supabase
Pass
Audited by Gen Agent Trust Hub on May 26, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches documentation and project configuration from official Supabase domains and GitHub repositories. These operations are limited to retrieving technical references and verifying service health.
- [COMMAND_EXECUTION]: Employs standard Supabase CLI commands for database migrations and environment management. A benign health check using
curlis documented to verify the availability of the Supabase MCP server. - [CREDENTIALS_UNSAFE]: Explicitly instructs the agent to avoid exposing sensitive
service_rolekeys and provides clear guidance on safe secret management practices within the Supabase ecosystem. - [PROMPT_INJECTION]: The skill body consists of operational guidelines and security best practices. It does not contain instructions intended to override AI safety filters or exfiltrate system prompts.
- [DATA_EXFILTRATION]: No suspicious data transfer patterns were detected. Network activity is restricted to authenticated interaction with official Supabase infrastructure and documentation sources.
Audit Metadata