supabase-postgres-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [METADATA_POISONING]: The skill manifest (SKILL.md) and metadata.json identify the author as 'Supabase', whereas the provided author context is 'claudiodearaujo'. This attribution inconsistency is deceptive as it leverages the reputation of a well-known service to imply official origin.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to guide an agent in 'writing, reviewing, or optimizing Postgres queries, schema designs, or database configurations', creating a vulnerability surface where the agent might follow malicious instructions embedded in the data it is analyzing.
- Ingestion points: SQL queries, schema definitions, and configuration files provided to the agent for review or optimization (referenced in SKILL.md).
- Boundary markers (absent): The instructions do not define delimiters or provide warnings for the agent to ignore instructions embedded within the SQL code it evaluates.
- Capability inventory: The skill is intended to be used by agents with the capability to generate, rewrite, or optimize database code, which could lead to the propagation of malicious patterns if the input is poisoned.
- Sanitization (absent): The rule set focuses on performance and standard security (RLS) but does not include instructions for the agent to sanitize or validate the untrusted SQL strings it processes.
- [EXTERNAL_DOWNLOADS]: The README.md specifies a build process for the skill rules requiring 'npm install' in a local package directory. The specific dependencies are not visible in the provided files, but the instruction to fetch external packages at build time introduces a dependency on external registries.
Audit Metadata