Read-only Postgres roles aren't truly read-only; dev open-sources scanner

Then_Respect_1964 · reddit · 2026-10-04

A developer points out that handing "read-only" Postgres credentials to MCP/agent workloads is unreliable: a role can gain privileges you didn't explicitly grant through inherited roles, ownership, PUBLIC grants, and more. What matters is the credential's effective permissions, not how it was originally provisioned.

To address this, the author open-sourced agent-db-scan: give it a Postgres connection string and it shows what that login can actually do. The author had been using manual scripting internally to check this before handing credentials to agents, and released a small open-source version. The project is still early.

Original post →

More from coding & agent

coding & agent channel →