Lintel
Provides read-only tools for auditing Supabase database migrations and Row Level Security (RLS) policies, including check_migrations, run_checks, diff_databases, list_checks, and explain_check. It replays base and PR migrations into throwaway Supabase databases to detect new leaks, prove anon access, and report findings.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Lintelis my new migration safe to merge?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Lintel
Catch Supabase RLS leaks in the pull request that introduces them.
Lintel replays your base branch's and your PR's migrations into two throwaway Supabase databases and checks both. It posts one PR comment listing only what the PR changed: new, fixed in this PR, unchanged. It can also prove a leak by querying as anon or as another user.
Status: early development. The table below lists what works today. Everything else is in docs/design.md.
Built on Supabase's linter
Supabase already ships an excellent linter, splinter. You can reach it through the dashboard Advisors, supabase db advisors and the Supabase MCP server. Lintel uses it for every static finding, and adds three things it doesn't do:
PR diffs. Findings are compared against the base branch, so only what the PR introduces fails the check.
Proof. Probes run real queries as
anon(and soon as another signed-in user) and report what actually leaks, e.g. "the public anon key can read 2 rows frompublic.messagesbecause RLS is disabled."One contract, three surfaces: a CLI, an MCP server for coding agents, and a REST API (in progress).
Related MCP server: schema-guard-mcp
Try it (from source)
You need Node 22 or later, Docker, and the Supabase CLI.
git clone https://github.com/Amsozzer1/lintel && cd lintel
pnpm install && pnpm build
node dist/cli.js setup # one time: pulls the database image
cd ~/your-supabase-project
node ~/lintel/dist/cli.js migrations check # your working tree vs mainNew
error public.messages rls_disabled_in_public
Table `public.messages` is public, but RLS has not been enabled.
error public.messages policy_exists_rls_disabled
Table `public.messages` has RLS policies but RLS is not enabled on the table. …
2 new (2 error, 0 warn, 0 info) · 0 resolved · 0 unchangedUse it from a coding agent (MCP)
lintel mcp serves five read-only tools over stdio. The one agents need most is check_migrations. Ask your agent "is this migration safe to merge?" and it replays your base branch and your working tree into throwaway databases. It answers NOT SAFE: the change introduces errors, with the proven leak, before anything reaches a real database.
{
"mcpServers": {
"lintel": {
"command": "node",
"args": ["/abs/path/to/lintel/dist/cli.js", "mcp", "--config", "/abs/path/to/lintel.config.json"],
"env": { "STAGING_DATABASE_URL": "postgresql://…" }
}
}
}{ "schemas": ["public"], "profiles": { "staging": { "url": "env:STAGING_DATABASE_URL" } } }Design choices:
Tools take profile names, never connection strings, so credentials don't pass through the model's context.
Every tool is read-only.
Results mark database identifiers as untrusted data. A table can be named like an instruction.
The tool list is a versioned contract (
schemas/mcp-tools.v1.json) that CI checks for drift.
Status
Piece | State |
| ✅ |
| ✅ |
| ✅ |
GitHub Action with a fork-safe sticky comment (see it on a demo PR) | ✅ |
Probe P001: proves what the | ✅ |
Probes P002 anon write, P003 cross-user read | ⏳ |
MCP server: | ✅ |
REST API (OpenAPI 3.1) | ⏳ |
lintel --help starts in about 25 ms (measured on an M-series Mac with Node 24).
Exit codes
Code | Meaning |
0 | Clean |
1 | Findings at or above |
2 | Usage error |
3 | Can't reach the database, Docker or the Supabase CLI |
4 | Internal error |
5 | A migration failed to apply |
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
Deterministic safety, correctness & cost gate that vets Postgres SQL before your AI agent runs it.
Your Supabase account in natural language: run SQL, apply migrations, manage tables, storage, edge f
Detects database migration table locks, terraform cost leaks, and OWASP API flaws.
Safe, read-only Postgres and MySQL access for AI agents. Audit log + column-level controls.
Related MCP Servers
- AlicenseAqualityCmaintenanceMCP server that lets AI coding agents (Claude Code, Cursor, Cline) audit Supabase projects for security misconfigurations AND apply the fixes — without leaving the agent. Tools: audit_project, list_findings, preview_fix (BEGIN/ROLLBACK safety), apply_fix (with confirmation), apply_all_fixes (transactional bulk). Closes the audit-fix loop entirely in the agent — other Supabase scanners only report.511 npm1MIT
- FlicenseAqualityCmaintenanceAudits PostgreSQL/Supabase schemas for security issues like missing RLS, permissive policies, and sensitive data exposure during AI conversations.3-
- AlicenseAqualityAmaintenanceBlocks unsafe PostgreSQL migrations before an AI agent writes or runs them. check_before_apply returns a pass/fail gate; reads the real Postgres parser, classifies the lock each statement takes, checks 112 safety rules. Runs offline, no database required.7612 npm7MIT
- AlicenseNot gradedqualityBmaintenanceEnables safe, read-only SQL exploration and debugging on Supabase Edge Functions, respecting user JWTs. It inspects schemas, explains query plans, proposes RLS policies, and runs guarded queries without destructive operations.MIT