Database
Database checks: Supabase, Firebase and Postgres
Find the table anyone can read before someone else does.
Supabase and Firebase put your database one request away from every visitor. If row-level security is off on a table, or a rule says "allow everyone", your users' data is public, and nothing in the app looks wrong.
Six agents review access rules, storage buckets, the connection, migrations and account deletion. They read your migration files and rules, tell you which data is exposed, and write the fix as a migration for you to review.
- 70
- Checks
- 9
- Agents
- 10
- Commands
Some of what it looks for
STOR-01criticalA public bucket holds files that should be privateSTOR-02criticalStorage policies let anyone upload, replace or delete filesTXN-01criticalA balance, credit count or stock level is read, changed in code and written back, so two requests at once lose an updateFIRE-01criticalFirestore rules allow everyone to read and writeFIRE-02criticalRules are still in "test mode", open until a dateFIRE-03criticalRules only require being logged in, so any user reaches every documentFIRE-05criticalRealtime Database rules have `.read` or `.write` set to `true`SUPA-01criticalA table in the `public` schema has row-level security turned off
These are 8 of the 70 checks in this area, worst first.
The agents that do the work
supabase-rules-checkerReviews a Supabase project's row-level security policies, views and database functions to find data that anyone on the internet can read or change.
supabase-storage-checkerReviews Supabase Storage buckets and their access policies to find private files that are public and files that any user can overwrite or delete.
firebase-rules-checkerReviews Firebase security rules for Firestore, Realtime Database and Storage, plus Admin SDK keys and Cloud Functions, to find data that anyone can read or change.
database-safety-checkerReviews how a project connects to its SQL database and whether the schema has the basic safeguards: a limited-rights user, encryption, connection pooling, indexes and constraints.
migration-checkerReviews how a project changes its database structure: whether migrations exist, whether a pending one would destroy data, whether seed scripts could reach production, and whether development and production share a database.
data-deletion-checkerChecks whether users can delete their account and get a copy of their data, and whether deletion really removes their personal data from every table, from file storage and from outside services.
query-performance-checkerFinds database queries that will slow down or fail as data and traffic grow: queries in loops, lists with no limit, filtering in app code, deep OFFSET paging, wildcard search and missing timeouts.
data-integrity-checkerFinds places where data goes wrong when two requests arrive at once or a step fails halfway: balances and stock that lose updates, missing transactions, coupons used twice, unsafe retries, deleted rows that reappear and cascades that delete too much.
db-runtime-checkerFinds database setup that breaks under real traffic and real deploys: pooler settings that crash queries, connection pools larger than the database allows, migrations that lock busy tables, raw database errors shown to users, no recovery from brief outages and stale replica reads.
The commands you type
/launch-databaseAll database checks, plus production checks that `/launch-check` does not run (see below). `/launch-database basic` skips them
/check-supabaseRow-level security, views and database functions
/check-storageSupabase Storage: private files that are public, files anyone can overwrite
/check-firebaseFirestore, Realtime Database and Storage rules
/check-databaseConnection, user rights, encryption, pooling, indexes, constraints
/check-migrationsMissing migrations, changes that would destroy data, seed scripts
/check-data-deletionCan users delete their account and get their data? Is everything removed?
/check-queriesQueries in loops, lists with no limit, filtering in code, deep paging, slow search, no query timeout
/check-data-integrityBalances and stock that lose updates, missing transactions, coupons used twice, unsafe retries, deleted data that comes back
/check-db-runtimePooler settings that crash queries, too many connections, migrations that lock tables, raw database errors shown to users
/launch-check
Find the problems before your users do.
Install the kit into Claude Code, type one command, and get a score and a list of what to fix. Pay once, use it on every project you own.
41 agents · 440 checks · read-only audit · one-time payment