{
  "product": "rowshield",
  "site": "https://rowshield.dev",
  "tool": "RowShield connected audit (nine rules) — runScan over the demo project's catalogue",
  "subject": "RowShield demo project (vulnerable variant, the same rows the dashboard seeds)",
  "scanned_at": "2026-09-07T08:09:15Z",
  "duration_ms": 28,
  "result": "FOUND",
  "finding": "RLS disabled on public.invoices, plus six more: an always-true policy, a policy without WITH CHECK, a public storage bucket, a table with no policies, an unwrapped auth.uid() call, an unindexed RLS predicate",
  "health": { "score": 25, "grade": "F", "counts": { "critical": 2, "high": 3, "medium": 2, "low": 0, "info": 0 } },
  "findings": [
    { "rule": "RLS_DISABLED", "severity": "critical", "title": "Row Level Security is disabled on public.invoices" },
    { "rule": "RLS_TAUTOLOGY", "severity": "critical", "title": "Policy \"public_read\" on public.posts always evaluates to true" },
    { "rule": "MISSING_WITH_CHECK", "severity": "high", "title": "Policy \"insert_any\" on public.comments has no WITH CHECK clause" },
    { "rule": "PUBLIC_BUCKET_EXPOSURE", "severity": "high", "title": "Storage bucket \"avatars\" is public" },
    { "rule": "RLS_NO_POLICIES", "severity": "high", "title": "public.profiles has RLS enabled but no policies" },
    { "rule": "RLS_UNWRAPPED_AUTH_CALL", "severity": "medium", "title": "Policy \"select_own\" on public.comments calls auth.uid() per row" },
    { "rule": "UNINDEXED_RLS_PREDICATE", "severity": "medium", "title": "RLS predicate column public.comments.user_id is not indexed" }
  ],
  "how_produced": "npx tsx scripts/sample-audit.ts vulnerable in the RowShield repository: the demo catalogue (apps/worker/src/demo-catalog.ts) is passed through @rowshield/scanner's runScan — the same function a connected project's scan runs. The free URL check on rowshield.dev runs only the two probe rules; these seven come from the connected audit.",
  "source_url": "https://rowshield.dev/",
  "note": "A demo project, scanned by the real rule engine. No customer data."
}
