supabase

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides high-quality security guidance, explicitly instructing users to avoid exposing service_role keys, use security_invoker for views, and implement proper Row Level Security (RLS) patterns.
  • [EXTERNAL_DOWNLOADS]: The skill references several external resources for documentation and changelogs, such as https://supabase.com/changelog.md and https://supabase.com/docs/guides/security/product-security.md. These are official domains belonging to the vendor (Supabase) and are considered safe.
  • [COMMAND_EXECUTION]: The skill provides examples of supabase CLI commands and curl for troubleshooting the MCP server. These are standard developer operations and do not represent a security risk within the context of the skill's purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external documentation and changelogs. While this presents a surface for indirect prompt injection, the instructions emphasize using official Supabase sources, and the risk is mitigated by the agent's internal safety guardrails. The severity is low.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 02:10 AM
Security Audit — agent-trust-hub — supabase