Catalog-Driven Security Testing
Use when testing database authority from live catalogs. Use this skill to turn a database's live authorization catalogs into deterministic, fail-closed security tests. It applies when a codebase must inventory tables, sequences, policies, grants, routine ownership, elevated execution modes, and runtime actor authority before or during privilege hardening.
Separate observation from approval
Maintain two explicit contracts:
- Observed baseline: the exact current catalog state, including known unsafe authority.
- Target policy: the desired least-privilege state and actor boundaries.
A discovery task may allow the exact current chain to pass while labeling unsafe entries TRANSITIONAL_<REMEDIATION_TASK>_REQUIRED. Never call transitional authority approved. The remediation task removes those entries and updates both contracts.
Inventory requirements
Inventory directly from live system catalogs after a clean migration reset:
- application tables and sequences;
- RLS enablement/force state and complete policy semantics;
- table, sequence, schema, and routine grants, including
PUBLIC; - routine identity by schema, name, and identity arguments so overloads cannot collide;
- routine owner, security-invoker/definer mode, and explicit
search_path/configuration; - authority for every runtime/operator actor (request, jobs, connectors, migrations, break-glass, and project-specific roles).
For PostgreSQL, do not treat non-null ACL rows as the whole truth. Expand default privileges such as implicit PUBLIC EXECUTE on routines and other catalog defaults relevant to the object class.
Fail-closed fixture pattern
Create transaction-scoped negative fixtures that introduce one defect at a time and assert the inventory fails:
- undocumented table or sequence;
- missing/changed RLS policy or semantics;
- extra role or
PUBLICgrant; - function overload/signature drift;
- owner drift;
SECURITY DEFINERdrift;- missing, unsafe, or changed
search_path; - privilege classification changed from transitional/approved to undocumented.
Each negative case must prove the expected inventory assertion fails, then roll back. A clean reset must pass afterward. Count and report the negative cases so accidental fixture removal is visible.
Review and verification
- Review catalog queries for omitted implicit/default privileges and overload collisions.
- Reconcile fixture counts with live catalog counts.
- Ensure known unsafe authority is exhaustive and assigned to a concrete remediation task.
- Run the database test against a clean local migration chain.
- After any reviewer mutation, rerun the focused database test and all required repository gates; earlier green evidence is stale.
- Inspect and remove agent bookkeeping before commit.
A review worker may make a valid security fix and still exit nonzero because a delivery hook lacks final review metadata. Preserve the mutation, inspect its exact paths, and judge it by post-mutation evidence rather than the prose wrapper.
Reference
See references/postgresql-privilege-inventory.md for PostgreSQL-specific ACL, routine, and negative-fixture pitfalls.
Supporting files: this skill's supporting files are held in the docsite at
docs/15-skills/_support/engineering/catalog-driven-security-testing/— fetch them fresh fromjknash/docsitemain alongside this page. Source:jknash/hermes-shared-skills· branchhermes-jkdev001@1d0d545c3970·skills/engineering/catalog-driven-security-testing/· view source · Imported 2026-10-04. Supporting files (references, scripts) remain in the source repository.
version 1.0.0.
Published by Muse · 2026-10-04.