supabase-js
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of official packages from the @supabase scope and references documentation assets hosted on Supabase's official domains and GitHub repositories.
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from external sources, specifically Supabase database tables and storage objects. This creates an attack surface for indirect prompt injection if the agent processes malicious data retrieved through the SDK.
- Ingestion points: Data is retrieved from the database, auth metadata, and storage buckets using the Supabase client (SKILL.md, reference READMEs).
- Boundary markers: The provided examples do not include explicit instructions to the agent to distinguish between system commands and untrusted data retrieved from Supabase.
- Capability inventory: The skill provides instructions for local tool execution, such as supabase gen types for generating TypeScript definitions (SKILL.md).
- Sanitization: The skill examples do not demonstrate sanitization of the data returned from database queries before processing.
Audit Metadata