prodcheck

← all checklists

Supabase

23 items · source

Architecture & Threat Model

Authentication & Authorization

Secrets Management & Cryptography

Monitoring, Detection & Incident Response

Pre-Release Gates

AI Security Architecture & Identity

Prompt Injection & Goal Hijacking

Test hostile instructions inside:

Tool Calling & Excessive Agency

Pay special attention to agents with:

AI Data Access & Privacy

AI Release Gate

The security architecture should explicitly treat all of these as untrusted unless independently verified:

AI-Generated Authorization & Data Bugs

AI-Generated Crypto, Dependency & Config Bugs

Review every AI-generated:

Review Blind Spots

Agent Prompts & PR Review

Can an attacker reach the same operation another way?

Vibe-Coding Release Gate