managing-supabase
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
execute_sqltool inSKILL.mdallows for the execution of arbitrary PostgreSQL queries against a project's database, providing full data access and modification capabilities.\n- [COMMAND_EXECUTION]: Thedeploy_edge_functiontool enables the deployment of arbitrary code to Supabase Edge Functions, allowing for serverless logic execution.\n- [CREDENTIALS_UNSAFE]: Theget_publishable_keystool provides the ability to retrieve sensitive API keys, including service role keys, for a Supabase project.\n- [PROMPT_INJECTION]: The skill facilitates the processing of data from potentially untrusted external sources, creating a surface for indirect prompt injection.\n - Ingestion points: Tools such as
get_logs,execute_sql, andsearch_docsingest data from Supabase environments and documentation which could contain malicious instructions.\n - Boundary markers: The skill documentation does not specify the use of delimiters or 'ignore' instructions for processed data to prevent the agent from obeying instructions embedded in tool outputs.\n
- Capability inventory: The skill possesses significant capabilities, including
execute_sqlfor database modification anddeploy_edge_functionfor code deployment, which could be abused if an injection is successful.\n - Sanitization: There is no mention of data validation or sanitization before the ingested data is returned to the agent's context.
Audit Metadata