supabase-validation

Pass

Audited by Gen Agent Trust Hub on Mar 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The playground automation scripts use the execSync function to interact with the local operating system, performing tasks such as file restoration via git checkout, database queries through docker exec, and project management via the supabase CLI.
  • [EXTERNAL_DOWNLOADS]: Connectivity to the official Supabase Management API (api.supabase.com) is implemented in the environment setup and pre-flight scripts to retrieve necessary project configuration and API keys for production-level verification tasks.
  • [SAFE]: The skill includes robust internal security guidelines, such as a 'Global Clause' that explicitly prohibits the agent from disclosing secrets like service role keys or JWTs, and an 'Environment Classification Gate' to prevent accidental destructive operations on production systems.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 16, 2026, 02:47 AM
Security Audit — agent-trust-hub — supabase-validation