
Audit AI
io.github.audit0v0.4.1Updated Oct 4, 2026
Finds authorization holes in Next.js + Supabase apps and live Supabase databases. No API key.
Overview
AI-generated overview
Audit AI scans Next.js and Supabase projects and live Supabase databases for authorization holes, running locally with no API key.
- What it does
- Audit AI is a local MCP server that checks authorization logic in Next.js applications that use Supabase, and also inspects live Supabase databases. According to its description, it finds authorization holes in those targets. The manifest lists no tools, so the exact operations are not documented here.
- When to use it
- Worth considering when you are reviewing a Next.js plus Supabase codebase or a live Supabase database and want an assistant to help surface authorization gaps. It is a desktop-only local process, so it suits developer machines rather than hosted or browser-based setups.
- Requirements
- Runs as a local process over stdio, started with npx from the npm package auditai-mcp, so Node.js and network access for package installation are needed. The manifest declares no authentication, environment variables, or headers. It is desktop only.
Before you install
It inspects live Supabase databases, so point it only at databases you are authorized to examine and be aware of what connection details you supply. The description states no API key is required, but the manifest lists no tools, so review what it actually does before running it against production data.
Installation
In SourceWeft
- Open Audit AI in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Tools
0Tool metadata has not been indexed yet.
Version history
1- v0.4.1LatestOct 4, 2026

