The credential inherits a history.
agent-db-scan is a small open-source tool that asks what a PostgreSQL login can read, write, or administer. Its report combines direct grants, inherited roles, PUBLIC grants, ownership, and default privileges.[1]
That list matters before an agent receives DATABASE_URL. PostgreSQL grants access through several routes. Membership can make another role's privileges available. Object ownership carries control rights. PUBLIC applies a grant to every role. Default privileges can grant access to objects created later.[2]
A connection test proves reachability. It does not inventory authority.
Current access and future access are different jobs.
An object ACL describes a table or sequence that exists now. ALTER DEFAULT PRIVILEGES changes what will be granted when a role creates a new object. PostgreSQL documents those as separate mechanisms. A clean scan of today's tables does not answer what tomorrow's migration will grant.[3]
The scanner reports both. Its source resolves effective roles and current object access, then computes forward-looking access from default ACL entries. This is the right split for an agent preflight because migrations can change the credential's reach without changing the connection string.
The scanner has a real brake and real blind spots.
The repository opens one PostgreSQL connection, starts a read-only transaction, applies a five-second statement timeout, and rolls the transaction back. The scan reads catalog metadata rather than table contents. We downloaded the v0.1.0 Linux release, verified its published checksum, ran its help command, and confirmed that it refuses to run without a connection string.[1]
Its README also names what it does not resolve. It does not evaluate row-level security expressions, trace SECURITY DEFINER functions, trace view-owner rights, or inspect column-level privileges. PostgreSQL provides separate inquiry functions for table, column, schema, function, database, and role privileges. One summary level cannot replace those checks.[4]
Keep secrets out of the command line.
The project accepts --dsn, but its README recommends DATABASE_URL because command arguments can land in shell history and process listings. Use a short-lived credential if the system supports one. Save the report without saving the password.
The cutaway below builds a review card for the scan. It does not connect to a database or judge whether a role is safe.