NYC

supabase

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [Data Exposure] (LOW): The skill includes commands for managing secrets (supabase secrets set) and authentication (supabase login). While these handle sensitive information, they are standard functions of the Supabase CLI and do not demonstrate malicious exfiltration patterns.
  • [Indirect Prompt Injection] (LOW): Several commands ingest external data, such as supabase db execute (SQL results), supabase storage cp (file content), and supabase functions logs (log data). This represents a standard attack surface for indirect injection, though no active exploits are present.
  • [Command Execution] (SAFE): The skill utilizes the supabase CLI to perform infrastructure management. While it executes commands and deploys code (Edge Functions), these actions are the primary, documented purpose of the tool and are directed at the user's own Supabase environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:34 PM