Someone found your anon key in the bundle. Is that a breach? Here's what the anon key actually grants, and the RLS mistake that turns it into one.
A working checklist for Supabase security: RLS policies, anon keys, service role leaks, and the mistakes I keep finding in AI-built apps.
A data report on 66 live apps built with Lovable, Bolt, Cursor, base44, and Tempo. 41% of the Supabase-backed apps had at least one table anyone could read with the public anon key. Methodology, findings, and a 60-second self-check.