Caveat verdict
supabase
supabase-db
88
๐ข Trusted
No high-risk patterns surfaced by the deep scan โ automated capability review, not behavioral proof.
Extended Supabase skill with same pattern; user-provided credentials, standard database operations against user own project, no unexpected exfiltration.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
70
security
100
transparency
90
maintenance
Findings (1)
Pattern match critical
Possible hardcoded credential
SKILL.md ยท code ยท TOKEN="sbp_xxxxx
Permissions & capabilities
Requires 2 environment variables.
Is this flag fair?
Thanks โ recorded.