backend-realtime

Fail

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill instructs the agent to read sensitive environment files (.env*) using shell commands (cat and grep) to verify Supabase configurations. Accessing these files exposes potentially sensitive credentials stored in the development environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements multiple points of untrusted data ingestion from real-time streams (Supabase Realtime, WebSockets, SSE), which can be used to deliver malicious instructions to the agent.
  • Ingestion points: The useRealtimeMessages hook in references/patterns.md and usePresence/useBroadcast hooks in SKILL.md subscribe to external data changes.
  • Boundary markers: None are present in the provided code examples to differentiate between data and instructions.
  • Capability inventory: The code patterns primarily manage UI state, but the agent's broad file system and shell capabilities increase the risk if the agent processes the real-time payloads.
  • Sanitization: There is no payload validation or sanitization implemented in the reference patterns to mitigate risks from malicious data content.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 13, 2026, 05:12 AM
Security Audit — agent-trust-hub — backend-realtime