cost-supabase
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill recommends executing various commands using the official Supabase CLI (e.g.,
supabase projects list,supabase status),curlfor API interactions, anddocker composefor self-hosted infrastructure management. - [EXTERNAL_DOWNLOADS]: Instructions are provided to install the official Supabase CLI via well-known package managers such as Homebrew (
brew install) and NPM (npm install), and to clone the official Supabase repository from GitHub for self-hosting. - [PROMPT_INJECTION]: The skill presents an indirect injection surface by instructing the agent to ingest pricing data from the Supabase website via web search or scraping (Ingestion point: Step 3 in SKILL.md) and possessing capabilities to execute shell commands like
supabaseandcurl(Capability inventory: Step 1 and Step 2 in SKILL.md). No specific boundary markers or sanitization logic are defined for the externally fetched content (Boundary markers: absent; Sanitization: absent).
Audit Metadata