skills/ericrisco/rsc-harness/supabase/Gen Agent Trust Hub

supabase

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is primarily defensive, providing high-quality instructions on how to secure a Supabase backend. It correctly identifies the trust boundary between anon and service_role keys and advocates for Row Level Security (RLS) as the primary authorization layer.
  • [COMMAND_EXECUTION]: The skill provides scripts/verify.sh, a local security linter. This script uses standard utilities (find, grep) to audit the project's source code for leaked service_role keys or insecure auth methods (like getSession()). It is a read-only script that does not perform network requests or modify files.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted external data via JWT claims and server-side cookies.
  • Ingestion points: JWT claims via supabase.auth.getClaims(), cookies via createServerClient, and user-provided form data in server actions.
  • Boundary markers: The instructions explicitly separate client-side (untrusted) and server-side (trusted) logic, recommending asymmetric signature verification for JWTs to ensure data integrity.
  • Capability inventory: Uses the supabase CLI for database management and the verify.sh script for auditing. No arbitrary execution of untrusted data is present.
  • Sanitization: Recommends getClaims() for local verification of cryptographically signed tokens, preventing user-controllable data from influencing authorization without verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:57 AM
Security Audit — agent-trust-hub — supabase