supabase-postgres-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill is composed entirely of static Markdown files and SQL reference templates. There are no executable scripts (Python, JavaScript, or Shell) or configuration files that trigger automated tasks.
- [SAFE]: External links provided in the documentation target well-known and official sources, including the PostgreSQL official documentation and Supabase guides.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to influence agent behavior by providing a library of optimization rules. It uses an 'Error-First' structure with 'Incorrect' vs 'Correct' examples, which is a standard and safe method for training or guiding AI agents in technical tasks.
- Ingestion points: Rule files located in the
references/directory. - Boundary markers: Instructions are clearly separated by YAML frontmatter and Markdown headers.
- Capability inventory: The skill does not define any subprocess calls, file writing operations, or network tools.
- Sanitization: Not applicable as the content is static documentation.
- [METADATA_POISONING]: The skill frontmatter claims the author is 'Supabase' and 'organization: Supabase', which differs from the provided author ID 'decoutkhanqindev'. While inconsistent, the content strictly aligns with public database best practices and does not include deceptive instructions.
Audit Metadata