RLS Doctor
A read-only Postgres and Supabase RLS auditor. Reports policy, role, and grant risks from catalog metadata without touching data.
Problem
Small policy mistakes can expose rows through disabled RLS, broad roles, missing write checks, or overlooked privilege paths. Normal application tests rarely explain the catalog state behind those failures.
System
The CLI reads PostgreSQL catalog metadata, models policies, roles, memberships, and grants together, then reports specific risks with text or JSON output without mutating the target database.
Proof
- Published on npm with install-free npx usage.
- Runs read-only catalog analysis and sanitizes credentials from connection errors.
- Includes disposable PostgreSQL integration fixtures and CI coverage.
- Packages the review workflow as an installable Agent Skill.
Architecture
- ConnectUse a read-only PostgreSQL connection for the selected schemas.
- ModelLoad tables, policies, grants, roles, and membership paths.
- AnalyzeCommand-aware rules identify structural access risks.
- ReportText and JSON outputs explain evidence and safer next steps.
Decisions
- Analyze policy composition and reachable roles instead of counting policies in isolation.
- Keep suggested remediation conservative because ownership and tenant models vary.
- Support human-readable output and stable JSON for automation.
Tradeoffs and limitations
- Catalog inspection cannot prove application-level authorization behavior.
- Hosted platform settings, views, and functions require separate review.
Technologies
- TypeScript
- Node.js
- PostgreSQL
- Supabase RLS
- Vitest
- GitHub Actions