supabase

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches product changelogs and documentation markdown files from official Supabase domains (supabase.com). These interactions are documented as a way to verify current feature signatures and breaking changes before implementation.- [COMMAND_EXECUTION]: Instructs the agent to utilize the Supabase CLI and MCP server tools to perform database queries, manage migrations, and search documentation. The skill provides clear guidance on safely discovering command syntax using the --help flag.- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources including vendor changelogs and documentation snippets. This creates a potential surface for indirect prompt injection where malicious instructions could be embedded in the fetched content. However, the sources are restricted to official vendor domains and the finding is limited to the presence of the ingestion surface and the agent's database execution capabilities.- [SAFE]: Includes a robust security checklist for the agent to follow, covering critical topics such as Row Level Security (RLS) implementation, avoiding the exposure of service role keys in frontend code, and identifying deprecated authentication patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 11:42 PM