← Vibe Code Security ReviewerCONTENT HISTORY

Update to Vibe Code Security Reviewer

Snapshot Sep 30, 2026 · 23:17 UTC · version 0.1.0

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "api-leak-and-key-security",
  "description": "Detect API keys, service credentials, tokens, and privileged endpoints leaked to clients or repositories.",
  "included_files": [],
  "skill_md_contents": "---\nname: api-leak-and-key-security\ndescription: Detect API keys, service credentials, tokens, and privileged endpoints leaked to clients or repositories.\n---\n\n# API Leak and Key Security\n\nSearch source, history, bundles, source maps, logs, error responses, CI output, previews, browser storage, and configuration for secrets. Treat `NEXT_PUBLIC_*`, `VITE_*`, `PUBLIC_*`, client-exposed environment variables, and frontend bundles as public. Never expose Supabase `service_role`, secret keys, database passwords, signing keys, or provider secrets. Report location and rotation need without reproducing values.\n\nVerify server/client boundaries, secret injection, redaction, rotation, least privilege, environment separation, and whether a leaked key remains usable after removal from source.\n"
}

SHA-256: 99d4811005aa139e38c21fd6b326f100d9c60b136d9be09ab32418c4ebb21611