supabase-nextjs-debugger
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands such as npx tsc, npx vitest, and npx next build to verify project integrity. It also utilizes curl and python3 for API testing and session generation. These are standard development practices for verifying deployment health.
- [PROMPT_INJECTION]: The skill analyzes user source code and configuration files, creating a surface for indirect prompt injection. Ingestion points: Local file system access via Read, Grep, and Glob tools. Boundary markers: None present to differentiate untrusted data from instructions. Capability inventory: Includes Bash, Write, and Edit tools, which could be misused if the analyzed content contains malicious instructions. Sanitization: No evidence of filtering or validation of the analyzed project content.
Audit Metadata