The skill appears to be a legitimate Volcengine Supabase administration skill, but it needs review because some paths can change live backend state or weaken authentication without strong guardrails.
Review before installing. Use only with Volcengine accounts and workspaces you want the agent to administer, prefer temporary or least-privilege credentials, and avoid shared machines with persistent CLI profiles. Do not use --no-verify-jwt unless the function implements its own authentication or webhook signature checks. Treat --show-values, API keys, service-role keys, raw SQL, delete, stop, and deployment commands as sensitive actions requiring explicit user intent and verification on a non-production branch first.