@viberaven/cli
A successful deploy does not show whether one user can read another user's rows. VibeRaven reads an AI-built Vercel + Supabase app's repository for missing row level security (RLS), permissive policies and other launch gaps, then writes findings and tasks a coding agent can work through.
Use a pass before launch or client handoff, after a migration or policy change, or when investigating a production RLS, environment, database connection, service-role or Stripe webhook failure.
Start From Your App
Requires Node.js 20 or newer. Run from the app's project root:
npx -y viberaven@1.6.6
npx -y viberaven@1.6.6 check
The viberaven package launches this CLI. Studio combines findings, provider context and git comparisons. For chat, select an installed/authenticated Codex CLI, Claude Code or Gemini CLI and use Test connection. Access modes: ask, approve, full. Stop Studio with Ctrl+C.
Repository Evidence And Tasks
Checks include migration tables without RLS, unrestricted policy conditions such as USING (true), browser-exposed service-role keys, environment names missing from .env.example or similar templates, and Stripe handlers without raw-body signature verification.
check refreshes .viberaven/agent-tasklist.md (tasks and source locations), gate-result.json (full verdict), context-map.json (agent context) and gaps/<gapId>.json without patching app source.
check --json prints a findings summary and artifact paths. --json without check runs a fresh scan and prints the full gate object.
npx -y viberaven@1.6.6 check --json
npx -y viberaven@1.6.6 audit --vercel-supabase --json
npx -y viberaven@1.6.6 fix --gap <gapId> --dry-run
npx -y viberaven@1.6.6 init --agents all --dry-run
Read tasks and source before targeted edits. Preview fixes first. The rls_disabled recipe adds an RLS migration without policies: agree before applying, because browser roles lose row access until policies exist. Apply/test through your database workflow; recheck after a batch. Provider actions require provider evidence.
Exit Codes And CI
check returns 0 with no critical blockers, allowing warnings; 1 for critical blockers; 2 for a scan or comparison error. Unrestricted SELECT can be intentional public content and is a default warning. The focused audit returns 1 whenever its status is not pass, including warnings.
npx -y viberaven@1.6.6 --strict --json
npx -y viberaven@1.6.6 --strict=warning --json
Default --strict returns 0 for clear/warning, 1 for not_clear, 2 for error, 3 for unknown or unavailable results. --strict=warning also returns 1 for warnings.
Optional Artifact Compatibility Mode
Older integrations can keep the canonical artifact command:
npx -y viberaven --agent-mode
Studio remains the default. MCP hosts use the separate @viberaven/mcp package.
Scope And Evidence
The scan needs no VibeRaven login or API key; npm downloads can need network. It does not query live policies, prove complete permission coverage, run your build or deploy. With RLS off, table grants determine which roles and operations can reach rows. Verify live user access and provider environment, DNS, billing and webhooks separately. A clear result or score is not a security audit.
The missing-RLS example and RLS comparison retain published 1.6.3 runs. They are maintainer-authored, not new scans or independent endorsement. Comparison databases are local, not hosted Supabase.
Public repository | Agent reference. License: MIT.