convention).

    Remediation · P1
    Make supabase satisfy P1 (Non-Interactive by Default) from the agent-native CLI standard. Address:
    - Flags advertise env-var bindings in --help (15 flag(s) found in --help but no `[env: NAME]` bindings advertised)
    - `--help` advertises default values for flags (no default-value annotations found in --help. SHOULD-tier — agents reading help text need to see what value a flag falls back to when omitted (`[default: <value>]` per clap convention).)
    - Rich-TUI affordance for TTY contexts (no rich-TUI affordance detected (no `--tui`/`--interactive`/`--ui` flag, no spinner/progress/tui mention in --help). MAY-tier — rich TUI in TTY contexts is a nice-to-have, not required.)
    Requirements: https://anc.dev/p1
    warn
  2. P2
    Structured, Parseable Output

    --output/--format flag detected but could not validate JSON via safe probes (--help/--version override output flags in most CLIs) · CLI emits structured output but exposes no `schema` subcommand or `--schema` flag at top level or nested one level deep. Agents need a runtime-discoverable schema to pin against shape changes.

    Remediation · P2
    Make supabase satisfy P2 (Structured, Parseable Output) from the agent-native CLI standard. Address:
    - Structured output support (--output/--format flag detected but could not validate JSON via safe probes (--help/--version override output flags in most CLIs))
    - Structured-output CLI exposes its schema at runtime (CLI emits structured output but exposes no `schema` subcommand or `--schema` flag at top level or nested one level deep. Agents need a runtime-discoverable schema to pin against shape changes.)
    - --json / --jsonl short aliases for --output (no --json or --jsonl short alias found. Agents and pipelines benefit from short forms alongside the canonical `--output` enum.)
    - `--raw` flag for pipe-safe unformatted output (no `--raw` flag advertised. MAY-tier — useful for pipelines that want to strip formatting before piping to other tools.)
    - Bad invocation exits with structured usage-error code (2) (bad invocation exited with code 1. The 0/1/2/77/78 convention reserves code 2 for usage errors; using a different non-zero code (often 1) blurs the distinction between usage errors and general failure.)
    - Errors emit JSON envelope with `error`/`kind`/`message` under `--output json` (bad invocation under `--output json` produced no parseable JSON on stderr or stdout. JSON mode must emit a JSON error envelope, not plain text.)
    Requirements: https://anc.dev/p2
    fail
  3. P3
    Progressive Help Discovery

    `--version` works but no short alias responded (tried -V, -v, -version). Adding one shortens version probes for agents. · `--version` works but no short alias responded (tried -V, -v, -version). Adding one shortens version probes for agents.

    Remediation · P3
    Make supabase satisfy P3 (Progressive Help Discovery) from the agent-native CLI standard. Address:
    - Version flag works (`--version` plus short alias) (`--version` works but no short alias responded (tried -V, -v, -version). Adding one shortens version probes for agents.)
    - Version flag works (`--version` plus short alias) (`--version` works but no short alias responded (tried -V, -v, -version). Adding one shortens version probes for agents.)
    - `examples` subcommand or `--examples` flag for curated usage patterns (no `examples` subcommand or `--examples` flag found. MAY-tier — a curated usage block keeps agents from hunting through long help text.)
    - Short `-h` summary differs from `--help` long form (`-h` and `--help` produce byte-identical output. SHOULD-tier — clap renders the short summary on `-h` and the full description on `--help` when `long_about` is set; collapsing them gives agents no concise list-level grep target.)
    - Help text pairs human and `--output json` example invocations (no paired text + `--output json` example found within 5 lines in top-level or any subcommand `--help`. Pairing keeps agents from reverse-engineering the JSON invocation from the text one.)
    Requirements: https://anc.dev/p3
    warn
  4. P4
    Fail-Fast, Actionable Errors

    errors under `--output json` are not JSON-formatted. Consumers parsing stdout-as-JSON cannot recover the failure without a separate text-parsing path; switch the error writer to honor the active output mode.

    Remediation · P4
    Make supabase satisfy P4 (Fail-Fast, Actionable Errors) from the agent-native CLI standard. Address:
    - `--output json` produces JSON-formatted errors (errors under `--output json` are not JSON-formatted. Consumers parsing stdout-as-JSON cannot recover the failure without a separate text-parsing path; switch the error writer to honor the active output mode.)
    Requirements: https://anc.dev/p4
    warn
  5. P5pass
  6. P6
    Composable, Predictable Command Structure

    no `--color` flag advertised. MAY-tier — `auto|always|never` lets agents and pipelines override the TTY-based default.

    Remediation · P6
    Make supabase satisfy P6 (Composable, Predictable Command Structure) from the agent-native CLI standard. Address:
    - `--color` flag for explicit color control (no `--color` flag advertised. MAY-tier — `auto|always|never` lets agents and pipelines override the TTY-based default.)
    Requirements: https://anc.dev/p6
    warn
  7. P7
    Bounded, High-Signal Responses

    no --quiet/-q flag detected in --help output · no `--verbose` / `-v` flag advertised. SHOULD-tier — agents debugging failures need a way to escalate diagnostic detail.

    Remediation · P7
    Make supabase satisfy P7 (Bounded, High-Signal Responses) from the agent-native CLI standard. Address:
    - Quiet mode available (no --quiet/-q flag detected in --help output)
    - `--verbose` flag for diagnostic escalation (no `--verbose` / `-v` flag advertised. SHOULD-tier — agents debugging failures need a way to escalate diagnostic detail.)
    - Help text advertises TTY-aware verbosity behavior (no TTY-aware language found in `--help`. MAY-tier — automatic verbosity reduction when stdout is piped or redirected lets agents skip the explicit `--quiet` flag. Behavioral probes cannot simulate a real TTY without a pty crate, so this audit relies on documented intent.)
    Requirements: https://anc.dev/p7
    warn
  8. P8pass

All Audits

P1: Non-Interactive by Default

PASSNon-interactive by default
SKIPNon-interactive gate flag advertised in --helptarget satisfies P1 via alternative gate (help-on-bare or stdin-primary)
WARNFlags advertise env-var bindings in --help15 flag(s) found in --help but no `[env: NAME]` bindings advertised
PASSSecret-bearing flags expose stdin or *-file companion
WARN`--help` advertises default values for flagsno default-value annotations found in --help. SHOULD-tier — agents reading help text need to see what value a flag falls back to when omitted (`[default: <value>]` per clap convention).
WARNRich-TUI affordance for TTY contextsno rich-TUI affordance detected (no `--tui`/`--interactive`/`--ui` flag, no spinner/progress/tui mention in --help). MAY-tier — rich TUI in TTY contexts is a nice-to-have, not required.

P2: Structured, Parseable Output

WARNStructured output support--output/--format flag detected but could not validate JSON via safe probes (--help/--version override output flags in most CLIs)
FAILStructured-output CLI exposes its schema at runtimeCLI emits structured output but exposes no `schema` subcommand or `--schema` flag at top level or nested one level deep. Agents need a runtime-discoverable schema to pin against shape changes.
WARN--json / --jsonl short aliases for --outputno --json or --jsonl short alias found. Agents and pipelines benefit from short forms alongside the canonical `--output` enum.
WARN`--raw` flag for pipe-safe unformatted outputno `--raw` flag advertised. MAY-tier — useful for pipelines that want to strip formatting before piping to other tools.
PASS`--output` advertises additional formats beyond text/json
WARNBad invocation exits with structured usage-error code (2)bad invocation exited with code 1. The 0/1/2/77/78 convention reserves code 2 for usage errors; using a different non-zero code (often 1) blurs the distinction between usage errors and general failure.
FAILErrors emit JSON envelope with `error`/`kind`/`message` under `--output json`bad invocation under `--output json` produced no parseable JSON on stderr or stdout. JSON mode must emit a JSON error envelope, not plain text.
SKIPJSON success and error envelopes share their non-payload key setsuccess-mode probe (`--help --output json`) produced no parseable JSON; cannot compare envelope shapes.

P3: Progressive Help Discovery

PASSHelp flag produces useful output
WARNVersion flag works (`--version` plus short alias)`--version` works but no short alias responded (tried -V, -v, -version). Adding one shortens version probes for agents.
WARNVersion flag works (`--version` plus short alias)`--version` works but no short alias responded (tried -V, -v, -version). Adding one shortens version probes for agents.
WARN`examples` subcommand or `--examples` flag for curated usage patternsno `examples` subcommand or `--examples` flag found. MAY-tier — a curated usage block keeps agents from hunting through long help text.
WARNShort `-h` summary differs from `--help` long form`-h` and `--help` produce byte-identical output. SHOULD-tier — clap renders the short summary on `-h` and the full description on `--help` when `long_about` is set; collapsing them gives agents no concise list-level grep target.
SKIPEach subcommand's `--help` ships at least one invocation examplebinary has no subcommands; MUST applies conditionally to CLIs that use them.
WARNHelp text pairs human and `--output json` example invocationsno paired text + `--output json` example found within 5 lines in top-level or any subcommand `--help`. Pairing keeps agents from reverse-engineering the JSON invocation from the text one.

P4: Fail-Fast, Actionable Errors

PASSRejects invalid arguments
PASSError messages include a hint or remediation phrase
WARN`--output json` produces JSON-formatted errorserrors under `--output json` are not JSON-formatted. Consumers parsing stdout-as-JSON cannot recover the failure without a separate text-parsing path; switch the error writer to honor the active output mode.

P5: Safe Retries & Mutation Boundaries

SKIPDestructive subcommands require `--force` or `--yes`no destructive subcommands detected; MUST applies conditionally to CLIs with destructive operations.
SKIPRead and write surfaces are both visible in subcommand listno recognizable read or write subcommand verbs; the read/write distinction is unobservable from the help surface alone.

P6: Composable, Predictable Command Structure

PASSHandles SIGPIPE gracefully
SKIPPager-using CLI ships --no-pager escape hatchno pager signal (less/more/$PAGER/--pager) in --help
PASSRespects NO_COLOR
SKIPSubcommand verbs follow community-standard namesno subcommands parsed from --help
WARN`--color` flag for explicit color controlno `--color` flag advertised. MAY-tier — `auto|always|never` lets agents and pipelines override the TTY-based default.
SKIPInput-accepting commands read from stdin when no file is givenno input-accepting subcommand detected (process/parse/convert/transform/analyze/validate/format/lint/audit); vacuous skip for the conditional SHOULD.
SKIPSubcommand naming follows a consistent verb/noun conventionfewer than 2 user-defined subcommands; vacuous skip for the conditional SHOULD.
PASSOperations are subcommands, not verb-shaped flags

P7: Bounded, High-Signal Responses

WARNQuiet mode availableno --quiet/-q flag detected in --help output
WARN`--verbose` flag for diagnostic escalationno `--verbose` / `-v` flag advertised. SHOULD-tier — agents debugging failures need a way to escalate diagnostic detail.
SKIP`--limit` / `--max-results` flag for list operationsno list-style subcommand detected (list/ls/search/query/find/show/get); vacuous skip for the list-only SHOULD.
SKIPCursor-based pagination flags for list traversalno list-style subcommand detected; vacuous skip for the list-only MAY.
SKIP`--timeout` flag for long-running operationsno long-running subcommand detected (serve/daemon/watch/tail/monitor/follow/run/start/stream); vacuous skip for the conditional SHOULD.
WARNHelp text advertises TTY-aware verbosity behaviorno TTY-aware language found in `--help`. MAY-tier — automatic verbosity reduction when stdout is piped or redirected lets agents skip the explicit `--quiet` flag. Behavioral probes cannot simulate a real TTY without a pty crate, so this audit relies on documented intent.

P8: Discoverable Through Agent Skill Bundles

PASSSkill bundle has install path (`tool skill install [<host>]`)
PASS`skill install --all` for multi-runtime install
PASS`skill update` / `skill upgrade` for bundle refresh

Details

Version scored
2.102.0
Audit date
2026-06-01 17:35:10 UTC
Duration
3.9s
Platform
linux/x86_64
Mode
command
Anc build
0.5.0
Install
brew install supabase

Embed the badge

The badge floor is 70%; this scorecard is at 66% (4 points below). Once the score clears the floor, the embed snippet will appear here. The top issues above are the place to start.

Reproduce this scorecard for supabase locally and inspect the failing audits:

anc audit --command supabase --output json

Install anc first if you don't have it. Add --output json to get the same JSON shape committed under scorecards/.