TechnoTenshi :verified_trans: :Fire_Lesbian:<p>Supabase's MCP is vulnerable to "lethal trifecta" attacks where LLMs with elevated DB access, exposed to user input, can be tricked into leaking sensitive data. Read-only mode helps but doesn't eliminate risk. </p><p><a href="https://simonwillison.net/2025/Jul/6/supabase-mcp-lethal-trifecta/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">simonwillison.net/2025/Jul/6/s</span><span class="invisible">upabase-mcp-lethal-trifecta/</span></a></p><p><a href="https://infosec.exchange/tags/PromptInjection" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PromptInjection</span></a> <a href="https://infosec.exchange/tags/LLMSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LLMSecurity</span></a> <a href="https://infosec.exchange/tags/Supabase" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Supabase</span></a> <a href="https://infosec.exchange/tags/Infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Infosec</span></a></p>