I audited my own back ends on 5 BaaS – leak in every one
Active anon-key probing confirms leaks live instead of just inferring them from config.
The Supabase deploy-gate that runs where you vibe-code. Static OSS scanner for the RLS/secret holes that leak vibe-coded apps — CLI + Claude Code skill + GitHub Action.
Static RLS scanner blocks deploys before Supabase leaks hit production.
Supabase developers
Semgrep · TruffleHog · Supabase CLI
Active anon-key probing confirms leaks live instead of just inferring them from config.
First static analyzer for MCP servers catching command injection before you plug it in.
Yet another secret scanner, but this one's a single Python file.
Static binary deployment platform, but README lacks concrete examples or live demos.
Static scanner catches prompt injections in code before runtime, unlike runtime guards.
Self-hosted Loom via Supabase—records to your infra, no vendor lock-in, fully auditable.