skills/hopeoverture/worldbuilding-app-skills/supabase-prisma-database-management/Gen Agent Trust Hub
supabase-prisma-database-management
Fail
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- Indirect Prompt Injection (HIGH): The skill presents a significant vulnerability surface because it processes untrusted content (database schemas and seed scripts) and possesses high-trust write and execute capabilities.\n
- Ingestion points: The agent processes database schema definitions (
prisma/schema.prisma) and data scripts (prisma/seed.ts) which can be influenced by external project requirements or attacker-controlled data.\n - Boundary markers: Absent; there are no clear delimiters or instructions telling the agent to ignore commands or logic embedded within the schema or data files it reads.\n
- Capability inventory: The skill can execute
npm install,npx prisma migrate dev(which executes SQL), andnpx prisma db seed(which executes TypeScript viats-node). It also includes destructive commands likenpx prisma migrate reset.\n - Sanitization: Absent; the skill relies on direct execution of the files it manages without validation of the embedded logic.\n- Unverifiable Dependencies & Remote Code Execution (MEDIUM): The skill installs and executes packages (
prisma,ts-node) and scripts (seed.ts) at runtime. While the packages are from a trusted registry (npm), the execution of a locally-defined seed script represents a high-capability execution path.\n- Privilege Escalation (MEDIUM): The skill encourages the use of potentially destructive commands likeprisma migrate resetand requires high-privilege database credentials to be stored in the.envfile for schema modifications.
Recommendations
- AI detected serious security threats
Audit Metadata