Default-Deny security posture for Supabase. Mandates strict RLS and 'WITH CHECK' clauses.
Scanned 9/12/2026
Install to Claude Code
npx -y skills add aibot88/sec_skill_store --skill draconian-rls-audit --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Draconian Rls Audit?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/aibot88-draconian-rls-audit)More formats (shields.io, HTML) on the badges page.
---
name: draconian_rls_audit
description: Default-Deny security posture for Supabase. Mandates strict RLS and 'WITH CHECK' clauses.
allowed-tools: Read, Edit, Write
---
# Draconian RLS Audit Protocol
## 1. Zero Trust (Default-Deny)
- **Mandate**: Every Table MUST have RLS enabled.
- **Policy**: The default state of any table should be NO ACCESS. Access is granted explicitly via Policy.
- **Detector**: Run `SELECT ... WHERE rowsecurity = false` to hunt down naked tables.
## 2. The "WITH CHECK" Imperative
- **Vulnerability**: An `INSERT` or `UPDATE` policy without `WITH CHECK` allows users to write data they cannot read, or worse, escalate privileges (e.g., "Give myself admin role").
- **Rule**: ALL modification policies MUST have a `WITH CHECK` clause matching the `USING` clause (or stricter).
## 3. Client-Side Key Ban
- **Strict Rule**: The string `service_role` MUST NOT exist in any file within `src/`.
- **Enforcement**: Grep for it. If found, STOP and warn the user.
## 4. Explicit `auth.uid()` Binding
- **Rule**: Policies should almost always bind to `auth.uid()`.
- **Ban**: Never hardcode UUIDs or email addresses in SQL policies.
## 5. Audit Checklist
- [ ] RLS enabled?
- [ ] Default policy is DENY?
- [ ] `WITH CHECK` present on writes?
- [ ] No `service_role` in client code?
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。
Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.
Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.
Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.