supabase-cli
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documents installation procedures that fetch assets from official Supabase repositories on GitHub and the npm registry. These are standard distribution channels for the official CLI tool.
- [REMOTE_CODE_EXECUTION]: The documentation includes a one-liner installation command (
curl -fsSL ... | bash) that executes a script directly from Supabase's official GitHub organization. While this pattern is typically high-risk, it is used here to fetch verified code from a well-known vendor. - [COMMAND_EXECUTION]: The skill facilitates the execution of the
supabaseCLI to perform project lifecycle tasks, including starting local Docker stacks, managing secrets, and executing SQL queries against both local and remote databases. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from external databases and schema definitions which could contain malicious payloads.
- Ingestion points: Data returned from
supabase db query,supabase db pull, andsupabase migration listas detailed in the reference files. - Boundary markers: The skill specifically identifies the use of an 'untrusted data warning envelope' when the CLI detects an AI agent, providing clear demarcation between data and instructions.
- Capability inventory: The CLI possesses capabilities to write to the local filesystem (migration files, configuration), interact with Docker for local services, and communicate with the Supabase platform API.
- Sanitization: The CLI tool includes a built-in agent mode that performs output wrapping to ensure that untrusted data from the database is not misinterpreted by the agent as high-priority instructions.
Audit Metadata