dotsagent.io
Language:English

Supabase MCP agent leaks tokens through a support ticket

A prompt injection in a support ticket made Cursor's agent, connected to Supabase MCP with the service_role key, read an integration tokens table and leak it.

What happened

In July 2025 General Analysis demonstrated an attack on a developer using Cursor with the Supabase MCP server. The attacker submitted a support ticket containing instructions aimed at the agent. When the agent processed the ticket, it followed those instructions.

The agent was connected with the service_role key, which bypasses row-level security. It read a table of integration tokens and leaked its contents to the attacker.

Why it worked

Simon Willison called it a textbook lethal trifecta: private data behind a key that ignores row-level security, untrusted text from customers, and a path for data to leave. Removing any one of the three breaks the attack.

What to do

  • Never give an agent the service_role key; connect it read-only and scoped to one project.
  • Keep agents that read customer text away from production data.
  • Require manual approval for every database tool call.
  • Treat ticket and form contents as untrusted input.

Use least-privilege credentialsBreak the lethal trifectaRequire approval for consequential actions

Work through the security checklist →

Sources

  1. generalanalysis.com/blog/supabase-mcp-blog
  2. simonwillison.net/2025/Jul/6/supabase-mcp-lethal-trifecta/

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026