
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@viberaven/cli
Advanced tools
VibeRaven CLI and local Studio: Supabase RLS and security check for AI-built Vercel + Supabase apps, with an agent task list and fix prompts.
A successful deploy does not show whether one user can read another user's rows. VibeRaven reads an AI-built Vercel + Supabase app's repository for missing row level security (RLS), permissive policies and other launch gaps, then writes findings and tasks a coding agent can work through.
Use a pass before launch or client handoff, after a migration or policy change, or when investigating a production RLS, environment, database connection, service-role or Stripe webhook failure.
Requires Node.js 20 or newer. Run from the app's project root:
# Open the local Studio
npx -y viberaven@1.6.5
# Fresh terminal check
npx -y viberaven@1.6.5 check
The viberaven package launches this CLI. Studio combines findings, provider context and git comparisons. For chat, select an installed/authenticated Codex CLI, Claude Code or Gemini CLI and use Test connection. Access modes: ask, approve, full. Stop Studio with Ctrl+C.
Checks include migration tables without RLS, unrestricted policy conditions such as USING (true), browser-exposed service-role keys, environment names missing from .env.example or similar templates, and Stripe handlers without raw-body signature verification.
check refreshes .viberaven/agent-tasklist.md (tasks and source locations), gate-result.json (full verdict), context-map.json (agent context) and gaps/<gapId>.json without patching app source.
check --json prints a findings summary and artifact paths. --json without check runs a fresh scan and prints the full gate object.
npx -y viberaven@1.6.5 check --json
npx -y viberaven@1.6.5 audit --vercel-supabase --json
npx -y viberaven@1.6.5 fix --gap <gapId> --dry-run
npx -y viberaven@1.6.5 init --agents all --dry-run
Read tasks and source before targeted edits. Preview fixes first. The rls_disabled recipe adds an RLS migration without policies: agree before applying, because browser roles lose row access until policies exist. Apply/test through your database workflow; recheck after a batch. Provider actions require provider evidence.
check returns 0 with no critical blockers, allowing warnings; 1 for critical blockers; 2 for a scan or comparison error. Unrestricted SELECT can be intentional public content and is a default warning. The focused audit returns 1 whenever its status is not pass, including warnings.
# Fail on blockers
npx -y viberaven@1.6.5 --strict --json
# Also fail on warnings
npx -y viberaven@1.6.5 --strict=warning --json
Default --strict returns 0 for clear/warning, 1 for not_clear, 2 for error, 3 for unknown or unavailable results. --strict=warning also returns 1 for warnings.
Older integrations can keep the canonical artifact command:
npx -y viberaven --agent-mode
Studio remains the default. MCP hosts use the separate @viberaven/mcp package.
The scan needs no VibeRaven login or API key; npm downloads can need network. It does not query live policies, prove complete permission coverage, run your build or deploy. With RLS off, table grants determine which roles and operations can reach rows. Verify live user access and provider environment, DNS, billing and webhooks separately. A clear result or score is not a security audit.
The missing-RLS example and RLS comparison retain published 1.6.3 runs. They are maintainer-authored, not new scans or independent endorsement. Comparison databases are local, not hosted Supabase.
Public repository | Agent reference. License: MIT.
FAQs
VibeRaven CLI and local Studio: Supabase RLS and security check for AI-built Vercel + Supabase apps, with an agent task list and fix prompts.
The npm package @viberaven/cli receives a total of 831 weekly downloads. As such, @viberaven/cli popularity was classified as not popular.
We found that @viberaven/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.