chore(deps): update supabase/agent-skills digest to 8331f91 - #881
Conversation
🛡️ Skill Security Scan Results✅ supabase
✅ supabase-postgres-best-practices
Summary: Scanned 2 skill(s), all passed security checks. ✅ |
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
|
Pushed a follow-up commit allowlisting the `skill-security-scan` finding on `skills/supabase/spec.yaml`. The blocking finding (`LLM_UNAUTHORIZED_TOOL_USE`, HIGH) flags a new file added upstream, `references/skill-feedback.md`, which instructs the agent to file a GitHub issue with feedback. Checked the actual file content: it's gated on an explicit up-front user consent step ("Ask permission... If they decline, move on.") before any draft/submit happens — a documented, human-in-the-loop workflow, not a covert external write. Added an allowlist entry with that justification; the four `ATR_2026_00061` "fetch" pattern matches in this same PR are below the block threshold and don't need action. |
This PR contains the following updates:
1207767→8331f91Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.