database-schema-designer
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyreferences/schema-design-and-security.md
LOWAnomalyLOW
references/schema-design-and-security.md
This fragment appears to be legitimate multi-tenant schema and RLS code, not malware or an intentional supply-chain attack. It contains a significant security risk: the separate permissive tasks_hide_deleted policy does not combine with the workspace policy as an AND condition, so authorized users may be able to read soft-deleted tasks. Combine the conditions in one policy or use restrictive policy semantics, and ensure app_user cannot bypass RLS and that the session identity is securely established.
Confidence: 97%Severity: 68%
Audit Metadata