I kept finding the same three mistakes in Supabase projects built with AI tools:
Audit AI reads your migrations and Next.js routes and flags these. For a flagged finding it can run a sandbox: a local Supabase with your migrations, two test users in different tenants, network off. It tries the attack, applies the suggested migration and tries again.
You can try it on a demo app with three planted holes: open https://auditai.sh and paste github.com/audit0/auditai-playground.
The scanner is open source: github.com/audit0/auditai-scanner (npx auditai-scan .). Precision on repos it had never seen was 36% on a blind sample, published at auditai.sh/stats, so expect false positives. I would like to hear about the ones you hit.
AuditAI_sh introduces a tool that identifies common security issues in Supabase projects, such as missing RLS and insecure functions. The tool simulates attacks in a sandbox environment and suggests fixes. Another user, PeterBuildsSecure, suggests additional security checks and questions the tool's precision rate.
Those three are the right starting set, but two more are worth adding since they slip past exactly this kind of check:
Both are invisible if you're just reading migrations for missing/malformed RLS -- you need to check pg_policies + relforcerowsecurity + role privileges against a live connection, not the SQL text.
Also curious about the 36% precision number -- is that mostly false positives on the SECURITY DEFINER check (hard to tell "calls auth.uid()" from "actually gates on it") or something else? That's low enough to be interesting on its own.