Skip to main content

Catalog-Driven Security Testing

Use when testing database authority from live catalogs. Use this skill to turn a database's live authorization catalogs into deterministic, fail-closed security tests. It applies when a codebase must inventory tables, sequences, policies, grants, routine ownership, elevated execution modes, and runtime actor authority before or during privilege hardening.

Separate observation from approval​

Maintain two explicit contracts:

  1. Observed baseline: the exact current catalog state, including known unsafe authority.
  2. Target policy: the desired least-privilege state and actor boundaries.

A discovery task may allow the exact current chain to pass while labeling unsafe entries TRANSITIONAL_<REMEDIATION_TASK>_REQUIRED. Never call transitional authority approved. The remediation task removes those entries and updates both contracts.

Inventory requirements​

Inventory directly from live system catalogs after a clean migration reset:

  • application tables and sequences;
  • RLS enablement/force state and complete policy semantics;
  • table, sequence, schema, and routine grants, including PUBLIC;
  • routine identity by schema, name, and identity arguments so overloads cannot collide;
  • routine owner, security-invoker/definer mode, and explicit search_path/configuration;
  • authority for every runtime/operator actor (request, jobs, connectors, migrations, break-glass, and project-specific roles).

For PostgreSQL, do not treat non-null ACL rows as the whole truth. Expand default privileges such as implicit PUBLIC EXECUTE on routines and other catalog defaults relevant to the object class.

Fail-closed fixture pattern​

Create transaction-scoped negative fixtures that introduce one defect at a time and assert the inventory fails:

  • undocumented table or sequence;
  • missing/changed RLS policy or semantics;
  • extra role or PUBLIC grant;
  • function overload/signature drift;
  • owner drift;
  • SECURITY DEFINER drift;
  • missing, unsafe, or changed search_path;
  • privilege classification changed from transitional/approved to undocumented.

Each negative case must prove the expected inventory assertion fails, then roll back. A clean reset must pass afterward. Count and report the negative cases so accidental fixture removal is visible.

Review and verification​

  1. Review catalog queries for omitted implicit/default privileges and overload collisions.
  2. Reconcile fixture counts with live catalog counts.
  3. Ensure known unsafe authority is exhaustive and assigned to a concrete remediation task.
  4. Run the database test against a clean local migration chain.
  5. After any reviewer mutation, rerun the focused database test and all required repository gates; earlier green evidence is stale.
  6. Inspect and remove agent bookkeeping before commit.

A review worker may make a valid security fix and still exit nonzero because a delivery hook lacks final review metadata. Preserve the mutation, inspect its exact paths, and judge it by post-mutation evidence rather than the prose wrapper.

Reference​

See references/postgresql-privilege-inventory.md for PostgreSQL-specific ACL, routine, and negative-fixture pitfalls.


Supporting files: this skill's supporting files are held in the docsite at docs/15-skills/_support/engineering/catalog-driven-security-testing/ — fetch them fresh from jknash/docsite main alongside this page. Source: jknash/hermes-shared-skills · branch hermes-jkdev001 @ 1d0d545c3970 · skills/engineering/catalog-driven-security-testing/ · view source · Imported 2026-10-04. Supporting files (references, scripts) remain in the source repository.

version 1.0.0.

Published by Muse · 2026-10-04.