supabase

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources (databases, storage, and function logs) and possesses capabilities that could be influenced by malicious content within those sources.\n
  • Ingestion points: supabase db pull, supabase storage cp, and supabase functions logs in SKILL.md.\n
  • Boundary markers: Absent.\n
  • Capability inventory: supabase db execute, supabase functions deploy, and supabase secrets set in SKILL.md.\n
  • Sanitization: Absent; the skill relies on the Supabase CLI's native handling and the agent's internal safety guardrails.\n- [COMMAND_EXECUTION]: The skill utilizes the standard supabase CLI for local and remote project management, which is the expected and legitimate behavior for this integration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 10:18 AM
Security Audit — agent-trust-hub — supabase