supabase
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is primarily defensive, providing high-quality instructions on how to secure a Supabase backend. It correctly identifies the trust boundary between
anonandservice_rolekeys and advocates for Row Level Security (RLS) as the primary authorization layer. - [COMMAND_EXECUTION]: The skill provides
scripts/verify.sh, a local security linter. This script uses standard utilities (find,grep) to audit the project's source code for leakedservice_rolekeys or insecure auth methods (likegetSession()). It is a read-only script that does not perform network requests or modify files. - [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted external data via JWT claims and server-side cookies.
- Ingestion points: JWT claims via
supabase.auth.getClaims(), cookies viacreateServerClient, and user-provided form data in server actions. - Boundary markers: The instructions explicitly separate client-side (untrusted) and server-side (trusted) logic, recommending asymmetric signature verification for JWTs to ensure data integrity.
- Capability inventory: Uses the
supabaseCLI for database management and theverify.shscript for auditing. No arbitrary execution of untrusted data is present. - Sanitization: Recommends
getClaims()for local verification of cryptographically signed tokens, preventing user-controllable data from influencing authorization without verification.
Audit Metadata