Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
database-sentinel — Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced from CVE-2025-48757 and 10 security studies. Safe for production. | Kitploit
Tools/GitHubGitHub/farenhytee/database-sentinel
Authentication & AuthorizationVulnerability ScannersCode AnalysisConfiguration AuditingCloud SecurityDevSecOpsSecret DetectionMisconfigurationLearning & Education

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
AI Security
Database Security
GitHubfarenhytee/database-sentinel

database-sentinel

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced from CVE-2025-48757 and 10 security studies. Safe for production.

View Repository
415175 months agoReviewed by Kitploit

🛡️ Database Sentinel

A Claude Skill that audits your database backends for security vulnerabilities.

Drop it into Claude Code, Cursor, or any Claude-powered environment. Say "audit my database" and get a comprehensive security report with exact fix code — in minutes, not days.

170+ Lovable apps were breached. 20.1M rows were exposed across YC startups. ~87,000 MongoDB instances were left vulnerable to MongoBleed (CVE-2025-14847, CISA KEV). 1.8M Firebase passwords leaked in a single 2025 incident. 45% of AI-generated code introduces OWASP Top 10 vulnerabilities. Database Sentinel tests whether your security configuration actually works — not just whether it's present.


What it does

Database Sentinel performs a 7-step security audit on whichever backend(s) your project uses:

  1. Detects which backends you're using (Supabase, Firebase, MongoDB, self-hosted Postgres / MySQL)
  2. Scans your codebase for exposed credentials, hardcoded keys, secrets in git
  3. Introspects each backend — schema, policies, rules, users, roles, configuration
  4. Matches findings against backend-specific anti-pattern catalogs sourced from CVEs, breach reports, CIS benchmarks, and 2025–2026 vibe-coding research
  5. Dynamically probes with safe primitives (tx=rollback, canary collections, opt-in MongoBleed detector)
  6. Generates a scored security report with plain-English explanations and concrete attacker scenarios
  7. Produces exact fix code — SQL DDL, rule files, config diffs, Terraform — copy, paste, done

Cross-backend reasoning catches issues that single-backend scanners miss (e.g., a Firebase Auth UID trusted by a Postgres API without JWT verification).


Status

PhaseBackendStatus
1Supabase✅ shipped
2MongoDB (self-hosted + Atlas)✅ shipped
3Firebase (Firestore / RTDB / Storage / Functions / Remote Config)🚧 planned
4PostgreSQL (self-hosted, including pgBouncer)🚧 planned
5MySQL (self-hosted)🚧 planned
6Cross-backend interaction analysis🚧 planned
7Distribution + polish🚧 planned

Database Sentinel was previously Supabase Sentinel (single-backend). The rename happened during Phase 1 of the multi-backend expansion. A backwards-compat shim at compat/supabase-sentinel/ preserves the old skill name through at least the next minor release — existing users see no regression.


Quick start

Option 1: Claude Code / Cursor

Clone the skill into your project's skills directory, or a central one:

git clone https://github.com/Farenhytee/database-sentinel.git ~/claude-skills/database-sentinel

Then ask Claude:

Audit my database

Database Sentinel will detect which backend(s) your project uses, run the relevant audits, and produce a unified report. If multiple backends are present (Firebase Auth + Postgres data, etc.), the report includes a cross-backend interactions section once Phase 6 lands.

Option 2: Single-backend invocation

If you only want to audit a specific backend, ask explicitly:

Audit my Supabase project
Audit my MongoDB instance

The dispatcher narrows the scope.

Option 3: Manual (any AI assistant)

Copy the contents of SKILL.md plus the relevant backends/<name>/workflow.md into your system prompt. Walk through the 7 steps with your credentials.


What it catches

Supabase (Phase 1) — 27 patterns

SeverityPatternWhat
🔴 CRITICALSB-001 RLS_DISABLEDTables without Row-Level Security — fully exposed to the internet
🔴 CRITICALSB-002 SERVICE_ROLE_EXPOSEDservice_role key in frontend code — bypasses ALL security
🔴 CRITICALSB-003 POLICIES_BUT_NO_RLSPolicies written but RLS never enabled — false security
🔴 CRITICALSB-005 WRITE_USING_TRUEINSERT/UPDATE/DELETE with USING(true) — anyone can modify
🟠 HIGHSB-006 USING_TRUE_SELECTAll rows readable by anonymous users on sensitive tables
🟠 HIGHSB-007 VIEW_NO_SECURITY_INVOKERViews bypass RLS, run as superuser
🟠 HIGHSB-008 SECURITY_DEFINER_EXPOSEDFunctions in public schema bypass RLS, callable via API
🟠 HIGHSB-009 USER_METADATA_IN_POLICYPolicies reference user-modifiable metadata — privilege escalation
🟠 HIGHSB-010 UPDATE_NO_WITHCHECKUPDATE policies without WITH CHECK — mass assignment risk
🟠 HIGHSB-011 GHOST_AUTHUnconfirmed email signups grant authenticated sessions
🟠 HIGHSB-012 STORAGE_NO_RLSStorage bucket missing access control policies
🟠 HIGHSB-013 JWT_SECRET_EXPOSEDJWT signing secret leaked — can forge any user's token
🟡 MEDIUM+ 15 more patternsSee backends/supabase/anti-patterns.md

MongoDB (Phase 2) — 20 patterns

SeverityPatternWhat
🔴 CRITICALMG-SH-001 MongoBleed (CVE-2025-14847, CISA KEV)Pre-auth heap memory disclosure via crafted compressed packet. ~87K instances exposed at disclosure.
🔴 CRITICALMG-SH-002 Auth disabledmongod running with no authentication — Meow ransomware attack surface
🔴 CRITICALMG-SH-003 Internet-bound mongod--bind_ip_all + 27017 reachable — paired with MG-SH-002 for total compromise
🔴 CRITICALMG-AT-001 Atlas allowlist 0.0.0.0/0Atlas cluster reachable from anywhere on the internet
🟠 HIGHMG-SH-004 localhost auth bypass + container execenableLocalhostAuthBypass true + docker exec access
🟠 HIGHMG-SH-005 Server-side JS enabled$where / $function / mapReduce reachable — NoSQL-RCE surface
🟠 HIGHMG-SH-006 TLS not requiredPlaintext traffic on the wire
🟠 HIGHMG-SH-007 Privileged role on app userApp connects as root / dbAdminAnyDatabase etc.
🟠 HIGHMG-SH-008 Self-modifiable role documentfindByIdAndUpdate(id, req.body) + no validator + role field
🟠 HIGHMG-AT-002 Atlas Function as DB pass-throughNoSQL injection over HTTPS — proliferated post-Data-API-deprecation
🟠 HIGHMG-AT-003 Atlas Data API still in codeDeprecated Sept 30 2025; broken AND likely rotated to less-audited Functions
🟡 MEDIUMMG-SH-009 Mongoose < 8.9.5CVE-2024-53900 / CVE-2025-23061 — populate-match $where injection
🟡 MEDIUM+ 8 more patternsSee backends/mongodb/anti-patterns.md

The MongoBleed network probe (backends/mongodb/mongobleed-probe.md) ships a single-packet detector that confirms exploitability at runtime — verified against mongo:7.0.20 (vulnerable) and mongo:7.0.28 (patched). It's read-only, gated behind two opt-in confirmations, and never extracts content.


Example output

╔════════════════════════════════════════════════════════╗
║                  SENTINEL SECURITY AUDIT               ║
╠════════════════════════════════════════════════════════╣
║  Backends:   supabase, mongodb                         ║
║  Scanned:    2026-04-30 14:30 UTC                      ║
║  Score:      0/100 🔴                                  ║
║  Summary:    2 backends, 8 findings (3C / 4H / 1M)     ║
╚════════════════════════════════════════════════════════╝

─────────────────────────────────────────────────────────
  Supabase                                       35/100 🔴
─────────────────────────────────────────────────────────

🔴 CRITICAL — public.users: RLS Disabled                  [SB-001]

  Risk:     Anyone on the internet can read your entire users table.
  Attack:   Open browser DevTools → copy anon key → curl the API → dump
            all emails, names, and metadata.
  Proof:    curl returns [{"id":"...","email":"[email protected]",...}]
  Source:   CVE-2025-48757 / Splinter 0013_rls_disabled_in_public

  Fix:
  ALTER TABLE public.users ENABLE ROW LEVEL SECURITY;
Download Tool