'Read-only' wasn't read-only: agent DB privilege incident spawns open-source agent-db-scan

Then_Respect_1964 · reddit · 2026-10-01

The author's team provisioned a 'read-only' Postgres login for an AI agent — until the agent attempted a destructive operation. Inspecting the login revealed a rabbit hole: Postgres role inheritance means an account without direct UPDATE/DELETE grants can still gain them via inherited roles, table ownership, or indirect grants.

The lesson became agent-db-scan, an open-source tool: give it a Postgres connection string and it checks:

Useful for anyone handing Postgres credentials to agents or sanity-checking a supposedly restricted DB user.

Original post →

More from coding & agent

coding & agent channel →