Back to skill

Security audit

supabase-postgres-best-practices

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Postgres best-practices reference skill, with expected database-change guidance but no hidden execution, persistence, or exfiltration behavior.

Install this as a documentation/reference skill for Postgres work, not as an automation you blindly apply to production. Review generated SQL before execution, especially examples involving ALTER SYSTEM, COPY, EXPLAIN ANALYZE, DROP, grants/revokes, RLS policies, or statistics resets, and prefer staging or backups for high-impact changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description says to load the skill before writing or changing 'anything that lives in a Postgres database' and also for many diagnosis scenarios. This trigger scope is extremely broad and lacks explicit boundaries or negative examples, increasing the chance of unintended invocation across routine database work.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This is a markdown file, so SQP-2 applies to omitted warnings about behaviors that could affect user data or system integrity. The guidance uses alter system and reloads configuration to terminate idle or idle-in-transaction sessions, but it does not warn users that affected sessions may be disconnected and uncommitted work may be lost or rolled back.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file falls under the markdown scope for missing user warnings. The guidance introduces a high-impact database operation that reads from a local path and loads data into a table, but it provides no warning about validating the file source, target table, or the risk of large-scale unintended data modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This guidance recommends EXPLAIN ANALYZE broadly and says it executes the query, but it does not warn that on non-SELECT statements it will actually run the statement and can trigger writes, function side effects, triggers, or external actions. In a database best-practices skill, that omission is risky because users may apply the advice to UPDATE, DELETE, INSERT, or function calls while diagnosing production issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guidance recommends calling pg_stat_statements_reset() without warning that it clears accumulated query statistics for the entire tracked dataset. In a monitoring and tuning context, this can cause loss of historical performance visibility, disrupt ongoing investigations, and make before/after comparisons unreliable if run prematurely or by the wrong operator.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.