perufitlife/Supabase Security Audit

Audit your Supabase project for RLS leaks, exposed buckets, anon-readable tables. Active anon-key probe confirms each finding live.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
project-refSupabase project reference (the subdomain in your *.supabase.co URL)yes
tokenSupabase Personal Access Token (read-only is enough). Generate at https://supabase.com/dashboard/account/tokensyes
output-pathPath for the HTML reportnosupabase-security-report.html
fail-onSeverity to fail the workflow on: critical, high, medium, low, nevernocritical
webhook-urlOptional webhook to POST findings to (e.g., RLS Monitor)no
webhook-tokenOptional bearer token for the webhookno
namedescription
critical-countNumber of CRITICAL findings
high-countNumber of HIGH findings
gradeLetter grade (A+ to F)
report-pathPath of the generated HTML report