supabase-knowledge-patch
Warn
Audited by Snyk on Apr 28, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The hosted MCP server URL https://mcp.supabase.com/mcp is explicitly used at runtime by MCP clients to fetch tool schemas/tools (via mcpClient.tools()), which directly supply/shape agent tools and prompts, so it is a runtime external dependency that can control agent behavior.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata