New:Microsoft Teams Notifications Are Now Available in Socket.Learn more
Get Started

nhost-security

Package Overview
Dependencies
Maintainers
1
Versions
2
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

nhost-security

Audit Nhost (Hasura+Postgres) projects for permissive role permissions, public GraphQL access, and unsafe auth config. Keyless --discover mode parses your repo + probes GraphQL anon (no admin secret needed).

latest
Source
npmnpm
Version
0.2.0
Version published
Weekly downloads
1
-83.33%
Maintainers
1
Weekly downloads
 
Created
Source

Nhost / Hasura Security Auditor

Audit any Hasura instance (or Nhost project) for permissive role permissions, missing row-level scoping, and public GraphQL leaks. Active probe confirms each leak by sending an anonymous GraphQL query and showing what comes back.

Run it without installing anything → apify.com/renzomacar/nhost-security-auditor (paste Hasura endpoint + admin secret, get HTML report)

⚡ Want me to run it for you and send back a written report? $99, 24h delivery → https://perufitlife.github.io/supabase-security-skill/ (one landing covers all five — Supabase, PocketBase, Appwrite, Hasura, Firebase)

Why this exists

Hasura's permission model is powerful but easy to leave too open. The patterns I see most often:

  • anonymous role with open SELECT permission — any unauthenticated request can query the table. Often a leftover from local dev.
  • user role with empty filter {} — any signed-up user can read/update/delete every row, ignoring ownership. Should usually be { user_id: { _eq: "X-Hasura-User-Id" } }.
  • SELECT permission with all columns — exposes sensitive columns (password_hash, internal_notes) the role doesn't actually need.
  • Public schema introspection — anyone can map your entire data model + permission structure without auth.

Install + run

HASURA_ENDPOINT=https://my.hasura.app \
HASURA_ADMIN_SECRET=$ADMIN_SECRET \
npx nhost-security --html report.html

For Nhost projects the endpoint is https://<subdomain>.hasura.<region>.nhost.run.

What it checks

#CheckSeverity
1anonymous role has open SELECT permissionCRITICAL
2anonymous role has INSERT/UPDATE/DELETE permissionCRITICAL
3user role has SELECT/UPDATE/DELETE without row-level filterHIGH
4Permission exposes all columns (no allowlist)MEDIUM
5GraphQL introspection enabled for anonymousMEDIUM

Active probe

For every suspect anonymous SELECT permission, the auditor sends an anonymous GraphQL query ({ <table>(limit: 1) { __typename } }) and reports confirmed: true if rows come back. For introspection, sends { __schema { queryType { name } } } and reports if anonymous can read the schema.

--no-probe disables the live fetch.

License + source

MIT. Open source: https://github.com/Perufitlife/nhost-security-skill

For Supabase, see https://github.com/Perufitlife/supabase-security-skill For PocketBase, see https://github.com/Perufitlife/pocketbase-security-skill For Appwrite, see https://github.com/Perufitlife/appwrite-security-skill

Keywords

nhost

FAQs

Package last updated on 11 May 2026

Related posts