AZ612: A schema on the search path others may create in
The functions that evaluate the policy's own SQL (its {...} conditions, the trees' triggers) run as the owner, and resolve names on the search path of the session that applied the policy. Another role may create objects in one of its schemas (often public: a database upgraded from Postgres 14 or older keeps CREATE for everyone), and a function made there can take the place of a built-in one, so it would run as the owner. Superusers, the owner, the database's owner and the roles that can become them are trusted. Revoke that CREATE (REVOKE CREATE ON SCHEMA public FROM PUBLIC), or apply with a search path without that schema (ALTER ROLE <owner> SET search_path = app): the policy's names are usually written with their schema anyway. authz.lint() reports it when the grant comes after.
Reported when the policy is applied (rowfence push, apply, a migration), against the database.