cost-supabase

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill recommends executing various commands using the official Supabase CLI (e.g., supabase projects list, supabase status), curl for API interactions, and docker compose for self-hosted infrastructure management.
  • [EXTERNAL_DOWNLOADS]: Instructions are provided to install the official Supabase CLI via well-known package managers such as Homebrew (brew install) and NPM (npm install), and to clone the official Supabase repository from GitHub for self-hosting.
  • [PROMPT_INJECTION]: The skill presents an indirect injection surface by instructing the agent to ingest pricing data from the Supabase website via web search or scraping (Ingestion point: Step 3 in SKILL.md) and possessing capabilities to execute shell commands like supabase and curl (Capability inventory: Step 1 and Step 2 in SKILL.md). No specific boundary markers or sanitization logic are defined for the externally fetched content (Boundary markers: absent; Sanitization: absent).
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 07:44 AM
Security Audit — agent-trust-hub — cost-supabase