database-sentinel
SkillClaude Code skill that audits projects for RLS misconfigurations, exposed keys, auth bypasses, and Supabase storage vulnerabilities.
git clone https://github.com/Farenhytee/database-sentinelSecurity audits for your database backend. Ask "audit my database" and get a scored report with exact fix code.
Works as a Claude Skill (Supabase, MongoDB), a read-only MCP server for any AI client, or a CLI agent that uses your own model (both Supabase).
→ MCP server setup and usage guide
2026-10-01 (v1.0.1) Fixed: an UPDATE policy without WITH CHECK is no longer reported as letting users reassign row ownership (Postgres reuses USING as the check). Q8's label and the agent prompt said otherwise, which produced false mass-assignment findings on real projects. Benchmark: new dev case 027 from that project. Test F1 unchanged (0.836 vs 0.838, same day). Runs.
- Source
- community
- Known advisories
- 0
- Maintenance
- active
- License
- MIT
- Age
- 6 months