Best fit
A local, read-only audit of a Supabase project for row-level-security mistakes: tables without RLS, policies that resolve to true, leaked service-role keys, missing auth.uid() checks, open storage buckets, overbroad grants, and migration drift.…