Back to list
cityfish91159

draconian-rls-audit

by cityfish91159

0🍴 0📅 Jan 24, 2026

SKILL.md


name: draconian_rls_audit description: Default-Deny security posture for Supabase. Mandates strict RLS and 'WITH CHECK' clauses. allowed-tools: Read, Edit, Write

Draconian RLS Audit Protocol

1. Zero Trust (Default-Deny)

  • Mandate: Every Table MUST have RLS enabled.
  • Policy: The default state of any table should be NO ACCESS. Access is granted explicitly via Policy.
  • Detector: Run SELECT ... WHERE rowsecurity = false to hunt down naked tables.

2. The "WITH CHECK" Imperative

  • Vulnerability: An INSERT or UPDATE policy without WITH CHECK allows users to write data they cannot read, or worse, escalate privileges (e.g., "Give myself admin role").
  • Rule: ALL modification policies MUST have a WITH CHECK clause matching the USING clause (or stricter).

3. Client-Side Key Ban

  • Strict Rule: The string service_role MUST NOT exist in any file within src/.
  • Enforcement: Grep for it. If found, STOP and warn the user.

4. Explicit auth.uid() Binding

  • Rule: Policies should almost always bind to auth.uid().
  • Ban: Never hardcode UUIDs or email addresses in SQL policies.

5. Audit Checklist

  • RLS enabled?
  • Default policy is DENY?
  • WITH CHECK present on writes?
  • No service_role in client code?

Score

Total Score

50/100

Based on repository quality metrics

SKILL.md

SKILL.mdファイルが含まれている

+20
LICENSE

ライセンスが設定されている

0/10
説明文

100文字以上の説明がある

0/10
人気

GitHub Stars 100以上

0/15
最近の活動

3ヶ月以内に更新がある

0/10
フォーク

10回以上フォークされている

0/5
Issue管理

オープンIssueが50未満

+5
言語

プログラミング言語が設定されている

+5
タグ

1つ以上のタグが設定されている

0/5

Reviews

💬

Reviews coming soon