supabase

Pass

Audited by Gen Agent Trust Hub on May 26, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches documentation and project configuration from official Supabase domains and GitHub repositories. These operations are limited to retrieving technical references and verifying service health.
  • [COMMAND_EXECUTION]: Employs standard Supabase CLI commands for database migrations and environment management. A benign health check using curl is documented to verify the availability of the Supabase MCP server.
  • [CREDENTIALS_UNSAFE]: Explicitly instructs the agent to avoid exposing sensitive service_role keys and provides clear guidance on safe secret management practices within the Supabase ecosystem.
  • [PROMPT_INJECTION]: The skill body consists of operational guidelines and security best practices. It does not contain instructions intended to override AI safety filters or exfiltrate system prompts.
  • [DATA_EXFILTRATION]: No suspicious data transfer patterns were detected. Network activity is restricted to authenticated interaction with official Supabase infrastructure and documentation sources.
Audit Metadata
Risk Level
SAFE
Analyzed
May 26, 2026, 10:52 AM
Security Audit — agent-trust-hub — supabase