More screenshots
Works with the AI tools you already use
🛡️ Supabase RLS Doctor
Audit your Supabase project for the row-level-security mistakes that quietly expose data: tables without RLS, policies that resolve to true, leaked service-role keys, missing auth.uid() checks, open storage buckets, overbroad grants, and migration drift. A local, read-only scan plus a full review checklist, each finding with severity, evidence, and a fix. No database changes without confirmation.
$19
· or 95 creditsSecure checkout via Stripe
About this skill
Deep Security Audits for Supabase Projects
The Supabase RLS Doctor is a specialized security skill designed to identify critical data exposure risks in your Supabase infrastructure. It moves beyond basic linting by performing an evidence-first audit of your Row Level Security (RLS) policies, storage rules, and client-side initialization logic.
What it does
- Identifies public table exposure and unsafe 'anonymous' access policies.
- Detects service role key leakage and frontend/backend boundary mistakes.
- Audits Supabase Storage bucket rules for unauthorized file access.
- Flags missing auth.uid() constraints and overbroad SQL grants.
- Analyzes migration drift and tenant ownership rules for multi-tenant apps.
Why use this skill
Unlike generic AI prompts, this skill uses a structured, multi-step workflow. It leverages internal heuristic scanners and a comprehensive audit checklist to ensure no stone is left unturned. It doesn't just guess; it ranks findings by severity (Critical to Info), cites exact lines of code as evidence, and provides copy-pasteable remediation snippets that are safe to apply.
Supported Inputs
- SQL Migrations and Policy files
- Supabase Client initialization code
- Database schema snapshots
- Storage policy configurations
Details
How to install
Drop the file into your AI Agent. Works with Claude, Cursor, ChatGPT, and 20+ more.
Reviews
No reviews yet - be the first to share your experience.
Only users who have downloaded or purchased this skill can leave a review.
Be the first to review this skill.
Only users who have downloaded or purchased this skill can leave a review.
Security Scanned
Passed automated security review
Permissions
File Scopes
Read-only inspection first. The bundled scanner reads matching files and prints markdown or JSON findings. It installs nothing, transmits nothing, and modifies nothing. Any write, install, deploy, payment, delete, reset, live-account action, or external network lookup requires explicit user confirmation.