supabase-postgres-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The README.md file contains instructions for users to run npm install to set up a documentation build environment within the packages/postgres-best-practices-build directory.
- [COMMAND_EXECUTION]: The documentation includes shell commands in README.md for environment setup, rule validation, and project building.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied SQL queries and schema designs to provide optimization advice, creating a data ingestion surface for external content.
- Ingestion points: User-provided SQL code and database configurations for analysis as described in SKILL.md.
- Boundary markers: No specific boundary markers or instructions to ignore embedded commands are defined for user-provided inputs.
- Capability inventory: The skill manifest (SKILL.md) does not define any active tool-calling capabilities or system-level permissions.
- Sanitization: The skill does not provide mechanisms for sanitizing or filtering user-provided SQL content.
Audit Metadata