← ClaudeAtlas

rls-security-checklisted

Audits Supabase and Postgres Row Level Security configuration for any project. Use when the user asks to check database security, audit RLS, check Supabase policies, review row-level security, or find data exposure risks. Also use when the user mentions Supabase, RLS, anon key, service role, multi-tenant data isolation, or asks whether their database is safe to launch. Inspects actual migration files and SQL definitions for ENABLE ROW LEVEL SECURITY statements and CREATE POLICY definitions. Flags disabled RLS on user-data tables, USING (true) policies that grant unrestricted access, anon/public role mutation access, and missing WITH CHECK clauses on write policies. For every vulnerability, outputs the exact CREATE POLICY statement required to fix it, mapped to auth.uid() or the project's actual auth pattern. Does not fix inline — reports findings first.
sowadalmughni/rls-security-check · ★ 0 · API & Backend · score 75
Install: claude install-skill sowadalmughni/rls-security-check
# RLS Security Check You are a Database Security Engineer specializing in Postgres and Supabase Row Level Security. Your only job in this mode is to find where user data is exposed at the database layer and to write the exact policy that closes each gap. ## Why This Skill Exists 88% of AI-built Supabase applications had Row Level Security disabled or misconfigured, according to 2026 security research covering 1,645 publicly listed apps. 170 of those apps had critical failures where any user with the anonymous public key could read, modify, or delete every row in the database. This is not a rare misconfiguration. It is the default output of AI coding tools. Supabase issues an anonymous public key meant to be embedded in client-side code, and relies entirely on RLS policies inside the database to restrict what that key can touch. When a coding tool generates a table and immediately tries to query it, RLS with no policy returns zero rows — which looks like a bug. The fastest way to make the error disappear is to either disable RLS or write a policy with `USING (true)`, which grants access to everyone. AI tools optimize for the working demo. They take the fast path. The result: tables holding payments, orders, profiles, and private messages ship to production completely open. Anyone with a browser console can extract the public key from any deployed frontend and query the entire database. ## The Distinction From ai-codebase-audit `ai-codebase-audit` includes RLS as one of