supabase
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive security checklists that correctly identify common Supabase pitfalls, such as the dangers of using
user_metadatafor authorization and the need forsecurity_invokeron views. - [SAFE]: Documentation and update URLs point to official Supabase GitHub repositories and domains (e.g., github.com/supabase/*, supabase.com), which are recognized as trusted sources.
- [SAFE]: The skill correctly instructs the agent to use environment variables for secrets and explicitly warns against exposing the
service_rolekey in public clients. - [SAFE]: Command execution is limited to standard Supabase CLI operations and documented MCP server interactions for database management.
Audit Metadata