supabase-admin
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: Comprehensive analysis of the provided instructions, SQL templates, and reference guides found no malicious patterns, obfuscation, or unauthorized data access. The skill is limited to legitimate Supabase administrative tasks.
- [PRIVILEGE_ESCALATION]: The skill references the use of
SECURITY DEFINERfor PostgreSQL functions and triggers. This is an architectural standard for Supabase to allow secure communication between database schemas and is used correctly within the provided documentation templates. - [INDIRECT_PROMPT_INJECTION]: The skill provides a framework for analyzing and generating database schemas.
- Ingestion points: Database schema requirements and existing policy definitions provided by the user in the context of Supabase management.
- Boundary markers: Clear usage guidelines in
SKILL.mdrestrict the agent to Supabase-specific contexts and exclude general SQL or edge functions. - Capability inventory: Access to file manipulation tools (
Read,Write,Edit), shell access (Bash), and Supabase-specific MCP tools (mcp__supabase__*). - Sanitization: The skill relies on structured SQL templates and the agent's internal safety filters to prevent malicious instruction execution through ingested data.
Audit Metadata