managing-supabase

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The execute_sql tool in SKILL.md allows for the execution of arbitrary PostgreSQL queries against a project's database, providing full data access and modification capabilities.\n- [COMMAND_EXECUTION]: The deploy_edge_function tool enables the deployment of arbitrary code to Supabase Edge Functions, allowing for serverless logic execution.\n- [CREDENTIALS_UNSAFE]: The get_publishable_keys tool provides the ability to retrieve sensitive API keys, including service role keys, for a Supabase project.\n- [PROMPT_INJECTION]: The skill facilitates the processing of data from potentially untrusted external sources, creating a surface for indirect prompt injection.\n
  • Ingestion points: Tools such as get_logs, execute_sql, and search_docs ingest data from Supabase environments and documentation which could contain malicious instructions.\n
  • Boundary markers: The skill documentation does not specify the use of delimiters or 'ignore' instructions for processed data to prevent the agent from obeying instructions embedded in tool outputs.\n
  • Capability inventory: The skill possesses significant capabilities, including execute_sql for database modification and deploy_edge_function for code deployment, which could be abused if an injection is successful.\n
  • Sanitization: There is no mention of data validation or sanitization before the ingested data is returned to the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 04:21 PM
Security Audit — agent-trust-hub — managing-supabase