Security Audit
nextjs-supabase-auth
github.com/sickn33/antigravity-awesome-skillsTrust Assessment
nextjs-supabase-auth received a trust score of 72/100, placing it in the Caution category. This skill has some security considerations that users should review before deployment.
SkillShield's automated analysis identified 1 finding: 1 critical, 0 high, 0 medium, and 0 low severity. Key findings include LLM Persona and Instruction Override.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 20, 2026 (commit e36d6fd3). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| CRITICAL | LLM Persona and Instruction Override The untrusted skill content attempts to define the host LLM's persona and core operating principles ('You are an expert...', 'Your core principles:'). This is a direct prompt injection attempt, aiming to manipulate the LLM's behavior and potentially override its default instructions or context. Remove all direct instructions to the host LLM from untrusted skill content. Skill descriptions should be declarative about the skill's function and capabilities, not imperative instructions for the LLM's behavior or persona. | LLM | SKILL.md:3 |
Scan History
Embed Code
[](https://skillshield.io/report/a573964dc9b7dea6)
Powered by SkillShield