Database

Database checks: Supabase, Firebase and Postgres

Find the table anyone can read before someone else does.

Supabase and Firebase put your database one request away from every visitor. If row-level security is off on a table, or a rule says "allow everyone", your users' data is public, and nothing in the app looks wrong.

Six agents review access rules, storage buckets, the connection, migrations and account deletion. They read your migration files and rules, tell you which data is exposed, and write the fix as a migration for you to review.

70
Checks
9
Agents
10
Commands

Some of what it looks for

  • STOR-01criticalA public bucket holds files that should be private
  • STOR-02criticalStorage policies let anyone upload, replace or delete files
  • TXN-01criticalA balance, credit count or stock level is read, changed in code and written back, so two requests at once lose an update
  • FIRE-01criticalFirestore rules allow everyone to read and write
  • FIRE-02criticalRules are still in "test mode", open until a date
  • FIRE-03criticalRules only require being logged in, so any user reaches every document
  • FIRE-05criticalRealtime Database rules have `.read` or `.write` set to `true`
  • SUPA-01criticalA table in the `public` schema has row-level security turned off

These are 8 of the 70 checks in this area, worst first.

The agents that do the work

  • supabase-rules-checker

    Reviews a Supabase project's row-level security policies, views and database functions to find data that anyone on the internet can read or change.

  • supabase-storage-checker

    Reviews Supabase Storage buckets and their access policies to find private files that are public and files that any user can overwrite or delete.

  • firebase-rules-checker

    Reviews Firebase security rules for Firestore, Realtime Database and Storage, plus Admin SDK keys and Cloud Functions, to find data that anyone can read or change.

  • database-safety-checker

    Reviews how a project connects to its SQL database and whether the schema has the basic safeguards: a limited-rights user, encryption, connection pooling, indexes and constraints.

  • migration-checker

    Reviews how a project changes its database structure: whether migrations exist, whether a pending one would destroy data, whether seed scripts could reach production, and whether development and production share a database.

  • data-deletion-checker

    Checks whether users can delete their account and get a copy of their data, and whether deletion really removes their personal data from every table, from file storage and from outside services.

  • query-performance-checker

    Finds database queries that will slow down or fail as data and traffic grow: queries in loops, lists with no limit, filtering in app code, deep OFFSET paging, wildcard search and missing timeouts.

  • data-integrity-checker

    Finds places where data goes wrong when two requests arrive at once or a step fails halfway: balances and stock that lose updates, missing transactions, coupons used twice, unsafe retries, deleted rows that reappear and cascades that delete too much.

  • db-runtime-checker

    Finds database setup that breaks under real traffic and real deploys: pooler settings that crash queries, connection pools larger than the database allows, migrations that lock busy tables, raw database errors shown to users, no recovery from brief outages and stale replica reads.

The commands you type

  • /launch-database

    All database checks, plus production checks that `/launch-check` does not run (see below). `/launch-database basic` skips them

  • /check-supabase

    Row-level security, views and database functions

  • /check-storage

    Supabase Storage: private files that are public, files anyone can overwrite

  • /check-firebase

    Firestore, Realtime Database and Storage rules

  • /check-database

    Connection, user rights, encryption, pooling, indexes, constraints

  • /check-migrations

    Missing migrations, changes that would destroy data, seed scripts

  • /check-data-deletion

    Can users delete their account and get their data? Is everything removed?

  • /check-queries

    Queries in loops, lists with no limit, filtering in code, deep paging, slow search, no query timeout

  • /check-data-integrity

    Balances and stock that lose updates, missing transactions, coupons used twice, unsafe retries, deleted data that comes back

  • /check-db-runtime

    Pooler settings that crash queries, too many connections, migrations that lock tables, raw database errors shown to users

/launch-check

Find the problems before your users do.

Install the kit into Claude Code, type one command, and get a score and a list of what to fix. Pay once, use it on every project you own.

41 agents · 440 checks · read-only audit · one-time payment