Autonomous pentesting agents can test Supabase RLS for you. Give the agents two test accounts and your app's URL. They sign in as each user and try to read, change, and delete the other user's rows. Every leak comes with a working exploit. The agents can retest on every push.
Supabase exposes your Postgres tables straight to the browser. That makes row level security (RLS) your authorization layer. Autonomous pentesting agents can now test those policies the way a real attacker would, and keep testing them as you ship. This guide walks through how to set that up today.
Can AI agents test Supabase row level security?
Yes. Pentesting agents sign in as real users through your app and try to reach data that belongs to someone else. They read, change, and delete rows across accounts, just as an attacker would. A linter can tell you a policy exists. An agent tells you whether the policy actually stops someone.
How do you scope AI agents for a Supabase app?
Start by telling the agents what they may touch. Add your app's domain and your Supabase project URL to the include scope, since the frontend talks to both. Exclude anything you don't own, like payment or email providers. Then pick a pacing mode from Auto down to Extreme Stealth, because agents run in large teams.
![]()
What context should the agents have about your RLS policies?
Upload a short note on who should see what. For example, "users see only their own notes" and "admins see every note in their tenant." Agents use this to spot business logic flaws, which scanners miss because they don't know your intended rules. With that context, false positives stay under 1%.
![]()
Should you run a black-box or white-box test?
A black-box test starts with only your app and the anon key in its JavaScript bundle. That mirrors an outside attacker. Supabase calls the anon key safe to expose when RLS is on, so the agents test exactly what it can reach.
A white-box test also gives the agents your repo, including supabase/migrations. They can then read each policy and aim straight at the weak ones, so white-box usually finds more.
![]()
Which test accounts do the agents need?
Create two accounts so the agents can test one user against another. A regular user plus an admin also tests privilege escalation. MindFort's dual credential mode runs one assessment with both. Agents sign in with a password or magic link and handle email, SMS, or TOTP MFA.
![]()
What else do the agents find besides RLS gaps?
Agents attack the whole app, so they also find the issues around your policies:
- Leaked secret keys: a service_role key in the frontend bundle or a mobile app.
- API routes that skip RLS: a Next.js route with a secret-key client that trusts a request ID.
- Editable roles: a profile update that also lets users change their
roleorplancolumn. - Public storage: buckets that serve other users' IDs and invoices, the mistake behind the Tea app breach.
- Views and functions: views or security definer functions that return rows RLS would hide.
- Business logic flaws: IDOR, tenant crossover, and workflow abuse in the rest of your app.
Does the Supabase service role key bypass RLS?
Yes. The secret (service_role) key uses a Postgres role that bypasses every RLS policy . If it ships in your frontend or a mobile app, anyone can read and write every table. A black-box agent sees the same bundle an attacker does, so a leaked key shows up as a finding.
What happens when the agents find an RLS leak?
Each finding was actually exploited, so it comes validated with a working proof. You see the vulnerability type, severity, and automatic triage based on your context. Send it to Linear or Jira, or merge the patch pull request the agents write. After the fix, a retest costs 1 credit.
![]()
How do you keep testing Supabase RLS continuously?
Every new migration can loosen a policy. Real attackers don't wait for your annual pentest, so your testing shouldn't either. Trigger the agents through MCP or the API on every push, or schedule assessments. MindFort's agents learn from each run, so they get sharper on your app over time.
Where does MindFort fit in Supabase security testing?
MindFort gives you the agent swarm described above without building a harness yourself. The free plan includes 200 credits, about one pentest on one target. Our guide to testing multi-tenant apps for IDOR goes deeper on tenants and admin roles. The startups page covers how small teams run MindFort on every release.
About the author

Akul Gupta
Co-Founder & CTO · MindFort
AI researcher focusing on LLMs in cybersecurity. Red-teamed models for OpenAI and Anthropic as part of their safety programs. Published multiple conference papers. M.S. Computer Science, UIUC.