supabase-cli

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documents installation procedures that fetch assets from official Supabase repositories on GitHub and the npm registry. These are standard distribution channels for the official CLI tool.
  • [REMOTE_CODE_EXECUTION]: The documentation includes a one-liner installation command (curl -fsSL ... | bash) that executes a script directly from Supabase's official GitHub organization. While this pattern is typically high-risk, it is used here to fetch verified code from a well-known vendor.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of the supabase CLI to perform project lifecycle tasks, including starting local Docker stacks, managing secrets, and executing SQL queries against both local and remote databases.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process data from external databases and schema definitions which could contain malicious payloads.
  • Ingestion points: Data returned from supabase db query, supabase db pull, and supabase migration list as detailed in the reference files.
  • Boundary markers: The skill specifically identifies the use of an 'untrusted data warning envelope' when the CLI detects an AI agent, providing clear demarcation between data and instructions.
  • Capability inventory: The CLI possesses capabilities to write to the local filesystem (migration files, configuration), interact with Docker for local services, and communicate with the Supabase platform API.
  • Sanitization: The CLI tool includes a built-in agent mode that performs output wrapping to ensure that untrusted data from the database is not misinterpreted by the agent as high-priority instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 11:42 PM