New:Introducing Socket Scanning for VS Code Marketplace Extensions.Learn more →
Get Started

@viberaven/cli

Package Overview
Dependencies
Maintainers
1
Versions
54
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@viberaven/cli

VibeRaven CLI and local Studio: Supabase RLS and security check for AI-built Vercel + Supabase apps, with an agent task list and fix prompts.

Source
npmnpm
Version
1.6.5
Version published
Weekly downloads
889
-19.62%
Maintainers
1
Weekly downloads
 
Created
Source

@viberaven/cli

A successful deploy does not show whether one user can read another user's rows. VibeRaven reads an AI-built Vercel + Supabase app's repository for missing row level security (RLS), permissive policies and other launch gaps, then writes findings and tasks a coding agent can work through.

Use a pass before launch or client handoff, after a migration or policy change, or when investigating a production RLS, environment, database connection, service-role or Stripe webhook failure.

Start From Your App

Requires Node.js 20 or newer. Run from the app's project root:

# Open the local Studio
npx -y viberaven@1.6.5

# Fresh terminal check
npx -y viberaven@1.6.5 check

The viberaven package launches this CLI. Studio combines findings, provider context and git comparisons. For chat, select an installed/authenticated Codex CLI, Claude Code or Gemini CLI and use Test connection. Access modes: ask, approve, full. Stop Studio with Ctrl+C.

Repository Evidence And Tasks

Checks include migration tables without RLS, unrestricted policy conditions such as USING (true), browser-exposed service-role keys, environment names missing from .env.example or similar templates, and Stripe handlers without raw-body signature verification.

check refreshes .viberaven/agent-tasklist.md (tasks and source locations), gate-result.json (full verdict), context-map.json (agent context) and gaps/<gapId>.json without patching app source.

check --json prints a findings summary and artifact paths. --json without check runs a fresh scan and prints the full gate object.

npx -y viberaven@1.6.5 check --json
npx -y viberaven@1.6.5 audit --vercel-supabase --json
npx -y viberaven@1.6.5 fix --gap <gapId> --dry-run
npx -y viberaven@1.6.5 init --agents all --dry-run

Read tasks and source before targeted edits. Preview fixes first. The rls_disabled recipe adds an RLS migration without policies: agree before applying, because browser roles lose row access until policies exist. Apply/test through your database workflow; recheck after a batch. Provider actions require provider evidence.

Exit Codes And CI

check returns 0 with no critical blockers, allowing warnings; 1 for critical blockers; 2 for a scan or comparison error. Unrestricted SELECT can be intentional public content and is a default warning. The focused audit returns 1 whenever its status is not pass, including warnings.

# Fail on blockers
npx -y viberaven@1.6.5 --strict --json
# Also fail on warnings
npx -y viberaven@1.6.5 --strict=warning --json

Default --strict returns 0 for clear/warning, 1 for not_clear, 2 for error, 3 for unknown or unavailable results. --strict=warning also returns 1 for warnings.

Optional Artifact Compatibility Mode

Older integrations can keep the canonical artifact command:

npx -y viberaven --agent-mode

Studio remains the default. MCP hosts use the separate @viberaven/mcp package.

Scope And Evidence

The scan needs no VibeRaven login or API key; npm downloads can need network. It does not query live policies, prove complete permission coverage, run your build or deploy. With RLS off, table grants determine which roles and operations can reach rows. Verify live user access and provider environment, DNS, billing and webhooks separately. A clear result or score is not a security audit.

The missing-RLS example and RLS comparison retain published 1.6.3 runs. They are maintainer-authored, not new scans or independent endorsement. Comparison databases are local, not hosted Supabase.

Public repository | Agent reference. License: MIT.

Keywords

viberaven

FAQs

Package last updated on 06 Oct 2026

Related posts