Skip to the card

Card 059 of 10002026-09-11 issue

Observed arrival · 2026-09-11

Audit AI: Authorization Bugs With Receipts

auditor.click Observed source
Editorial interest 82/100 Selection signal · not a rating of the site

A security scanner for AI-built Next.js and Supabase applications that tests whether users can cross tenant boundaries, proposes a fix, and generates a regression test.

Landing page captured for the 2026-09-11 issue.

Field notes

The scanner focuses on authorization and tenant-isolation paths in Next.js and Supabase projects, tracing routes, identity, queries, and row-level security policies before exercising endpoints with synthetic customers. Its example report records a cross-tenant invoice request changing from HTTP 200 to HTTP 403, alongside a five-test security suite and a 142-test existing suite. The page says public scans are read-only and model-free, while private-repository auditing is described through a GitHub App or local command.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

OpenPublic substance visible
$PaidCommerce or pricing visible
PrettyNotable craft visible
ProPolished or operationally mature
NicheUnusually specific use
ƒJavaScriptBrowser-side code central

One card from the complete issue

Projection by Pedal

381,023 arrived 1,000 judged 1000 catalogued Enter the complete issue
auditor.click

Landing page observed 2026-09-11. The live site may have changed.