Open to contract work. Based in Ukraine, working remotely with clients in the US and EU.
- supabase-security-mcp — MCP server that audits a Supabase project from Claude/Cursor: anon-key probe, RLS policy audit (using(true), missing TO clause, exposed SECURITY DEFINER), two-account cross-tenant test.
npx supabase-security-mcp. - RLS Watch — self-hosted daily security monitor for agencies running many Supabase projects: same checks, diff vs yesterday, Telegram alerts, client report. Live at watch.sixthgear.dev.
- LeaseAI — AI lease-analysis SaaS I built and run: Supabase backend with hardened row-level security and rate limiting, Paddle billing, live payments.
- LeadBox security demo — live before/after showing how an AI-built app leaks every user's data when row-level security isn't done right, and what "fixed" looks like. Try both buttons.
- github/github-mcp-server — open-source contributions in Go: #3293 (tool annotations), #3317 (input validation), issue #3316.
Take AI-built MVPs (Lovable, Bolt, v0, Cursor) to production: auth, billing, deploys, and the Supabase security holes those tools leave open. Build n8n / Make automations for small teams.
larik2174@gmail.com · Reddit: u/Alternative-Year-430