← Vibe Code Security ReviewerCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Vibe Code Security Reviewer
Snapshot Sep 30, 2026 · 23:17 UTC · version 0.1.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "api-leak-and-key-security",
"description": "Detect API keys, service credentials, tokens, and privileged endpoints leaked to clients or repositories.",
"included_files": [],
"skill_md_contents": "---\nname: api-leak-and-key-security\ndescription: Detect API keys, service credentials, tokens, and privileged endpoints leaked to clients or repositories.\n---\n\n# API Leak and Key Security\n\nSearch source, history, bundles, source maps, logs, error responses, CI output, previews, browser storage, and configuration for secrets. Treat `NEXT_PUBLIC_*`, `VITE_*`, `PUBLIC_*`, client-exposed environment variables, and frontend bundles as public. Never expose Supabase `service_role`, secret keys, database passwords, signing keys, or provider secrets. Report location and rotation need without reproducing values.\n\nVerify server/client boundaries, secret injection, redaction, rotation, least privilege, environment separation, and whether a leaked key remains usable after removal from source.\n"
}SHA-256: 99d4811005aa139e38c21fd6b326f100d9c60b136d9be09ab32418c4ebb21611