Runtime Defense Against Prompt Injection in Supabase MCP
Runtime Defense Against Prompt Injection in Supabase MCP
I wrote this after studying the Supabase MCP prompt injection issue. The blog shows how I built a working defense using an open-source AI agent runtime I’ve been building called Tansive ( https://github.com/tansive/tansive ) Instead of just filtering malicious prompts, I implemented role-based policies with runtime input validation that can scale across combinations of different AI tools (GitHub, Stripe, Linear, etc.). All the code referenced in the blog is in the examples/supabase_demo folder. I welcome your feedback — especially from folks working with AI toolchains or security.
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
Merlin’s Defense. GPT-4 Prompt Attack CTF
Exploit farm for attack-defense CTF competitions
Celestron – a tower defense submission to madewithreplit
Eight-layer prompt injection defense for AI agents
A container runtime implemented in x86_64 assembly
Subverting Go's Runtime System
Toggle Methods and Endpoints at Runtime
Mixing C++ with Angelscript for runtime introspection and debugging
Restate, a Distributed Async Runtime
AegisBPF – Deterministic Runtime Enforcement via eBPF LSM