supabase-pentest-skills

Warn

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions to download an agent configuration template from an unverified GitHub repository (yoanbernabeu/supabase-pentest-skills).
  • [COMMAND_EXECUTION]: The skill setup involves executing shell commands like curl and npx to fetch templates and install skill packs.
  • [PROMPT_INJECTION]: The auditing logic ingests data from external URLs and APIs which creates a surface for indirect prompt injection.
  • [PROMPT_INJECTION]: Ingestion points: Data extracted from target website URLs, JS files, and API responses. Boundary markers: No delimiters or ignore directives are used to separate untrusted content from instructions. Capability inventory: File system writes for evidence collection, network requests for auditing, and package management for installation. Sanitization: No evidence of validation or sanitization of ingested content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 13, 2026, 09:41 AM
Security Audit — agent-trust-hub — supabase-pentest-skills