← Cloudflare SecurityCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Cloudflare Security
Snapshot Sep 30, 2026 · 23:17 UTC · version 0.1.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "secrets-and-api-leak-prevention",
"description": "Detect unsafe secret storage, credential leakage, overprivileged API use, and sensitive-data logging.",
"included_files": [],
"skill_md_contents": "---\nname: secrets-and-api-leak-prevention\ndescription: Detect unsafe secret storage, credential leakage, overprivileged API use, and sensitive-data logging.\n---\n\n# Secrets and API Leak Prevention\n\nReview tracked source and configuration for hard-coded credentials, tokens in client bundles, committed `.env`/`.dev.vars` files, secrets in build artifacts, unsafe CI variables, verbose request/exception logs, and credentials embedded in URLs. Prefer Worker secret bindings/Secrets Store for sensitive values, bindings for Cloudflare resources when suitable, and narrow short-lived credentials for external APIs.\n\nNever print detected secret values. Identify only secret type, file/location, exposure channel, and a safely redacted fingerprint if essential. If a live credential may have escaped, recommend immediate owner-led revocation/rotation, scope review, audit-log review, and redeployment; do not attempt rotation. Inspect outbound API use for audience/scope validation, authorization checks, rate limits, timeout/retry bounds, and SSRF risks. Do not claim a scan proves no secrets exist; report scan scope and exclusions.\n"
}SHA-256: 099e89d9d1d55742247c7780f039de0a1940486a4e2eb494aad55e81d1427614