skills/jeremylongshore/claude-code-plugins-plus-skills/supabase-deploy-integration/Gen Agent Trust Hub
supabase-deploy-integration
Pass
Audited by Gen Agent Trust Hub on Mar 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were identified in the skill. The operations described are consistent with standard application deployment workflows.
- [COMMAND_EXECUTION]: The skill requires access to the Bash tool for executing commands via vercel, fly, and gcloud CLIs. This access is limited to the respective command namespaces and is necessary for managing secrets and deploying code to the specified platforms.
- [EXTERNAL_DOWNLOADS]: The skill references documentation and deployment services from well-known technology companies, including Supabase, Vercel, and Google Cloud Platform. These references are documented neutrally as legitimate resources for the deployment process.
- [PROMPT_INJECTION]: An indirect prompt injection surface exists as the skill ingests user-controlled application data (referenced in SKILL.md, references/google-cloud-run.md, and references/vercel-deployment.md) and possesses the capability to execute shell commands via platform-specific CLIs. No active exploitation or boundary bypass patterns were identified within the skill static instructions.
Audit Metadata