PM case study + runnable eval harness: making the Supabase MCP safe-by-default. Unprompted, AI agents skip RLS ~93% of the time; gating the server's success on its own advisor takes data-safety from 7% to 100%.
Or install with pip: pip install agent-friendly-rls
README Excerpt
Supabase has written that AI coding agents "know about Supabase but don't always use it right." The most common version seems to be an agent that creates a table and forgets Row Level Security, leaving every user's rows readable by everyone else. It happens on the surface Supabase is investing in most: