supabase-help
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents a suite of commands that ingest external URLs as input, creating a surface where malicious content from those targets could attempt to influence agent behavior.
- Ingestion points: URL arguments described in SKILL.md for commands like /supabase-pentest and /supabase-detect.
- Boundary markers: No explicit boundary markers or 'ignore' instructions are described in this help reference.
- Capability inventory: The documented tools perform network requests, API data extraction, and local file writing for evidence storage.
- Sanitization: No input validation or content sanitization processes are mentioned in the help text.
Audit Metadata