supabase-postgres-best-practices

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill is composed entirely of static Markdown files and SQL reference templates. There are no executable scripts (Python, JavaScript, or Shell) or configuration files that trigger automated tasks.
  • [SAFE]: External links provided in the documentation target well-known and official sources, including the PostgreSQL official documentation and Supabase guides.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to influence agent behavior by providing a library of optimization rules. It uses an 'Error-First' structure with 'Incorrect' vs 'Correct' examples, which is a standard and safe method for training or guiding AI agents in technical tasks.
  • Ingestion points: Rule files located in the references/ directory.
  • Boundary markers: Instructions are clearly separated by YAML frontmatter and Markdown headers.
  • Capability inventory: The skill does not define any subprocess calls, file writing operations, or network tools.
  • Sanitization: Not applicable as the content is static documentation.
  • [METADATA_POISONING]: The skill frontmatter claims the author is 'Supabase' and 'organization: Supabase', which differs from the provided author ID 'decoutkhanqindev'. While inconsistent, the content strictly aligns with public database best practices and does not include deceptive instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:53 AM
Security Audit — agent-trust-hub — supabase-postgres-best-practices