supabase
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides high-quality security guidance, explicitly instructing users to avoid exposing
service_rolekeys, usesecurity_invokerfor views, and implement proper Row Level Security (RLS) patterns. - [EXTERNAL_DOWNLOADS]: The skill references several external resources for documentation and changelogs, such as
https://supabase.com/changelog.mdandhttps://supabase.com/docs/guides/security/product-security.md. These are official domains belonging to the vendor (Supabase) and are considered safe. - [COMMAND_EXECUTION]: The skill provides examples of
supabaseCLI commands andcurlfor troubleshooting the MCP server. These are standard developer operations and do not represent a security risk within the context of the skill's purpose. - [INDIRECT_PROMPT_INJECTION]: The skill ingests external documentation and changelogs. While this presents a surface for indirect prompt injection, the instructions emphasize using official Supabase sources, and the risk is mitigated by the agent's internal safety guardrails. The severity is low.
Audit Metadata