SkillAgentSearch skills...

database-sentinel

Open-source security audits for Supabase: a read-only MCP server, a CLI agent and a Claude Skill. Finds RLS misconfigurations, exposed keys and risky functions, and returns a scored report with fix SQL. Hosted version: Locksoup.

Install / Use

claude mcp add Farenhytee -- npx -y github:Farenhytee/database-sentinel

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

79/100

Category

Security

Supported Platforms

Claude Code
Claude Desktop

Our assessment of database-sentinel

database-sentinel scores 79/100 on our quality scale, 1015th of 1,116 Security skills we index.

Its MCP Server is 15 KB long, well organised into 18 sections with 6 code examples: a thorough specification that gives an agent plenty to work with.

It has 48 GitHub stars, so there is little community track record yet; judge it on its content.

Substance
30/30
Structure
20/20
Description
15/15
Adoption
7/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated yesterday, so database-sentinel is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 97/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

database-sentinel compared with similar skills

All 4 of these similar skills score higher than database-sentinel; compare them before choosing.

SkillScoreStarsUpdatedFormat
database-sentinel (this skill)by Farenhytee79481d agoMCP Server
claude-memby thedotmack10096.6ktodayCLAUDE.md
Agent-Reachby Panniantong10091.8k20d agoCLAUDE.md
headroomby headroomlabs-ai10074.5ktodayCLAUDE.md
CowAgentby zhayujie10047.2ktodayCLAUDE.md

Frequently asked questions

How do I install database-sentinel?
Run claude mcp add Farenhytee -- npx -y github:Farenhytee/database-sentinel. The install tabs above show the steps for each supported agent.
Which AI agents does database-sentinel work with?
It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
Is database-sentinel safe to use?
It is MIT-licensed and scores 97/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is database-sentinel still maintained?
The repository was last updated yesterday, so database-sentinel is actively maintained.

🛡️ Database Sentinel

ci

Security audits for your database backend. Ask "audit my database" and get a scored report with exact fix code.

Works as a Claude Skill (Supabase, MongoDB), a read-only MCP server for any AI client, or a CLI agent that uses your own model (both Supabase).

→ MCP server setup and usage guide

→ Don't want to run it yourself? Locksoup is the hosted version: a Supabase security audit with scheduled re-checks and alerts.


Changelog

2026-10-01 (v1.0.1)

  • Fixed: an UPDATE policy without WITH CHECK is no longer reported as letting users reassign row ownership (Postgres reuses USING as the check). Q8's label and the agent prompt said otherwise, which produced false mass-assignment findings on real projects.
  • Benchmark: new dev case 027 from that project. Test F1 unchanged (0.836 vs 0.838, same day). Runs.

2026-09-30 (docs)

  • MCP flow benchmarked: a model driving the real server over stdio scored test F1 0.865, precision 0.905, critical recall 1.0 (results). Harness: evals/mcp_client.py, eval system m.

v1.0.0 (2026-09-30): MCP server release

  • MCP server v1.0: four read-only Supabase tools, an audit prompt and the catalog resources. Benchmarked end to end: a model driving the server over stdio scored test F1 0.865, with critical recall 1.0.
  • Verified on hosted Supabase: session pooler, read-only role with BYPASSRLS, all 20 queries.
  • Fewer false alarms:
    • Q1 now checks API grants: RLS off with anon/authenticated revoked isn't reported as exposed.
    • The audit prompt knows SECURITY INVOKER functions only have the caller's rights.
    • Found on a real project; new dev case 026.
  • Pin a version: git+https://github.com/Farenhytee/database-sentinel@v1.0.0 in any uvx/pipx command. The Claude Code plugin is pinned automatically.
  • Standard audit is now the CLI default: one prompt plus anon-probe verification, ~$0.0007 and ~15s per audit. --deep runs the tool-using agent, which scored the same on our bench at ~5× the cost.

v0.2.1 (2026-09-30)

  • Test F1: agent 0.782 → 0.831, single-prompt 0.766 → 0.849. No crashes or timeouts (results).
  • Fixed:
    • A bad tool argument no longer ends the audit; the error goes back to the model.
    • OpenRouter calls route to the fastest provider (slow ones caused timeouts).
    • The agent's final findings step no longer lists candidates it had dismissed.

v0.2.0 (2026-09-29)

  • Published test results: agent F1 0.782, single-prompt 0.766, rules 0.559 on a blind, locked 10-case test split, 3 runs each (results).
  • Bench: 25 labeled cases (15 dev, 10 blind test).
  • Agent:
    • Verify step: probes as anon to confirm exploitable findings.
    • --fix: prints fix SQL for findings you pick. It's never executed.
    • Cost reporting: tokens, $ and tool calls for each audit.
  • CI: free rules-only regression gate.

2026-09-29

  • One-command install: Claude Code plugin (skill + MCP server, prompts for your connection string) and an Add to Cursor button.
  • Install from GitHub: one command for the MCP server (uvx --from git+… sentinel-mcp) and the agent (pipx install "database-sentinel[agent] @ git+…").
  • sentinel-mcp --role-sql prints the read-only role setup SQL.
  • Clearer errors: the MCP client now sees why a call failed, and the CLI prints a single-line error.

2026-09-28

  • New: MCP server for Supabase. Four read-only tools, an audit prompt and the pattern catalog as resources. Your own LLM does the analysis, so it's free.
  • New: lite agent (sentinel-audit). A LangGraph pipeline that works with any OpenAI-compatible model: OpenRouter, OpenAI, or local Ollama.
  • New: benchmark + evals. 10 labeled Supabase cases, with precision/recall/F1 compared across a rules baseline, a single-prompt baseline and the agent.
  • Fixed: six Supabase audit queries. Q8 (UPDATE without WITH CHECK) never matched anything, Q16 and Q19 missed rows for least-privilege roles, and Q6, Q13 and Q14 had wrong conditions.

Quick start

Claude Code installs the audit skill and the MCP server in one go (needs uv):

claude plugin marketplace add Farenhytee/database-sentinel
claude plugin install database-sentinel@database-sentinel

Supabase users: create the read-only login (step 1), then run /plugin configure database-sentinel@database-sentinel in Claude Code. Then ask: Audit my database.

Cursor   Add to Cursor

Other MCP clients, and full setup: MCP guide

<details> <summary>More ways to install</summary>

Skill only (Claude Code picks it up automatically):

git clone https://github.com/Farenhytee/database-sentinel.git ~/.claude/skills/database-sentinel

CLI agent (Supabase, bring your own model):

pipx install "database-sentinel[agent] @ git+https://github.com/Farenhytee/database-sentinel"
export SENTINEL_BASE_URL=http://localhost:11434/v1 SENTINEL_MODEL=<model>   # Ollama, or any OpenAI-compatible API + SENTINEL_API_KEY
sentinel-audit --dsn "postgresql://sentinel_auditor:<password>@<host>:5432/postgres" \
  --rest-url https://<ref>.supabase.co --anon-key <anon key> --repo ./my-app

The default audit is one prompt plus anon-probe verification. --deep runs a tool-using agent instead: same accuracy on our bench, ~5× the cost. --fix prints fix SQL for the findings you pick; it's never executed.

</details>

What it catches

| Backend | Patterns | Examples | |---|---|---| | Supabase | 27 (catalog) | RLS disabled, service-role key in frontend, USING (true), views bypassing RLS, exposed SECURITY DEFINER functions, user_metadata in policies, mass assignment, public buckets | | MongoDB | 20 (catalog) | MongoBleed (CVE-2025-14847), auth disabled, 0.0.0.0/0 Atlas allowlist, server-side JS, privileged app user |

Full tables are in Appendix A.

Safety

  • Read-only by default. Only system catalogs are read. The MCP server and agent can't write, drop or delete anything.
  • Your rows are never read. The audit role has no access to table data. Repo scans report file and line, never secret values.
  • Write and network probes are opt-in (Skill only). Details are in Appendix D.

Status

| Backend | Skill | MCP server / agent | |---|---|---| | Supabase | ✅ | ✅ | | MongoDB | ✅ | planned | | Firebase, Postgres, MySQL, cross-backend | planned | planned |

License

MIT. Exception: database_sentinel/agent/, database_sentinel/mcp_server/ and database_sentinel/kb/ are AGPL-3.0 (see the LICENSE in each).


Appendix

A. Pattern highlights

Supabase

| Severity | Pattern | What | |---|---|---| | 🔴 CRITICAL | RLS_DISABLED | Tables without Row-Level Security are fully exposed | | 🔴 CRITICAL | SERVICE_ROLE_EXPOSED | service_role key in frontend code bypasses all security | | 🔴 CRITICAL | POLICIES_BUT_NO_RLS | Policies written but RLS never enabled | | 🟠 HIGH | USING_TRUE | USING (true) on writes or private data | | 🟠 HIGH | VIEW_NO_SECURITY_INVOKER | Views bypass RLS and run as their owner | | 🟠 HIGH | SECURITY_DEFINER_EXPOSED | RLS-bypassing functions callable via the API | | 🟠 HIGH | USER_METADATA_IN_POLICY | Policies trust user-editable metadata | | 🟠 HIGH | MASS_ASSIGNMENT | Users can update privilege/billing columns on their own rows | | 🟠 HIGH | GHOST_AUTH | Unconfirmed sign-ups get authenticated sessions | | 🟠 HIGH | JWT_SECRET_EXPOSED | Leaked signing secret lets attackers forge any token | | 🟡 MEDIUM | + 17 more | anti-patterns.md |

MongoDB

| Severity | Pattern | What | |---|---|---| | 🔴 CRITICAL | MG-SH-001 MongoBleed (CVE-2025-14847, CISA KEV) | Pre-auth heap memory disclosure; ~87K instances exposed at disclosure | | 🔴 CRITICAL | MG-SH-002 Auth disabled | No authentication (Meow ransomware surface) | | 🔴 CRITICAL | MG-SH-003 Internet-bound mongod | --bind_ip_all + reachable 27017 | | 🔴 CRITICAL | MG-AT-001 Atlas allowlist 0.0.0.0/0 | Cluster reachable from anywhere | | 🟠 HIGH | MG-SH-005 Server-side JS enabled | $where / $function / mapReduce reachable | | 🟠 HIGH | MG-SH-007 Privileged app user | App connects as root / dbAdminAnyDatabase | | 🟠 HIGH | MG-AT-002 Atlas Function pass-through | NoSQL injection over HTTPS | | 🟡 MEDIUM | + 13 more | anti-patterns.md |

The MongoBleed probe (mongobleed-probe.md) is a single-packet, read-only detector. It was verified against mongo:7.0.20 (vulnerable) and 7.0.28 (patched), and runs only after two opt-in confirmations.

B. How the Skill audits

  1. Detect backends. 2. Scan code for exposed credentials. 3. Introspect schema, policies and config. 4. Match against the anti-pattern catalogs. 5. Probe safely (opt-in). 6. Score and report. 7. Generate fix code.

Only SKILL.md (~2K tokens) and core/* load up front; each backend's files load only when that backend is detected.

C. Example output

╔════════════════════════════════════════════════════════╗
║                  SENTINEL SECURITY AUDIT               ║
║  Backends: supabase        Score: 35/100 🔴            ║
╚════════════════════════════════════════════════════════╝

🔴 CRITICAL — public.users: RLS Disabled                  [RLS_DISABLED]
  Risk:   Anyone on the internet can read your entire users table.
  Attack: Copy the anon key from DevTools → curl the API → dump all rows.
  Source: CVE-2025-48757 / Splinter 0013_rls_disabled_in_public
  Fix:    ALTER TABLE public.users ENABLE ROW LEVEL SECURITY;
          CREATE POLICY "users_select_own" ON public.users FOR SELECT
            TO authenticated USING ((SELECT auth.uid()) = id);

D. Safety details

  • Supabase write probes: Prefer: tx=rollback, so no data is modified.
  • MongoDB write probes: session + abortTransaction() on replica sets; canary insert + delete on standalone (opt-in).
  • MongoBleed network probe: double opt-in; some monitoring tools alert on the 42-byte probe packet.
  • Auth probes use .invalid email domains (RFC 6761).
  • Credentials are held in memory for the audit only, and redacted in reports.
  • MCP server: five independent read-only layers (details).

E. Benchmark and evals

bench/cases/ holds labeled Supabase schemas applied to a local Supabase. evals/ scores three systems on precision, recall and F1: R0 (rules, no LLM), B0 (single prompt) and A (agent). The test split is frozen and never tuned on.

Test split (10 blind, locked cases), deepseek-v4-flash, 3 runs each:

| Version | System | Precision | Recall | F1 | CRITICAL recall | $/audit | |---|---|---|---|---|---|---| | v1.0.0 | MCP server

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars48
CategorySecurity
Updated1d ago
Forks7

Languages

Python

Trust signals

97/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 info