HNHacker News
TopNewBestAskShowJobs

anand-tan

1 karma · joined July 2, 2025

building Tansive (tansive.com)

anand.mail@mugil.net

submissionscomments
anand-tan··on Show HN: Runtime Defense Against Prompt Injection in Supabase MCP
Absolutely. If the tools were only from Supabase, then yes, you could use Postgres roles. However, most people use a combination of tools (GitHub, Stripe, Linear, etc.), and each has different permission models. I wanted to implement a solution that works generically across tools rather than requiring separate security configurations for each service. This doesn't preclude one from limiting the access scope at the database, though.
anand-tan··on Show HN: I Built a Runtime Defense Against Prompt Injection in Supabase MCP
For reference, this was the thread that led me to work on this.

https://news.ycombinator.com/item?id=44502318

anand-tan··on Supabase MCP can leak your entire SQL database
This was precisely why I posted Tansive on Show HN this morning -

https://news.ycombinator.com/item?id=44499658

MCP is generally a bad idea for stuff like this.