AI coding agents write insecure Supabase RLS policies — dev's CLI scan finds 12 high-severity issues

Real_KingZeotic · reddit · 2026-10-01

A Reddit user reports that when building Supabase apps with Cursor and Claude, AI agents often generate RLS policies that look secure but aren't — one loose policy can let anonymous users read everything.

The author built a small CLI to audit this and found 95 issues in his own repo, 12 high-severity: mostly stale test fixtures, but also a live service-role key in a public HTML file and outdated RLS policies exposing an access-key table.

He asks how others handle agent-written security policies: review or trust? Any key leaks? What tools do you check with before shipping?

Original post →

More from coding & agent

coding & agent channel →