AI coding agents write insecure Supabase RLS policies — dev's CLI scan finds 12 high-severity issues
Real_KingZeotic · reddit · 2026-10-01
A Reddit user reports that when building Supabase apps with Cursor and Claude, AI agents often generate RLS policies that look secure but aren't — one loose policy can let anonymous users read everything.
The author built a small CLI to audit this and found 95 issues in his own repo, 12 high-severity: mostly stale test fixtures, but also a live service-role key in a public HTML file and outdated RLS policies exposing an access-key table.
He asks how others handle agent-written security policies: review or trust? Any key leaks? What tools do you check with before shipping?
More from coding & agent
- LlamaIndex Draws ~600 in SF for Agent Document Processing Events — llama_index · 2026-10-01
- Prime Intellect on why enterprises should own their intelligence, not rent it — willcb · 2026-10-01
- Falcon Neo enters private beta with next-gen design infra and agent-friendly markup language — KadriJibraan · 2026-10-01
- AWS shows multi-account MCP pattern: shared AgentCore Gateway keeps data in each team's account — gethackteam · 2026-10-01
- OpenClaw Collapses Inter-Agent Receipts Into Single Expandable Rows — steipete · 2026-10-01
- Google replaces Gems with Skills, adopting Anthropic's agent-ready prompt standard — The Decoder · 2026-10-01