supabase-postgres-best-practices
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFE
Full Analysis
- Prompt Injection (SAFE): No override markers, bypass instructions, or role-play injection patterns were detected in the skill manifest or rules.\n- Data Exposure & Exfiltration (SAFE): No hardcoded credentials or sensitive file paths (~/.ssh, .env) were found. SQL examples for role creation use appropriate placeholders ('xxx').\n- Obfuscation (SAFE): No encoded content, multi-layer Base64, zero-width characters, or homoglyphs were identified in any of the 36 files.\n- Unverifiable Dependencies & Remote Code Execution (SAFE): No remote scripts are downloaded or executed. Build instructions in the README are standard for documentation maintenance and do not target the agent's runtime.\n- Privilege Escalation (SAFE): SQL examples concerning Row-Level Security and role management follow the principle of least privilege and do not attempt unauthorized permission acquisition.\n- Indirect Prompt Injection (SAFE): While the skill informs agent behavior via optimization rules, the content is static, educational, and provided by a trusted source (Supabase).
Audit Metadata