← Files Vibe Code Security ReviewerARCHIVED FILE
skills/supabase-rls-security/SKILL.md
1.57 KB · Oct 3, 2026 · 06:36 UTC
--- name: supabase-rls-security description: Perform deep Supabase Row Level Security, Data API exposure, policy, view, function, and role analysis. --- # Supabase RLS Security Use for any Supabase database, Auth, Data API, Storage, view, function, or user-data review. ## Mandatory checks - Enable RLS on every table in exposed schemas, including `public` by default. - Confirm Data API exposure and explicit grants separately from row policies. - Check every table's `SELECT`, `INSERT`, `UPDATE`, and `DELETE` model. - For `UPDATE`, verify both `USING` and `WITH CHECK`; also verify the required `SELECT` policy. - Reject `TO authenticated` without an ownership, membership, tenant, or capability predicate. - Prefer `TO authenticated` or `TO anon` clauses; flag deprecated `auth.role()` checks. - Never use user-editable `raw_user_meta_data` for authorization; use trusted server-controlled app metadata or database membership tables. - Review views for `security_invoker = true` on supported Postgres versions or restricted access in an unexposed schema. - Review `SECURITY DEFINER` functions for schema placement, explicit authorization, fixed search path, minimal grants, and default `PUBLIC` execute privileges. - Check storage policies, including `SELECT`, `INSERT`, and `UPDATE` for upsert behavior. - Review service-role usage and ensure it never reaches public clients. ## Findings format Report table/schema, exposed role, operation, policy, predicate, bypass path, impact, and a safe SQL or application-level remediation. Never invent a policy without understanding the intended access model.
SHA-256: de6887369d3dbf3a95e3513a4e8e5d9ce72a63a54eb8e480e2c70b608c66ff84