supabase

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed to assist with Supabase project management and development tasks. It correctly prioritizes security through explicit checklists for RLS, authentication, and database view configuration.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: All network operations, including fetching the changelog and documentation or checking the MCP server status, are directed to official and trusted Supabase domains (supabase.com, mcp.supabase.com). No unauthorized data exfiltration was detected.
  • [COMMAND_EXECUTION]: The skill guides the agent to use standard Supabase CLI and MCP server tools for database schema management and querying. These operations are appropriate for the skill's stated purpose and do not represent malicious command execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches documentation and changelog summaries from official sources. This ingestions is performed safely as a standard part of project management, and the skill provides internal checklists to ensure implementations remain secure.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 06:05 AM
Security Audit — agent-trust-hub — supabase