backend-realtime
Fail
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill instructs the agent to read sensitive environment files (
.env*) using shell commands (catandgrep) to verify Supabase configurations. Accessing these files exposes potentially sensitive credentials stored in the development environment. - [INDIRECT_PROMPT_INJECTION]: The skill implements multiple points of untrusted data ingestion from real-time streams (Supabase Realtime, WebSockets, SSE), which can be used to deliver malicious instructions to the agent.
- Ingestion points: The
useRealtimeMessageshook inreferences/patterns.mdandusePresence/useBroadcasthooks inSKILL.mdsubscribe to external data changes. - Boundary markers: None are present in the provided code examples to differentiate between data and instructions.
- Capability inventory: The code patterns primarily manage UI state, but the agent's broad file system and shell capabilities increase the risk if the agent processes the real-time payloads.
- Sanitization: There is no payload validation or sanitization implemented in the reference patterns to mitigate risks from malicious data content.
Recommendations
- AI detected serious security threats
Audit Metadata