Security researcher finds 60+ live Supabase keys in public repos, tests if AI can catch them
A security researcher discovered more than 60 live Supabase service_role keys exposed in public GitHub repositories over just three days of scanning, with keys found in config files, .env templates, deploy docs, and even browser-bundled JavaScript. These keys bypass Row Level Security entirely, granting full read/write access to real production databases. The researcher then built a benchmark on Kaggle to test whether nine leading AI models could identify such credential leaks when acting as security reviewers. Results were mixed: Claude Sonnet 5, Gemini 3.7 Flash, Gemini 3 Flash Preview, and Gemini 3.1 Flash Lite each scored a perfect 10 out of 10, while GPT-5.4-nano scored 8/10 and DeepSeek-R1 scored 0/10 due to flagging every case as critical. The findings highlight both the widespread risk of accidental credential exposure and the varying ability of AI coding assistants to detect the very leaks they may have helped create.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in