Observed arrival · 2026-09-11
Audit AI: Authorization Bugs With Receipts
A security scanner for AI-built Next.js and Supabase applications that tests whether users can cross tenant boundaries, proposes a fix, and generates a regression test.
Field notes
The scanner focuses on authorization and tenant-isolation paths in Next.js and Supabase projects, tracing routes, identity, queries, and row-level security policies before exercising endpoints with synthetic customers. Its example report records a cross-tenant invoice request changing from HTTP 200 to HTTP 403, alongside a five-test security suite and a 142-test existing suite. The page says public scans are read-only and model-free, while private-repository auditing is described through a GitHub App or local command.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue