{"id":22207,"plugin_id":"plugins_6ab01c9056c481918eac972df8fb396d","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:17:11.300Z","digest":"99d4811005aa139e38c21fd6b326f100d9c60b136d9be09ab32418c4ebb21611","against":null,"payload":{"name":"api-leak-and-key-security","description":"Detect API keys, service credentials, tokens, and privileged endpoints leaked to clients or repositories.","included_files":[],"skill_md_contents":"---\nname: api-leak-and-key-security\ndescription: Detect API keys, service credentials, tokens, and privileged endpoints leaked to clients or repositories.\n---\n\n# API Leak and Key Security\n\nSearch source, history, bundles, source maps, logs, error responses, CI output, previews, browser storage, and configuration for secrets. Treat `NEXT_PUBLIC_*`, `VITE_*`, `PUBLIC_*`, client-exposed environment variables, and frontend bundles as public. Never expose Supabase `service_role`, secret keys, database passwords, signing keys, or provider secrets. Report location and rotation need without reproducing values.\n\nVerify server/client boundaries, secret injection, redaction, rotation, least privilege, environment separation, and whether a leaked key remains usable after removal from source.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}