opencode-supabase

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements strong security education by warning users about the risks of public API keys and the necessity of enabling Row-Level Security (RLS) to prevent unauthorized data access.
  • [SAFE]: It provides clear instructions on distinguishing between publishable keys (safe for frontend) and secret keys (server-side only), including remediation steps if a secret key is accidentally leaked.
  • [SAFE]: Dependency management uses official libraries from well-known services (Supabase via the esm.sh CDN), minimizing supply chain risks.
  • [SAFE]: The skill acknowledges the potential for Indirect Prompt Injection when using the MCP tool to read user-generated content and provides appropriate mitigations, such as using read-only access and project scoping.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 02:21 AM
Security Audit — agent-trust-hub — opencode-supabase